EU's digital-sovereignty “boo‑boo” might be a blessing: it exposes Intel/AMD Ring‑3 risks and forces Europe to DIY secure chips & supply chains. DIY or die — and for heaven’s sake, don’t let the CIA buy it. 🇪🇺🔒🤖 #DigitalSovereignty #SupplyChainSecurity #SovereignCloud https://www.theregister.com/systems/2026/05/26/eus-digital-sovereignty-boo-boo-may-be-the-best-thing-to-ever-happen-to-the-project/5244715
EU's digital sovereignty boo-boo may be the best thing to ever happen to the project

DIY or die. Just don't let the CIA buy it

theregister
Netherlands blocks US takeover of vital digital supplier

Across Europe, there have been increased concerns about the bloc’s reliance on American tech.

POLITICO
Having worked with other CIs previously, I've just learned that essential GitHub Actions like checkout are implemented using NodeJS. #git #github #devops #supplychainsecurity https://github.com/actions/checkout
GitHub - actions/checkout: Action for checking out a repo

Action for checking out a repo. Contribute to actions/checkout development by creating an account on GitHub.

GitHub

Relying on fragmented security tools creates conflicting remediation priorities. What one tool considers acceptable before the build, another flags in production.

Anchore Enterprise v6 solves this with the new Unified Asset Model. Join our June 4 webinar to see how v6 combines all of your application assets—from modern containers to legacy infrastructure and third-party SBOMs—into a single, normalized "Application Version" for unified... https://go.anchore.com/anchore-enterprise-6.html

#DevSecOps #SupplyChainSecurity

🎙️ The #FIRSTImpressionsPodcast is back for the 2026 conference season!
Tune in to the newest episode at: https://media.first.org/podcasts/FIRST_Impressions-MorLior.mp3

In this episode, podcasters interview Mor Weinberger and Lior Kaplan to preview their #FIRSTCON26 session: “From Discovery to Fix: What 10,000 Open Source Projects Reveal About CVE Remediation”

The conversation dives into:
🔹 Why 90% of #CVEs already have fixes available
🔹 Why #remediation still takes months
🔹 How AI is accelerating vulnerability discovery
🔹 The hidden complexity of open source supply chains
🔹 Practical ways organizations can reduce risk today

New episodes drop every Friday leading up to FIRSTCON, featuring previews of conference talks and conversations with presenters across the global incident response community.

📍FIRST Conference 2026
June 14–19 | Denver, Colorado

Secure your seat today: https://www.first.org/conference/2026/registration

#FIRSTCON26 #CyberSecurity #OpenSource #VulnerabilityManagement #CVE #DevSecOps #SupplyChainSecurity

GitHub links a repo breach to the TanStack npm supply-chain attack - one compromised dependency can ripple across thousands of developers. Trust in code must be continuously verified. 📦⚠️ #SupplyChainSecurity #OpenSourceRisk

https://www.bleepingcomputer.com/news/security/github-links-repo-breach-to-tanstack-npm-supply-chain-attack/

GitHub links repo breach to TanStack npm supply-chain attack

GitHub says the hackers who breached 3,800 internal repositories gained access via a malicious version of the Nx Console VS Code extension, compromised in last week's TanStack npm supply-chain attack.

BleepingComputer

Müzeyyen Gökçen Arslan Tapkan of Black Kite says organizations still confuse compliance with actual security.

⚠️ Vendors can pass audits while exposing live risk
⚠️ Attackers rank vendors by exposure paths, not spend
⚠️ AI is worsening noise and confidence problems in cyber datasets

“Saying HITL in TPCRM is easy. Designing for it, vendor by vendor, signal by signal, decision by decision, this is the real work.”

https://www.technadu.com/why-attackers-understand-supply-chains-better-than-companies/628246/

#CyberSecurity #TPRM #SupplyChainSecurity #AI #Compliance

If you’ve seen the latest supply chain compromise via a malicious update to a VS Code extension, you might be thinking of using Intune to manage VS Code enterprise settings.

Microsoft however have the stupidest bug that they might want to prioritise fixing…

If you create the HKLM\Software\Policies\Microsoft\VSCode registry path first then it will work.

🤦‍♂️

#SupplyChainSecurity #SupplyChainCompromise #VSCode #VSCodeExtensions #Intune

https://github.com/microsoft/vscode/issues/281840

vscode.admx does not work with InTune · Issue #281840 · microsoft/vscode

The custom vscode.admx / adml that comes with VSCode is not supported for import in InTune. As per https://learn.microsoft.com/en-us/windows/client-management/win32-and-centennial-app-policy-config...

GitHub

Compromised art-template npm package versions reportedly delivered a Coruna-like iOS Safari exploit framework through a watering-hole attack.
Researchers say the framework targeted Safari users on iOS 11–17.2 via malicious redirect chains.

https://www.technadu.com/compromised-art-template-npm-package-delivers-coruna-like-ios-exploit/628212/

#CyberSecurity #SupplyChainSecurity #iOS #InfoSec

GitHub says a poisoned Nx Console VS Code extension enabled unauthorized access to internal infrastructure, contributing to the loss of ~3,800 repositories.

Researchers say the payload harvested GitHub tokens, AWS creds, SSH keys, and more.

https://www.technadu.com/3800-internal-github-repositories-lost-due-to-malicious-nx-console-vs-code-extension/628149/

#CyberSecurity #SupplyChainSecurity #GitHub #VSCode