Supply Chain Security

Kaspersky Identifies 250,000 Security Issues in GitHub Actions Workflows
Kaspersky researchers discovered over 250,000 potential security issues in GitHub Actions workflows, highlighting widespread configuration risks.

TanStack npm Supply Chain Compromise: 84 Malicious Versions Detected Across 42 Packages
An attacker exploited three chained vulnerabilities to publish 84 malicious npm versions across 42 TanStack packages on May 11. Detection occurred within 20 minutes; all versions were deprecated and npm security was engaged.

Anthropic Introduces Auto Mode for Claude Code with AI-Powered Permission Controls
Anthropic has added auto mode to Claude Code, using a Claude Sonnet 4.6 classifier to approve or block agent actions in real time. Security experts note the AI-based approach has inherent limitations compared to deterministic sandboxes.

Supply Chain Attacks Top Cyber Threats Facing Businesses Globally and in Saudi Arabia
Supply chain attacks affected 31% of enterprises globally and 30% in Saudi Arabia over the past 12 months, topping all other cyberthreat categories in a new Kaspersky study.
