home.social

#supply-chain — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #supply-chain, aggregated by home.social.

fetched live
  1. Wonder how the Medline fire will impact healthcare here in California... major supplier of surgical instruments and medical supplies.

    theguardian.com/us-news/2026/j

    #fire #supplychain #california

  2. Wonder how the Medline fire will impact healthcare here in California... major supplier of surgical instruments and medical supplies.

    theguardian.com/us-news/2026/j

    #fire #supplychain #california

  3. [#TRADESHOW] #CPHI & #PMEC #China 2026 from June 16 to 18, 2026, at the #Shanghai New #International #Expo #Center (#SNIEC). As #Asia’s leading #pharmaceutical #sourcing and #networking #platform, the #exhibition #event has more than 20 years of experience connecting #Chinese and international #pharma professionals. It serves as a key #meeting point for #innovation, #SupplyChain #collaboration, and #market expansion within the #global pharmaceutical #ecosystem. cnbusinessforum.com/event/cphi

  4. [#TRADESHOW] #CPHI & #PMEC #China 2026 from June 16 to 18, 2026, at the #Shanghai New #International #Expo #Center (#SNIEC). As #Asia’s leading #pharmaceutical #sourcing and #networking #platform, the #exhibition #event has more than 20 years of experience connecting #Chinese and international #pharma professionals. It serves as a key #meeting point for #innovation, #SupplyChain #collaboration, and #market expansion within the #global pharmaceutical #ecosystem. cnbusinessforum.com/event/cphi

  5. Fedora Account Compromise Raises AI Agent Supply Chain Concerns

    「 Williamson updated the thread, reporting that Giovannini claimed his credentials had been compromised and denied involvement with the AI system. Williamson advised treating all actions by the account with suspicion and said he would continue to review Bugzilla history and related upstream pull requests more closely. 」

    linuxiac.com/fedora-account-co

    #fedora #vibecoding #supplychain #opensource #cybersecurity

  6. Fedora Account Compromise Raises AI Agent Supply Chain Concerns

    「 Williamson updated the thread, reporting that Giovannini claimed his credentials had been compromised and denied involvement with the AI system. Williamson advised treating all actions by the account with suspicion and said he would continue to review Bugzilla history and related upstream pull requests more closely. 」

    linuxiac.com/fedora-account-co

    #fedora #vibecoding #supplychain #opensource #cybersecurity

  7. US Arms Sales to Europe Hit by Delivery Delays

    European countries are facing a frustrating dilemma: they're being urged to boost defense spending, but when they try to purchase US arms, they're met with lengthy and uncertain delivery timelines, sometimes as far off as 2029-2030. This has led some, like Poland, to look elsewhere, such as to the Korean defense industry, for quicker solutions.

    osintsights.com/us-arms-sales-

    #UsArmsSales #Europe #DefenseIndustry #Nato #SupplyChain

  8. 📰 AI Agent 'Skills' Pose Major Supply Chain Risk; New Audit Tool Finds 80% Deviate from Declared Behavior

    ⚠️ New AI Supply Chain Risk! 80% of AI agent 'skills' deviate from their promises, with 5% hiding multi-stage attacks for credential theft & RCE. A new audit tool, BIV, exposes the threat. #AISecurity #SupplyChain #LLM

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/tr

  9. 📰 AI Agent 'Skills' Pose Major Supply Chain Risk; New Audit Tool Finds 80% Deviate from Declared Behavior

    ⚠️ New AI Supply Chain Risk! 80% of AI agent 'skills' deviate from their promises, with 5% hiding multi-stage attacks for credential theft & RCE. A new audit tool, BIV, exposes the threat. #AISecurity #SupplyChain #LLM

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/tr

  10. Nehmt Arch haben sie gesagt! Das wird toll, haben sie gesagt! 🙄

    Scheiß npm. Wer das erfunden hat, sollte sowieso ewig in die supply chain und dependency hell.

    #arch #linux #aur #npm #supplychain #alvr

    @sodiboo gaysex.cloud/notes/andaxow7itf

  11. Nimmt Arch haben sie gesagt! Das wird toll, haben sie gesagt! 🙄

    Scheiß npm. Wer das erfunden hat, sollte sowieso ewig in die supply chain und dependency hell.

    #arch #linux #aur #npm #supplychain

    @sodiboo gaysex.cloud/notes/andaxow7itf

  12. More than 30 Red Hat npm packages were backdoored in a supply-chain attack deploying Miasma malware to steal developer credentials, cloud secrets, SSH keys, and CI/CD tokens. 🔐
    Researchers say the attack used a compromised GitHub account and npm publishing flows, underscoring risks in open-source supply chains. 📦

    🔗 bleepingcomputer.com/news/secu

    #TechNews #RedHat #npm #GitHub #Miasma #ShaiHulud #SupplyChain #OpenSource #Cybersecurity #Infosec #Security #DevOps #Linux #Malware #Developers

  13. More than 30 Red Hat npm packages were backdoored in a supply-chain attack deploying Miasma malware to steal developer credentials, cloud secrets, SSH keys, and CI/CD tokens. 🔐
    Researchers say the attack used a compromised GitHub account and npm publishing flows, underscoring risks in open-source supply chains. 📦

    🔗 bleepingcomputer.com/news/secu

    #TechNews #RedHat #npm #GitHub #Miasma #ShaiHulud #SupplyChain #OpenSource #Cybersecurity #Infosec #Security #DevOps #Linux #Malware #Developers

  14. Arch supply chain attacks: Arch Linux has a popular package repository called AUR. It's a frequent target of attacks to inject malware, so KDE is going to stop including it
    linux-magazine.com/Online/News
    #supplychain #security #badtech #linux #arch #aur #kde #-

  15. Arch supply chain attacks: Arch Linux has a popular package repository called AUR. It's a frequent target of attacks to inject malware, so KDE is going to stop including it
    linux-magazine.com/Online/News
    #supplychain #security #badtech #linux #arch #aur #kde #-

  16. Security Tip: Transparency is key to supply chain security. 🛡️ Implement a Software Bill of Materials (SBOM) for your applications. An SBOM is a formal record of all components and dependencies used in your software. When a new vulnerability is discovered, an SBOM allows your team to instantly verify if you are affected, reducing response time from days to minutes. Learn more about tracking vulnerabilities at cvedatabase.com #SupplyChain #SBOM #CyberSecurity

  17. Security Tip: Transparency is key to supply chain security. 🛡️ Implement a Software Bill of Materials (SBOM) for your applications. An SBOM is a formal record of all components and dependencies used in your software. When a new vulnerability is discovered, an SBOM allows your team to instantly verify if you are affected, reducing response time from days to minutes. Learn more about tracking vulnerabilities at cvedatabase.com

  18. Supply chain attack su npm: 11 pacchetti malevoli con C2 blockchain colpiscono 2,7 milioni di download crypto

    Cyfirma ha scoperto undici pacchetti npm malevoli che prendono di mira sviluppatori blockchain e Web3: il solo pacchetto moralis-sdk ha raggiunto 2,7 milioni di download. La campagna usa typosquatting, lifecycle hooks npm, furto di wallet crypto e — novità significativa — smart contract Ethereum come infrastruttura di comando e controllo.

    insicurezzadigitale.com/supply

  19. Supply chain attack su npm: 11 pacchetti malevoli con C2 blockchain colpiscono 2,7 milioni di download crypto

    Cyfirma ha scoperto undici pacchetti npm malevoli che prendono di mira sviluppatori blockchain e Web3: il solo pacchetto moralis-sdk ha raggiunto 2,7 milioni di download. La campagna usa typosquatting, lifecycle hooks npm, furto di wallet crypto e — novità significativa — smart contract Ethereum come infrastruttura di comando e controllo.

    insicurezzadigitale.com/supply

  20. Il worm Miasma disabilita 73 repository Microsoft su GitHub in 105 secondi: supply chain attack prende di mira gli AI coding agent

    Il worm Miasma, attribuito al gruppo TeamPCP, ha colpito le organizzazioni Azure e Microsoft su GitHub, piantando payload nei file di configurazione di Claude Code, Gemini CLI, Cursor e VS Code. GitHub ha disabilitato 73 repository in due ondate automatizzate in soli 105 secondi.

    insicurezzadigitale.com/il-wor

  21. Il worm Miasma disabilita 73 repository Microsoft su GitHub in 105 secondi: supply chain attack prende di mira gli AI coding agent

    Il worm Miasma, attribuito al gruppo TeamPCP, ha colpito le organizzazioni Azure e Microsoft su GitHub, piantando payload nei file di configurazione di Claude Code, Gemini CLI, Cursor e VS Code. GitHub ha disabilitato 73 repository in due ondate automatizzate in soli 105 secondi.

    insicurezzadigitale.com/il-wor

  22. 🛡️ Sicurezza nella Supply Chain, la rotta della geopolitica by Secsolution

    dlvr.it/TSzkwF

    Notizie, Tecnologie, Soluzioni, Approfondimenti, Formazione per i professionisti della security in Italia
    #SovranitaTecnologica #sicurezzaOT #supplychain #protezioneperimetrale #formazioneNormativa

  23. Taiwan taucht in meinem Alltag erstaunlich oft auf.

    Nicht als Schlagzeile. Nicht als Reiseziel.
    Sondern als Teil von Lieferketten, Technologie und Diagnostik. Manchmal reicht ein Blick auf die Herkunft eines einzelnen Bauteils, um zu merken, wie eng unsere Welt inzwischen miteinander verbunden ist.

    #Taiwan #SupplyChain #Tech #AI #Diagnostics #Mastodon

  24. Taiwan taucht in meinem Alltag erstaunlich oft auf.

    Nicht als Schlagzeile. Nicht als Reiseziel.
    Sondern als Teil von Lieferketten, Technologie und Diagnostik. Manchmal reicht ein Blick auf die Herkunft eines einzelnen Bauteils, um zu merken, wie eng unsere Welt inzwischen miteinander verbunden ist.

    #Taiwan #SupplyChain #Tech #AI #Diagnostics #Mastodon

  25. AI agents are now reading code and dependencies at scale, which means the landscape of supply chain risk has officially shifted 🛡️.

    We are diving into why build time matters and how you can add a Snyk scan to your build hook on Upsun to keep things secure.

    It is time to address what these fixes catch and where you still need to keep a watchful eye in this new AI era 💡

    👉 developer.upsun.com/posts/how-

    #CyberSecurity #AI #DevOps #SupplyChain"

  26. AI agents are now reading code and dependencies at scale, which means the landscape of supply chain risk has officially shifted 🛡️.

    We are diving into why build time matters and how you can add a Snyk scan to your build hook on Upsun to keep things secure.

    It is time to address what these fixes catch and where you still need to keep a watchful eye in this new AI era 💡

    👉 developer.upsun.com/posts/how-

    #CyberSecurity #AI #DevOps #SupplyChain"

  27. [#TRADESHOW] #CPHI & #PMEC #China 2026 from June 16 to 18, 2026, at the #Shanghai New #International #Expo #Center (#SNIEC). As #Asia’s leading #pharmaceutical #sourcing and #networking #platform, the #exhibition #event has more than 20 years of experience connecting #Chinese and international #pharma professionals. It serves as a key #meeting point for #innovation, #SupplyChain #collaboration, and #market expansion within the #global pharmaceutical #ecosystem. cnbusinessforum.com/event/cphi

  28. [#TRADESHOW] #CPHI & #PMEC #China 2026 from June 16 to 18, 2026, at the #Shanghai New #International #Expo #Center (#SNIEC). As #Asia’s leading #pharmaceutical #sourcing and #networking #platform, the #exhibition #event has more than 20 years of experience connecting #Chinese and international #pharma professionals. It serves as a key #meeting point for #innovation, #SupplyChain #collaboration, and #market expansion within the #global pharmaceutical #ecosystem. cnbusinessforum.com/event/cphi

  29. Il metallo dell'AI: stagno a +40% in sei mesi e il rally non è finito
    metallirari.com/metallo-ai-sta
    Lo stagno ha guadagnato il 40% in sei mesi in Cina, spinto dalla domanda di server AI e semiconduttori avanzati. Analisi dei fattori di offerta e geopolitica che tengono i prezzi ai massimi storici.
    #stagno #tin #intelligenzaartificiale #AI #materieprime #commodities #semiconduttori #prezzimaterie #metalliindustriali #supplychain #geopolitica #chipAI #metallistrategici

  30. Ich habe festgestellt, dass moderne Diagnostik, KI und Lieferketten viel enger miteinander verbunden sind, als ich dachte.

    Wenn über KI gesprochen wird, reden viele über Modelle. Aber irgendwo dazwischen stehen Fabriken, Stromnetze, Logistik und Menschen. Und erstaunlich oft führt diese Spur irgendwann nach Taiwan.

    #AI #Taiwan #SupplyChain #Tech #DigitalInfrastructure #Mastodon

  31. Supply chain nel mirino: white paper Italsicurezza per aziende e specialisti: La sicurezza della supply chain e’ sempre piu’ centrale per la continuita’ operativa delle imprese. Centri logistici e magazzini rappresentano oggi infrastrutture strategiche,...
    #sicurezza #supplychain #Italsicurezza #systemintegrator #security dlvr.it/TSybXJ