<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Software Supply Chain</title><description>Cybersecurity articles tagged #Software Supply Chain on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Python Supply Chain: Malicious Packages Targeting Developers</title><link>https://runtimerebel.com/blog/python-supply-chain-malicious-packages-targeting-developers</link><guid isPermaLink="true">https://runtimerebel.com/blog/python-supply-chain-malicious-packages-targeting-developers</guid><description>Malicious Python packages exploit trusted ecosystems like PyPI, enabling supply chain attacks on developer systems. Learn about the threat and mitigation.</description><pubDate>Sun, 09 Aug 2026 00:59:54 GMT</pubDate><category>Python</category><category>Supply Chain Attack</category><category>PyPI</category><category>Malware</category><category>Software Supply Chain</category></item><item><title>AI&apos;s Transformative Impact on Threat Intelligence and Defenses</title><link>https://runtimerebel.com/blog/ai-s-transformative-impact-on-threat-intelligence-and-defenses</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-s-transformative-impact-on-threat-intelligence-and-defenses</guid><description>AI is rapidly accelerating the threat landscape, enabling machine-speed attacks and increasing defender challenges. Prioritizing intelligence is key.</description><pubDate>Fri, 07 Aug 2026 02:15:12 GMT</pubDate><category>AI</category><category>Threat Intelligence</category><category>Attack Surface</category><category>Zero Trust</category><category>Software Supply Chain</category></item><item><title>CISA&apos;s Updated SBOM Guidance: Enhancing Software Supply Chain Transparency</title><link>https://runtimerebel.com/blog/cisa-s-updated-sbom-guidance-enhancing-software-supply-chain-transparency</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-s-updated-sbom-guidance-enhancing-software-supply-chain-transparency</guid><description>CISA has released updated SBOM guidance, refining field definitions for greater software supply chain transparency. Debate continues on its impact on risk management.</description><pubDate>Sat, 01 Aug 2026 10:01:00 GMT</pubDate><category>SBOM</category><category>CISA</category><category>Software Supply Chain</category><category>Guidance</category><category>Cybersecurity Policy</category></item><item><title>GitHub Adjusts Bug Bounty: Impact on Vulnerability Disclosure</title><link>https://runtimerebel.com/blog/github-adjusts-bug-bounty-impact-on-vulnerability-disclosure</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-adjusts-bug-bounty-impact-on-vulnerability-disclosure</guid><description>GitHub is halving public bug bounty payouts and shifting top rewards to an invite-only VIP program, impacting vulnerability research and disclosure.</description><pubDate>Wed, 22 Jul 2026 21:11:24 GMT</pubDate><category>GitHub</category><category>Bug Bounty</category><category>Vulnerability Disclosure</category><category>Security Research</category><category>Software Supply Chain</category></item><item><title>FakeGit Campaign Exploits GitHub for SmartLoader Malware</title><link>https://runtimerebel.com/blog/fakegit-campaign-exploits-github-for-smartloader-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/fakegit-campaign-exploits-github-for-smartloader-malware</guid><description>Analysis of the FakeGit campaign leveraging 7,600 GitHub repositories, including AI/MCP lures, to distribute SmartLoader malware. Learn detection and mitigation.</description><pubDate>Mon, 20 Jul 2026 21:13:10 GMT</pubDate><category>FakeGit</category><category>SmartLoader</category><category>GitHub</category><category>Malware</category><category>Supply Chain Attack</category><category>Social Engineering</category><category>Software Supply Chain</category></item><item><title>AI-Assisted Vulnerability Management: Operational Guardrails &amp; Risks</title><link>https://runtimerebel.com/blog/ai-assisted-vulnerability-management-operational-guardrails-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-assisted-vulnerability-management-operational-guardrails-risks</guid><description>Implement robust guardrails for AI-assisted vulnerability management. Learn to safely deploy LLM agents, reduce architectural risks, and prioritize human-led threat…</description><pubDate>Thu, 16 Jul 2026 17:25:07 GMT</pubDate><category>AI</category><category>LLM</category><category>Vulnerability Management</category><category>SAIF</category><category>NIST AI RMF</category><category>OWASP Top 10 for LLMs</category><category>Mandiant</category><category>Risk Based Vulnerability Management</category><category>Zero Trust</category><category>Software Supply Chain</category><category>SAST</category><category>DAST</category><category>Red Teaming</category></item><item><title>Linux Foundation&apos;s Project Akrites: Bolstering Open Source Security</title><link>https://runtimerebel.com/blog/linux-foundation-s-project-akrites-bolstering-open-source-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/linux-foundation-s-project-akrites-bolstering-open-source-security</guid><description>Project Akrites aims to streamline vulnerability management across open source projects, enhancing reporting, patching, and disclosure processes for critical software.</description><pubDate>Fri, 26 Jun 2026 12:52:09 GMT</pubDate><category>Linux Foundation</category><category>Akrites</category><category>Open Source Security</category><category>Vulnerability Management</category><category>Software Supply Chain</category></item><item><title>RevEng.AI Secures $15M for AI-Powered Software Binary Analysis</title><link>https://runtimerebel.com/blog/reveng-ai-secures-15m-for-ai-powered-software-binary-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/reveng-ai-secures-15m-for-ai-powered-software-binary-analysis</guid><description>RevEng.AI raises $15 million to scale BinNet, a proprietary AI model designed to automate binary analysis and detect hidden backdoors in software assets.</description><pubDate>Wed, 27 May 2026 13:22:57 GMT</pubDate><category>RevEng AI</category><category>BinNet</category><category>Binary Analysis</category><category>Software Supply Chain</category><category>Vulnerability Research</category></item><item><title>TrapDoor Campaign: Detecting Cross-Ecosystem Supply Chain Attacks</title><link>https://runtimerebel.com/blog/trapdoor-campaign-detecting-cross-ecosystem-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/trapdoor-campaign-detecting-cross-ecosystem-supply-chain-attacks</guid><description>The TrapDoor campaign targets npm, PyPI, and Crates.io with over 384 malicious versions designed to exfiltrate developer credentials and sensitive data.</description><pubDate>Mon, 25 May 2026 09:28:16 GMT</pubDate><category>Trapdoor</category><category>NPM</category><category>PyPI</category><category>Crates Io</category><category>Credential Theft</category><category>Software Supply Chain</category></item><item><title>Software Supply Chain Security: Addressing Visibility Gaps</title><link>https://runtimerebel.com/blog/software-supply-chain-security-addressing-visibility-gaps</link><guid isPermaLink="true">https://runtimerebel.com/blog/software-supply-chain-security-addressing-visibility-gaps</guid><description>An analysis of the growing software supply chain crisis, focusing on the acceleration of vulnerability exploitation and the lack of systemic visibility.</description><pubDate>Thu, 21 May 2026 09:16:05 GMT</pubDate><category>Software Supply Chain</category><category>Vulnerability Management</category><category>SBOM</category><category>Application Security</category></item><item><title>Compromised Checkmarx Jenkins Plugin Spreads Infostealer</title><link>https://runtimerebel.com/blog/compromised-checkmarx-jenkins-plugin-spreads-infostealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/compromised-checkmarx-jenkins-plugin-spreads-infostealer</guid><description>Official Checkmarx Jenkins AST plugin version 2023.2.7 was compromised with an infostealer, risking credentials and system data.</description><pubDate>Tue, 12 May 2026 00:48:58 GMT</pubDate><category>Checkmarx AST</category><category>Jenkins</category><category>Infostealer</category><category>Supply Chain Attack</category><category>Software Supply Chain</category><category>Plugin Compromise</category><category>Credential Theft</category></item><item><title>DPRK&apos;s &apos;Contagious Interview&apos; Spreads RATs via Dev Repositories</title><link>https://runtimerebel.com/blog/dprk-s-contagious-interview-spreads-rats-via-dev-repositories</link><guid isPermaLink="true">https://runtimerebel.com/blog/dprk-s-contagious-interview-spreads-rats-via-dev-repositories</guid><description>DPRK threat actors are employing a &apos;contagious interview&apos; scam, weaponizing compromised developer repositories to propagate RATs and malware across the software supply…</description><pubDate>Wed, 22 Apr 2026 20:27:05 GMT</pubDate><category>DPRK</category><category>Lazarus Group</category><category>Fake Job Scam</category><category>RAT</category><category>Software Supply Chain</category><category>Social Engineering</category><category>Developer Compromise</category></item><item><title>AI&apos;s Impact on Software Supply Chain Security and Vulnerability Management</title><link>https://runtimerebel.com/blog/ai-s-impact-on-software-supply-chain-security-and-vulnerability-management</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-s-impact-on-software-supply-chain-security-and-vulnerability-management</guid><description>AI is set to revolutionize software development, enabling &apos;instant software&apos; and advanced vulnerability detection, profoundly reshaping future cybersecurity strategies.</description><pubDate>Tue, 07 Apr 2026 20:20:49 GMT</pubDate><category>AI</category><category>Instant Software</category><category>Software Supply Chain</category><category>Vulnerability Management</category><category>Future Threats</category><category>Automated Security</category></item><item><title>Risks of AI-Driven Dependency Resolution and Software Maintenance</title><link>https://runtimerebel.com/blog/risks-of-ai-driven-dependency-resolution-and-software-maintenance</link><guid isPermaLink="true">https://runtimerebel.com/blog/risks-of-ai-driven-dependency-resolution-and-software-maintenance</guid><description>AI models often hallucinate version numbers and ignore security fixes during dependency resolution, increasing technical debt and supply chain risks.</description><pubDate>Thu, 26 Mar 2026 16:33:53 GMT</pubDate><category>Artificial Intelligence</category><category>Dependency Management</category><category>Technical Debt</category><category>Software Supply Chain</category><category>Llm Hallucinations</category></item><item><title>InstallFix Attacks: Malvertising Spreads Fake Claude AI Code</title><link>https://runtimerebel.com/blog/installfix-attacks-malvertising-spreads-fake-claude-ai-code</link><guid isPermaLink="true">https://runtimerebel.com/blog/installfix-attacks-malvertising-spreads-fake-claude-ai-code</guid><description>InstallFix attacks leverage malvertising and ClickFix-style techniques to spread fake Claude AI code, targeting users of coding assistants and CLI operations.</description><pubDate>Tue, 10 Mar 2026 00:32:56 GMT</pubDate><category>InstallFix</category><category>Malvertising</category><category>AI Security</category><category>Claude AI</category><category>Social Engineering</category><category>Software Supply Chain</category></item><item><title>AI Code Generation Poses Supply Chain Risk to Developer Machines</title><link>https://runtimerebel.com/blog/ai-code-generation-poses-supply-chain-risk-to-developer-machines</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-code-generation-poses-supply-chain-risk-to-developer-machines</guid><description>Learn how AI-generated code, like from Anthropic&apos;s Claude, can introduce vulnerabilities and malicious payloads, compromising developer machines and software supply…</description><pubDate>Thu, 26 Feb 2026 00:34:32 GMT</pubDate><category>AI Security</category><category>Software Supply Chain</category><category>Developer Security</category><category>Code Generation</category><category>Anthropic Claude</category><category>Malicious Code</category></item></channel></rss>