<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Supply Chain Risk</title><description>Cybersecurity articles tagged #Supply Chain Risk on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Cybersecurity Affordability Crisis: Impact on Small Businesses</title><link>https://runtimerebel.com/blog/cybersecurity-affordability-crisis-impact-on-small-businesses</link><guid isPermaLink="true">https://runtimerebel.com/blog/cybersecurity-affordability-crisis-impact-on-small-businesses</guid><description>Rising breach costs and defense spending strain budgets, leaving small businesses dangerously exposed and elevating supply chain risks.</description><pubDate>Tue, 25 Aug 2026 16:27:51 GMT</pubDate><category>Supply Chain Risk</category><category>Risk Management</category><category>Cybersecurity Economics</category><category>Small Business Security</category><category>Data Breach Costs</category></item><item><title>AI Coding Accelerates Open Source Risk and Remediation Debt</title><link>https://runtimerebel.com/blog/ai-coding-accelerates-open-source-risk-and-remediation-debt</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-coding-accelerates-open-source-risk-and-remediation-debt</guid><description>AI coding tools introduce open-source dependencies faster than security teams can manage, creating &quot;remediation debt&quot; that impacts enterprise security.</description><pubDate>Tue, 25 Aug 2026 00:40:34 GMT</pubDate><category>Open Source Security</category><category>Supply Chain Risk</category><category>Enterprise Security</category><category>AI Coding</category><category>Remediation Debt</category></item><item><title>PurpleDelta: North Korean IT Workers Exploit Remote Hiring</title><link>https://runtimerebel.com/blog/purpledelta-north-korean-it-workers-exploit-remote-hiring</link><guid isPermaLink="true">https://runtimerebel.com/blog/purpledelta-north-korean-it-workers-exploit-remote-hiring</guid><description>Recorded Future exposes PurpleDelta, North Korean IT workers using sophisticated fraudulent employment, AI, and extensive vetting evasion to fund DPRK military programs.</description><pubDate>Tue, 18 Aug 2026 16:25:57 GMT</pubDate><category>North Korea</category><category>State Sponsored</category><category>Supply Chain Risk</category><category>PurpleDelta</category><category>Fraudulent Employment</category></item><item><title>China Military Bans Top Cybersecurity Firms for Procurement Violations</title><link>https://runtimerebel.com/blog/china-military-bans-top-cybersecurity-firms-for-procurement-violations</link><guid isPermaLink="true">https://runtimerebel.com/blog/china-military-bans-top-cybersecurity-firms-for-procurement-violations</guid><description>Major Chinese firms like Qi-An-Xin and Sangfor face PLA procurement bans due to integrity violations, impacting China’s domestic cybersecurity landscape.</description><pubDate>Thu, 16 Jul 2026 10:14:07 GMT</pubDate><category>China</category><category>PLA</category><category>Qi an Xin</category><category>Sangfor</category><category>Supply Chain Risk</category><category>Military Procurement</category></item><item><title>Klue Security Incident: Analyzing Third-Party Supply Chain Impact</title><link>https://runtimerebel.com/blog/klue-security-incident-analyzing-third-party-supply-chain-impact</link><guid isPermaLink="true">https://runtimerebel.com/blog/klue-security-incident-analyzing-third-party-supply-chain-impact</guid><description>An analysis of the Klue security incident affecting Recorded Future, highlighting the risks of third-party SaaS vendors and competitive intelligence data.</description><pubDate>Tue, 14 Jul 2026 06:12:08 GMT</pubDate><category>Klue</category><category>Recorded Future</category><category>Supply Chain Risk</category><category>SaaS Security</category><category>Third Party Breach</category></item><item><title>Zero-Day Acquisition Firm Raises Red Flags: Trust and Supply Chain Risks</title><link>https://runtimerebel.com/blog/zero-day-acquisition-firm-raises-red-flags-trust-and-supply-chain-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/zero-day-acquisition-firm-raises-red-flags-trust-and-supply-chain-risks</guid><description>A cybersecurity startup offering millions for zero-days is operated by convicted felons. This raises concerns about vulnerability integrity and supply chain risks.</description><pubDate>Wed, 08 Jul 2026 14:16:54 GMT</pubDate><category>Zero-Day</category><category>Vulnerability Acquisition</category><category>Threat Intel Integrity</category><category>Supply Chain Risk</category></item><item><title>AI-Generated Workflows: Hidden Vulnerabilities &amp; Control Gaps</title><link>https://runtimerebel.com/blog/ai-generated-workflows-hidden-vulnerabilities-control-gaps</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-generated-workflows-hidden-vulnerabilities-control-gaps</guid><description>Explore the silent security disaster of AI-generated workflows. Understand hidden vulnerabilities, control gaps, and the critical need for human oversight in AI-driven…</description><pubDate>Tue, 30 Jun 2026 16:49:06 GMT</pubDate><category>AI Security</category><category>Workflow Automation</category><category>Shadow IT</category><category>Supply Chain Risk</category><category>Developer Security</category></item><item><title>AI Agent Skill Security Bypass: Fake Skill Reached 26,000 Agents</title><link>https://runtimerebel.com/blog/ai-agent-skill-security-bypass-fake-skill-reached-26000-agents</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agent-skill-security-bypass-fake-skill-reached-26000-agents</guid><description>A security firm demonstrated how a fake AI agent skill bypassed marketplace security scans, reaching 26,000 agents, including corporate accounts, highlighting critical…</description><pubDate>Tue, 23 Jun 2026 20:54:30 GMT</pubDate><category>AI Agent Skill</category><category>Security Bypass</category><category>Marketplace Security</category><category>Supply Chain Risk</category><category>AIR</category></item><item><title>Trellix Source Code Breach: Assessing Risk to Security Products</title><link>https://runtimerebel.com/blog/trellix-source-code-breach-assessing-risk-to-security-products</link><guid isPermaLink="true">https://runtimerebel.com/blog/trellix-source-code-breach-assessing-risk-to-security-products</guid><description>Trellix confirms unauthorized access to a portion of its source code repositories, raising concerns regarding potential downstream supply chain risks.</description><pubDate>Sat, 02 May 2026 08:36:24 GMT</pubDate><category>Trellix</category><category>Source Code Breach</category><category>Supply Chain Risk</category><category>Repository Security</category></item><item><title>FBI Alert: Hacker-Enabled Cargo Theft Surges via Broker Impersonation</title><link>https://runtimerebel.com/blog/fbi-alert-hacker-enabled-cargo-theft-surges-via-broker-impersonation</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-alert-hacker-enabled-cargo-theft-surges-via-broker-impersonation</guid><description>The FBI warns of sophisticated cyber-physical cargo theft operations where hackers compromise shipping brokers and carriers to redirect high-value shipments.</description><pubDate>Fri, 01 May 2026 08:46:25 GMT</pubDate><category>Fbi Alert</category><category>Cargo Theft</category><category>Business Email Compromise</category><category>Logistics Security</category><category>Supply Chain Risk</category></item><item><title>Beyond Code Security: Managing Your Expanding Attack Surface</title><link>https://runtimerebel.com/blog/beyond-code-security-managing-your-expanding-attack-surface</link><guid isPermaLink="true">https://runtimerebel.com/blog/beyond-code-security-managing-your-expanding-attack-surface</guid><description>Organizations often overlook security gaps in shadow IT, SaaS, and AI agents. Learn to manage an expanding attack surface beyond just secure code.</description><pubDate>Fri, 24 Apr 2026 16:29:42 GMT</pubDate><category>Shadow IT</category><category>SaaS Security</category><category>Attack Surface Management</category><category>Cloud Security</category><category>AI Security</category><category>Supply Chain Risk</category></item><item><title>Microsoft Developer Account Suspensions Block OSS Security Patches</title><link>https://runtimerebel.com/blog/microsoft-developer-account-suspensions-block-oss-security-patches</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-developer-account-suspensions-block-oss-security-patches</guid><description>Microsoft&apos;s suspension of high-profile open-source developer accounts disrupts security patch delivery and introduces significant supply chain risks for Windows.</description><pubDate>Thu, 09 Apr 2026 08:38:53 GMT</pubDate><category>Microsoft Partner Center</category><category>Open Source Security</category><category>Software Signing</category><category>Supply Chain Risk</category><category>Windows Development</category></item><item><title>FBI Warning: Assessing Data Security Risks of Chinese Mobile Applications</title><link>https://runtimerebel.com/blog/fbi-warning-assessing-data-security-risks-of-chinese-mobile-applications</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-warning-assessing-data-security-risks-of-chinese-mobile-applications</guid><description>The FBI warns against data security risks associated with foreign-developed mobile applications, particularly Chinese apps, due to potential data exfiltration.</description><pubDate>Wed, 01 Apr 2026 12:27:27 GMT</pubDate><category>Mobile Security</category><category>Data Privacy</category><category>FBI Warning</category><category>Data Exfiltration</category><category>China</category><category>Supply Chain Risk</category></item><item><title>Navia Benefit Solutions Breach Exposes HackerOne Employee PII</title><link>https://runtimerebel.com/blog/navia-benefit-solutions-breach-exposes-hackerone-employee-pii</link><guid isPermaLink="true">https://runtimerebel.com/blog/navia-benefit-solutions-breach-exposes-hackerone-employee-pii</guid><description>HackerOne confirms 519 employees&apos; PII was exposed in a third-party breach at Navia Benefit Solutions. Analysis of supply chain risks and mitigation steps.</description><pubDate>Wed, 25 Mar 2026 08:20:57 GMT</pubDate><category>HackerOne</category><category>Navia Benefit Solutions</category><category>PII Theft</category><category>Supply Chain Risk</category><category>Third Party Breach</category></item><item><title>FCC Bans Foreign-Made Routers Over National Security Concerns</title><link>https://runtimerebel.com/blog/fcc-bans-foreign-made-routers-over-national-security-concerns</link><guid isPermaLink="true">https://runtimerebel.com/blog/fcc-bans-foreign-made-routers-over-national-security-concerns</guid><description>The FCC has prohibited the importation of new foreign-made routers to mitigate supply chain risks and protect critical communication infrastructure from adversaries.</description><pubDate>Wed, 25 Mar 2026 08:20:11 GMT</pubDate><category>FCC</category><category>Router Security</category><category>Supply Chain Risk</category><category>National Security</category><category>Hardware Security</category></item><item><title>Security Platform Consolidation: Strategies for Mid-Market Resilience</title><link>https://runtimerebel.com/blog/security-platform-consolidation-strategies-for-mid-market-resilience</link><guid isPermaLink="true">https://runtimerebel.com/blog/security-platform-consolidation-strategies-for-mid-market-resilience</guid><description>Explore how mid-market organizations leverage security platform consolidation to mitigate supply chain risks and meet enterprise-level compliance standards.</description><pubDate>Mon, 09 Mar 2026 12:18:08 GMT</pubDate><category>Mid Market Security</category><category>Platform Consolidation</category><category>Supply Chain Risk</category><category>Business Resilience</category><category>XDR</category></item><item><title>Pentagon Designates Anthropic as AI Supply Chain Risk</title><link>https://runtimerebel.com/blog/pentagon-designates-anthropic-as-ai-supply-chain-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/pentagon-designates-anthropic-as-ai-supply-chain-risk</guid><description>The Pentagon designated Anthropic a supply chain risk following disputes over Claude AI usage policies regarding autonomous weapons and mass surveillance.</description><pubDate>Sat, 28 Feb 2026 08:10:05 GMT</pubDate><category>Anthropic</category><category>Claude AI</category><category>Pentagon</category><category>Supply Chain Risk</category><category>Autonomous Weapons</category><category>Mass Surveillance</category></item><item><title>Federal Directive Mandates Phase-Out of Anthropic AI from U.S. Agencies</title><link>https://runtimerebel.com/blog/federal-directive-mandates-phase-out-of-anthropic-ai-from-u-s-agencies</link><guid isPermaLink="true">https://runtimerebel.com/blog/federal-directive-mandates-phase-out-of-anthropic-ai-from-u-s-agencies</guid><description>All U.S. federal agencies must discontinue Anthropic technology, impacting AI supply chains while OpenAI, Google, and xAI maintain their government contracts.</description><pubDate>Sat, 28 Feb 2026 00:30:48 GMT</pubDate><category>Anthropic</category><category>Federal Government</category><category>AI Security</category><category>Supply Chain Risk</category><category>Claude</category><category>National Security</category></item><item><title>UFP Technologies Data Breach Exposes Sensitive Personal Information</title><link>https://runtimerebel.com/blog/ufp-technologies-data-breach-exposes-sensitive-personal-information</link><guid isPermaLink="true">https://runtimerebel.com/blog/ufp-technologies-data-breach-exposes-sensitive-personal-information</guid><description>Medical device manufacturer UFP Technologies confirms a February 2024 cyberattack led to the theft of Social Security numbers and personal data.</description><pubDate>Thu, 26 Feb 2026 00:32:54 GMT</pubDate><category>Ufp Technologies</category><category>Medical Device Security</category><category>Data Breach</category><category>Social Security Numbers</category><category>Supply Chain Risk</category></item></channel></rss>