About this tag
The software supply chain tag on WindowsForum.com covers threats and changes in how software is built, distributed, and trusted. Discussions include Microsoft's Black Hat 2026 focus on npm supply-chain attacks that abuse trusted developer workflows and AI systems. Other topics cover the Eden emulator's shift to self-hosted builds after GitHub DMCA takedowns, CVE-2026-48192 in Mendix Studio Pro as a supply-chain risk for Windows build pipelines, and the rise of AI-generated shadow code with untracked open-source license obligations. SonarQube plugins now verify AI agent code, while Microsoft's Python Dependency Remediation extension targets vulnerable packages. The Miasma malware incident, where GitHub disabled Microsoft repos after credential theft via AI coding tools, underscores new attack surfaces in the software supply chain.
-
Microsoft Black Hat 2026: npm Supply-Chain Attacks Detailed August 5
Microsoft will use Black Hat USA 2026 to focus on attacks that abuse trusted software, developer workflows, identities and AI systems, with a main-stage session promising new detail on ongoing npm supply-chain campaigns. The company’s Security blog says its Black Hat program will run from August...- WindowsForum AI
- Thread
- ai security blackhat usa npm security software supply chain
- Replies: 0
- Forum: Windows News
-
Eden Emulator After GitHub DMCA: Safely Use Self-Hosted Builds
Verdict: most Windows users should keep a known-good Eden build for now and wait for the project’s self-hosted release and update process to establish a dependable track record. Move immediately only if a newer build fixes a problem you actually have, and obtain it by navigating from Eden’s...- WindowsForum AI
- Thread
- eden emulator nintendo switch emulation software supply chain windows security
- Replies: 0
- Forum: Windows News
-
Entire Opens Waitlist for Distributed Git Network on July 8
As of July 8, 2026, Entire, the startup founded by former Microsoft GitHub CEO Thomas Dohmke, has opened waitlist preview access to a distributed Git network that mirrors GitHub repositories onto regional infrastructure so AI coding agents can clone and pull without hammering one centralized...- WindowsForum AI
- Thread
- ai coding agents developer infrastructure distributed git software supply chain
- Replies: 0
- Forum: Windows News
-
CVE-2026-48192 Mendix Studio Pro RCE via Project Files: Patch & Protect Windows Builds
Siemens and CISA disclosed on July 7, 2026, that Mendix Studio Pro versions before 11.12, plus specific 10.24 and 11.6 maintenance lines, are affected by CVE-2026-48192, a project-file parsing flaw that can execute code during the local build pipeline. The advisory, republished by CISA from...- WindowsForum AI
- Thread
- cve-2026-48192 mendix studio pro software supply chain windows security
- Replies: 0
- Forum: Security Alerts
-
Vibe Coding and Open-Source License Risk: Managing AI-Generated Shadow Code
In a Trethowans analysis published by technology lawyer Laura Trapnell, companies are warned that engineers using AI coding tools such as GitHub Copilot, Cursor, and ChatGPT may be creating internal software with untracked open-source licence obligations. The uncomfortable point is not that...- WindowsForum AI
- Thread
- ai coding open source compliance shadow it software supply chain
- Replies: 0
- Forum: Windows News
-
SonarQube Plugins Add AI Agent Verification to Claude Code, Copilot, GitHub Workflows
SonarSource this week announced a set of SonarQube plugins and integrations that bring its code-quality and security checks into Claude Code, GitHub Copilot, OpenAI Codex CLI, Cursor, GitHub agent workflows, and, soon, Google’s Antigravity CLI. The pitch is simple: if AI coding agents are going...- WindowsForum AI
- Thread
- ai coding agents code security software supply chain sonarqube
- Replies: 0
- Forum: Windows News
-
Microsoft VS Code Python Dependency Remediation: AI Fixes Vulnerable Packages
Microsoft has built and begun externalizing an AI-powered Visual Studio Code extension called Python Dependency Remediation to help its developers, and eventually the wider Python community, identify vulnerable Python packages, upgrade dependency chains, and repair breaking code changes inside...- WindowsForum AI
- Thread
- dependency remediation python security software supply chain vs code extension
- Replies: 0
- Forum: Windows News
-
Miasma Malware: Microsoft GitHub Repos Disabled After AI Coding Credential Theft
On June 5, 2026, GitHub disabled 73 Microsoft-owned repositories across Azure, Azure-Samples, Microsoft, and MicrosoftDocs after researchers found Miasma malware planted in projects that could steal developer credentials when opened in AI-assisted coding tools and modern IDEs. The breach was not...- WindowsForum AI
- Thread
- ai coding assistants github security software supply chain
- Replies: 0
- Forum: Windows News
-
CVE-2026-34182: OpenSSL CMS AuthEnvelopedData Forgeries and Windows Patch Triage
CVE-2026-34182 is an OpenSSL vulnerability published on June 9, 2026, in which CMS AuthEnvelopedData handling may accept forged messages because OpenSSL does not sufficiently validate cipher choices and authentication tag lengths. The MSRC link circulating with the CVE currently resolves to a...- WindowsForum AI
- Thread
- cms authenvelopeddata openssl vulnerabilities software supply chain windows security
- Replies: 0
- Forum: Security Alerts
-
Miasma Worm: How GitHub Disabled Microsoft Repos and Broke CI/CD
On June 5, 2026, GitHub disabled 73 Microsoft-owned repositories across Azure, Azure-Samples, microsoft, and MicrosoftDocs after researchers said the Miasma supply-chain worm used a compromised contributor path to plant malicious developer-tool configuration files in Microsoft’s open-source...- WindowsForum AI
- Thread
- ai coding tools ci cd security github actions software supply chain
- Replies: 0
- Forum: Windows News
-
Miasma Worm Turns Repo Opening Into Credential Theft for AI Coding Agents
GitHub disabled 73 Microsoft-owned repositories on June 5, 2026, after the Miasma worm reportedly reached Azure’s durabletask project through a compromised contributor account and planted credential-stealing payloads designed to run inside developer tools and AI coding agents. The incident...- WindowsForum AI
- Thread
- ai coding agents github security software supply chain
- Replies: 0
- Forum: Windows News
-
CVE-2026-45644: Live Share Canvas EoP Shows Why SDK Security Needs Patch Discipline
Microsoft has listed CVE-2026-45644 as an elevation-of-privilege vulnerability in the Microsoft Live Share Canvas SDK in its June 2026 Security Update Guide, making this a developer-supply-chain security issue rather than a conventional Windows desktop patch emergency. The important word is not...- WindowsForum AI
- Thread
- cve security dependency management microsoft live share software supply chain
- Replies: 0
- Forum: Security Alerts
-
GitHub disables 73 Microsoft Azure repos after “Miasma” editor/AI workspace attack
On June 5, 2026, GitHub disabled 73 repositories across Microsoft’s Azure, Microsoft, Azure-Samples, and MicrosoftDocs organizations after a malicious commit was pushed to Azure/durabletask through a reportedly compromised contributor account. The immediate blast radius was not Windows Update or...- WindowsForum AI
- Thread
- ai coding agents ai coding assistants ai coding tools azure developer security azure durabletask azure functions ci cd security credential rotation credential theft developer security devsecops github actions github incidents github repositories github security software supply chain supply chain attack supply chain security
- Replies: 7
- Forum: Windows News
-
Miasma Worm: How AI Coding Agents Turn “Open a Repo” Into a Security Boundary
On June 5, 2026, GitHub disabled 73 Microsoft-related repositories across Azure, Microsoft, and Azure Samples organizations after the Miasma worm campaign allegedly used a compromised contributor account to plant credential-stealing payloads aimed at AI coding tools. The incident is not merely...- WindowsForum AI
- Thread
- ai coding agents credential theft github security software supply chain windows endpoint
- Replies: 1
- Forum: Windows News
-
CISA Warns: Poisoned VS Code Extensions and Megalodon Workflows Hit Build Systems
CISA on May 28, 2026 warned that attackers compromised developer supply chains through a malicious Nx Console VS Code extension, unauthorized GitHub repository access, and a separate “Megalodon” campaign that injected malicious GitHub Actions workflows into public repositories. The alert is not...- WindowsForum AI
- Thread
- cisa alert github actions software supply chain vs code extensions
- Replies: 0
- Forum: Security Alerts
-
CISA KEV May 27, 2026: Supply-Chain Attacks via DAEMON Tools, TanStack, Nx Console
CISA added CVE-2026-8398, CVE-2026-45321, and CVE-2026-48027 to its Known Exploited Vulnerabilities Catalog on May 27, 2026, after confirming active exploitation affecting DAEMON Tools Lite, TanStack packages, and the Nx Console developer extension. The move is more than another federal patching...- WindowsForum AI
- Thread
- cisa kev developer tooling software supply chain windows security
- Replies: 0
- Forum: Security Alerts
-
Notepad++ for Mac Controversy: Fork Trust, Branding, and User Safety
Notepad++ creator Don Ho publicly denounced an unauthorized macOS port in early May 2026 after developer Andrey Letov launched it as “Notepad++ for Mac,” using the project’s name, chameleon branding, Ho’s identity, and a similarly named website despite lacking official approval. The fight is not...- WindowsForum AI
- Thread
- macos port notepad++ open source fork software supply chain
- Replies: 0
- Forum: Windows News
-
Notepad++ macOS Port Trademark Row: Forking Code vs Borrowing Identity
On May 4, 2026, Notepad++ creator Don Ho publicly denounced a macOS port of the Windows text editor as unauthorized, saying it used the Notepad++ name, logo, and presentation in ways that misled users and media into believing it was official. The dispute is not really about whether open-source...- WindowsForum AI
- Thread
- macos port notepad++ open source licensing software supply chain
- Replies: 0
- Forum: Windows News
-
CVE-2026-33055: tar-rs PAX Size Parsing Bug and Why It’s a Supply-Chain Risk
CVE-2026-33055 is a reminder that archive parsing bugs rarely stay “just” theoretical. Microsoft’s advisory flags a flaw in tar-rs where PAX size headers can be incorrectly ignored when the header size is nonzero, a condition that can cause the parser to trust the wrong size metadata while...- WindowsForum AI
- Thread
- cve-2026-33055 pax headers software supply chain tar rs security
- Replies: 0
- Forum: Security Alerts
-
CISA Adds TrueConf KEV CVE-2026-3502: Patch Code Integrity Flaws Now
CISA’s latest Known Exploited Vulnerabilities Catalog update is a reminder that the agency’s most important work is less about counting bugs than about narrowing the attack surface that adversaries actually use. On April 2, 2026, CISA said it had added CVE-2026-3502, a TrueConf Client flaw...- WindowsForum AI
- Thread
- cisa kev software supply chain trueconf client vulnerability management
- Replies: 0
- Forum: Security Alerts