LIVE · cybersecurity feed
Live wire
Critical Flaws Discovered in Belgian eID Software Used by 2 Million PeopleSecurity Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITIONWebmail CSS Attacks Expose a New Risk for AI-Powered Email ToolsMetabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and TokensCVE-2023-38646 · Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
security

Chainloop: Open-source evidence store and policy engine for the software supply chain

Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable storage, and references each one in a signed in-toto attestation. in-toto is a specification for recording who ran which step of a build, so the record can be che

zeroday.news ·

Chainloop is an open-source evidence store and policy engine designed to secure the software supply chain by providing a verifiable record of build artifacts and processes. The system aims to address the challenge of tracking and verifying diverse build outputs, such as software bills of materials (SBOMs), static analysis reports, and container images, which often land in disparate locations without cryptographic links to their originating commits.

The core of Chainloop is a command-line interface (CLI) tool that integrates into continuous integration (CI) pipelines, including GitHub Actions, GitLab, Jenkins, and Dagger. This tool captures build outputs, uploads them to content-addressable storage, and references them within a signed in-toto attestation. In-toto is a specification that records details about who executed each step of a build, enabling subsequent verification of the process.

Compliance and security teams utilize a control plane where all signed attestations and artifacts are collected, regardless of the CI provider. The system enforces "Workflow Contracts," which are declarations defining the required materials, build information, and execution environment for a build. These contracts are authored by security and compliance teams, and Chainloop verifies that artifact creation and attestations adhere to them. Failure to produce a required artifact, such as an SBOM, would result in a contract violation.

Further enhancing policy enforcement, Rego policies, written in the Open Policy Agent language, can be attached to these contracts. These policies are automatically evaluated, and their results are embedded within the attestation before it is signed and stored. This ensures that the verdict on a build's compliance travels with the signed record, preventing later tampering with dashboard-based assessments.

Chainloop offers first-class handling for seventeen named evidence formats, with a broader catalog of supported types. These include CycloneDX and SPDX SBOMs, OpenVEX, four CSAF document types, SARIF, ZAP DAST results, BlackDuck SCA output, PrismaCloud Twistcli scans, GitLab security reports, JUnit results, JaCoCo XML coverage, Helm charts, and container image references. Custom evidence types, such as JSON approval reports, and key-value metadata pairs can also be incorporated.

The system supports flexible signing methods, allowing evidence to be signed via Sigstore or an organization's internal Public Key Infrastructure (PKI), including services like AWS KMS or Keyfactor, which is crucial for organizations with strict key management requirements.

Artifacts and evidence can be routed to OCI registries or cloud blob storage. For analysis, they can be sent to tools like Dependency-Track or Guac for SBOM analysis. Notifications can be integrated with platforms such as Jira, Discord, or Slack. The design ensures that changing the analysis backend does not require modifications to the CI pipeline, as the pipeline only interacts with the crafting tool.

Chainloop is designed to help organizations meet regulatory requirements from frameworks such as FedRamp, the U.S. Executive Order 14028, the EU Cyber Resilience Act, and the Digital Operational Resilience Act. The project provides guides for the Cyber Resilience Act and for SLSA (Supply-chain Levels for Software Artifacts), aiming to satisfy SLSA Level 3 by establishing a single source of truth for build information. A FedRamp guide is also planned.

While the CLI tool defaults to pointing at a hosted Chainloop instance, which sends evidence outside the user's infrastructure, organizations can deploy Chainloop on their own Kubernetes clusters using a Helm chart to keep the control plane in-house. Chainloop is freely available on GitHub.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause

OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity. In response to the discovery, the AI upstart said it's implementing security controls for higher-capability models and associated activities, such as isolated

cloud

Product showcase: Enpass Password Manager breaks away from the proprietary cloud model

Enpass is a password manager that stores passwords, passkeys, payment cards, identities, secure notes, software licenses, and other sensitive information in encrypted vaults. Vaults remain on the device or in a cloud storage service selected by the user. Users who work across multiple devices can install Enpass on Windows, macOS, Linux, Android, and iOS. Browser extensions are available for Chrome

vulnerabilitycritical

Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

The vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies. The post Critical Flaws Discovered in Belgian eID Software Used by 2 Million People appeared first on SecurityWeek.

nation-state

How to report an AI Act violation in the EU

The EU’s fight to regulate AI models entered a new chapter on 2 August 2026, when the European Commission’s AI Office and national authorities began enforcing the AI Act. The AI Act is the EU’s law regulating AI, the first broad legal framework of its kind. It creates a common set of rules for AI systems used or sold in the EU, with the goal of encouraging innovation while protecting people’s safe

phishing

U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data

Defense manufacturer IEH Corporation has disclosed a phishing attack that compromised an employee's Microsoft 365 inbox. The breach, discovered on August 4, potentially exposed sensitive export-controlled military data, customer information, and engineering documents. While no data exfiltration has been confirmed, the incident highlights the risks associated with sophisticated social engineering tactics targeting critical infrastructure suppliers.

malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 109

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums DarkSword’s Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting