Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable storage, and references each one in a signed in-toto attestation. in-toto is a specification for recording who ran which step of a build, so the record can be che

Chainloop is an open-source evidence store and policy engine designed to secure the software supply chain by providing a verifiable record of build artifacts and processes. The system aims to address the challenge of tracking and verifying diverse build outputs, such as software bills of materials (SBOMs), static analysis reports, and container images, which often land in disparate locations without cryptographic links to their originating commits.
The core of Chainloop is a command-line interface (CLI) tool that integrates into continuous integration (CI) pipelines, including GitHub Actions, GitLab, Jenkins, and Dagger. This tool captures build outputs, uploads them to content-addressable storage, and references them within a signed in-toto attestation. In-toto is a specification that records details about who executed each step of a build, enabling subsequent verification of the process.
Compliance and security teams utilize a control plane where all signed attestations and artifacts are collected, regardless of the CI provider. The system enforces "Workflow Contracts," which are declarations defining the required materials, build information, and execution environment for a build. These contracts are authored by security and compliance teams, and Chainloop verifies that artifact creation and attestations adhere to them. Failure to produce a required artifact, such as an SBOM, would result in a contract violation.
Further enhancing policy enforcement, Rego policies, written in the Open Policy Agent language, can be attached to these contracts. These policies are automatically evaluated, and their results are embedded within the attestation before it is signed and stored. This ensures that the verdict on a build's compliance travels with the signed record, preventing later tampering with dashboard-based assessments.
Chainloop offers first-class handling for seventeen named evidence formats, with a broader catalog of supported types. These include CycloneDX and SPDX SBOMs, OpenVEX, four CSAF document types, SARIF, ZAP DAST results, BlackDuck SCA output, PrismaCloud Twistcli scans, GitLab security reports, JUnit results, JaCoCo XML coverage, Helm charts, and container image references. Custom evidence types, such as JSON approval reports, and key-value metadata pairs can also be incorporated.
The system supports flexible signing methods, allowing evidence to be signed via Sigstore or an organization's internal Public Key Infrastructure (PKI), including services like AWS KMS or Keyfactor, which is crucial for organizations with strict key management requirements.
Artifacts and evidence can be routed to OCI registries or cloud blob storage. For analysis, they can be sent to tools like Dependency-Track or Guac for SBOM analysis. Notifications can be integrated with platforms such as Jira, Discord, or Slack. The design ensures that changing the analysis backend does not require modifications to the CI pipeline, as the pipeline only interacts with the crafting tool.
Chainloop is designed to help organizations meet regulatory requirements from frameworks such as FedRamp, the U.S. Executive Order 14028, the EU Cyber Resilience Act, and the Digital Operational Resilience Act. The project provides guides for the Cyber Resilience Act and for SLSA (Supply-chain Levels for Software Artifacts), aiming to satisfy SLSA Level 3 by establishing a single source of truth for build information. A FedRamp guide is also planned.
While the CLI tool defaults to pointing at a hosted Chainloop instance, which sends evidence outside the user's infrastructure, organizations can deploy Chainloop on their own Kubernetes clusters using a Helm chart to keep the control plane in-house. Chainloop is freely available on GitHub.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed