SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers

SCA stories

Flux result cef25112 fd4e 4c59 aae1 c1a8e25ed2cc

payabl. launches Visa Click to Pay for European merchants

Yesterday
#
fintech
#
cx
#
martech
payabl. adds Visa Click to Pay across Europe, aiming to cut checkout friction, lift authorisations and reduce fraud for merchants.
Flux result 20e12820 27f4 4e8a 9da9 1c2ee2ea902d

Sonatype warns of surge in trusted open-source malware

3 days ago
#
application security
#
devsecops
#
supply chain
Sonatype flags 21,764 malicious open-source packages in Q1 2026, with npm hit hardest as attackers used trusted workflows to steal secrets.
Flux result a551e609 c277 41e0 a40d 9441732a3040

Cloudsmith survey finds SBOM gaps before cyber law

Last week
#
devops
#
cloud security
#
application security
Cloudsmith survey finds most engineering teams still lack automated SBOM checks, leaving many unready for fast EU Cyber Resilience Act audits.
Flux result 2134aca4 e1cc 446a 8945 80553175f1f3

Malware surge in open source software alarms firms

This month
#
malware
#
devops
#
application security
Open source malware advisories jumped in 2025 as Endor Labs warned that firms are under-prepared and budgets lag the threat.
Flux result 86c5d3ff 8544 4b88 ac41 93781b8158bc

AppOmni adds Heisenberg mode after LiteLLM supply attack

Last month
#
virtualisation
#
cloud security
#
application security
AppOmni upgrades Heisenberg to help teams trace GitHub Actions and spot tainted dependencies after the LiteLLM supply chain breach.
Flux result 0b725e6f 488f 44c4 b57e 5c23a2bc516f

NetRise launches Provenance to trace open source risk

Last month
#
devops
#
iot security
#
iot
NetRise unveils Provenance, a tool to trace open source maintainers and stop risky dependencies before they spread through software.
Noel

Fime gains EMVCo recognition for biometric card tests

Last month
#
biometrics
#
fintech
#
iam
Fime's EMEA lab wins EMVCo nod to test fingerprint sensors for biometric cards, supporting global roll-out of trusted contactless payments.
Software engineer reviewing branching dependency tree upgrade success green

Sonatype finds live data beats larger AI models on upgrades

Last month
#
devops
#
application security
#
supply chain
Sonatype says smaller AI tied to live software data can outsecure larger models on dependency upgrades, slashing risk and cost.
Editorial software dev code review open source supply chain shield repair vulnerable deps

Veracode launches Fix for open-source vulnerability repair

Last month
#
devops
#
application security
#
devsecops
Veracode unveils an AI-driven tool that automatically fixes open-source vulnerabilities, tackling mounting security debt in software supply chains.
Secure ai dev pipeline centralized governance monitoring icons

Backslash adds cross-tool governance for AI coding Skills

Last month
#
cloud security
#
application security
#
advanced persistent threat protection
Backslash adds cross-tool governance to discover, vet and monitor 'Skills' powering AI coding assistants like Cursor, Claude Code and Copilot.
Sam french

Token.io unveils Account on File to streamline Pay by Bank

Last month
#
data protection
#
fintech
#
cx
Token.io launches Account on File to make Pay by Bank a near one-tap checkout, cutting steps and boosting conversion for UK and EU merchants.
Secure ai software engineer workstation multi screens cinematic night

Harness unveils AI Security & coding tools for DevSecOps

Last month
#
devops
#
application security
#
advanced persistent threat protection
Harness has launched AI Security and Secure AI Coding tools to spot and block vulnerabilities in AI-powered apps and AI-generated code.
Eu digital identity wallet smartphone secure shield circuit stars

Ditto unveils cryptographic digital ID platform for EU

Last month
#
malware
#
data protection
#
digital transformation
Ditto launches cryptographic digital ID platform for EU, promising reusable wallet-based identities and less personal data exposure.
Secure datacenter with shielded servers and vetted oss packages flow

ActiveState unveils Curated Catalog for safer code

Last month
#
application security
#
devsecops
#
supply chain
ActiveState launches Curated Catalog, a private, pre-vetted open source repository to tighten software supply chain security for enterprises.
Sleek fintech trophy golden emblems dark stage london skyline

Ecommpay scoops dual FSTech Awards for fraud & access

Last month
#
fintech
#
risk & compliance
#
payment technologies
Ecommpay clinches Anti-fraud Solution and Financial Inclusion titles at the FSTech Awards 2026, underscoring its payments innovation.
Embedded circuit board to document stack symbolizing software bom

Manifest tool boosts SBOMs for critical C & C++ code

Last month
#
application security
#
cartech
#
devsecops
Manifest unveils SBOM generator for unmanaged C and C++ code, tackling critical supply chain blind spots in embedded and safety systems.
Airplane over world map global travel payments vector illustration

RateGain & Juspay launch RG Pay for travel payments

Last month
#
saas
#
digital transformation
#
fintech
RateGain and Juspay unveil RG Pay, an embedded payments layer to boost cross-border checkout performance for global travel brands.
Smartphone banking login fraud detection shadowy hand warning

BioCatch unveils DeviceIQ to spot banking fraud pre-login

Last month
#
biometrics
#
mfa
#
fintech
BioCatch launches DeviceIQ to scan mobile and web devices before login, spotting AI-driven fraud and compromised handsets in milliseconds.
Abby kearns

ActiveState names Abby Kearns as new Chief Executive

Last month
#
digital transformation
#
application security
#
it automation
ActiveState appoints seasoned open source leader Abby Kearns as Chief Executive, sharpening its focus on managed open source security.
Smartphone layered translucent shields spiral threat icons

Appdome unveils Threat-Memory to track repeated attacks

Last month
#
malware
#
endpoint protection
#
application security
Appdome's new Threat-Memory tool stores on-device threat histories and AI scores to counter repeat mobile fraud and account takeovers.