AUTO-UPDATED

TanStack weighs invitation-only pull requests after supply chain attack

The technology sector faces significant challenges as unauthorized AI usage surges, critical security vulnerabilities emerge in software like Drupal, and enterprises navigate complex shifts in hardware and cloud infrastructure.

Key Points

  • Unauthorized "Shadow AI" usage in workplaces has increased fourfold over the past year, raising concerns about proprietary data exposure.
  • Drupal released a critically urgent security patch affecting versions as far back as the 8.9 branch.
  • Airbus secured a five-year HPC-as-a-service contract with Bull to support the development of new aircraft.
  • Microsoft launched its latest Surface for Business lineup, featuring AI-focused Intel processors starting at $1,499.
  • A supply chain attack on npm compromised 314 JavaScript packages, including popular modules like size-sensor and echarts-for-react.

Why it Matters

These developments highlight the growing tension between rapid AI adoption and the necessity for robust enterprise security and governance. Organizations must balance the benefits of new technologies against the risks of shadow IT, supply chain vulnerabilities, and unpredictable operational costs.
Theregister.com Published by Tim Anderson
Read original