Organizations are moving beyond traditional vulnerability management and treating software transparency as a core security requirement, with Software Bills of Materials (SBOMs) becoming central to software supply chain defense. Reporting on preparations for the EU Cyber Resilience Act (CRA) says manufacturers of products with digital elements will be required to create, maintain, and when necessary provide inventories of software components, driving broader adoption of SBOM tooling and automation. The shift is intended to improve visibility into open-source libraries and third-party dependencies so teams can identify vulnerable packages, assess supplier risk, and respond faster to newly disclosed flaws.
Security practitioners are also pushing companies to use SBOMs as an operational tool rather than a compliance document. Group-IB researcher Anastasia Tikhonova said organizations should apply SBOM data continuously for vulnerability triage, vendor access reviews, identity monitoring, and incident response, as modern supply chain attacks increasingly link phishing, ransomware, and data breaches through inherited trust relationships. She warned that attackers’ use of AI is compressing attack timelines from weeks to minutes, increasing the need to prioritize exposed systems, define compromise windows, contain stolen credentials, and score vendor risk by access level and potential blast radius.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The referenced coverage says the EU Cyber Resilience Act will require manufacturers of products with digital elements to create, maintain, and when necessary provide inventories of software components. The article identifies this requirement as a driver of broader software transparency efforts.
In a Help Net Security video, Group-IB researcher Anastasia Tikhonova says organizations should use SBOMs continuously for vulnerability triage, vendor access reviews, identity monitoring, and incident response rather than only for compliance. She also describes practical response steps and warns that attackers' use of AI is compressing attack timelines.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.