Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Survey Surfaces Uneven Adoption of SBOMs to Secure Software

A survey of 100 security professionals indicates that nearly half (48%) of organizations are not meeting Software Bill of Materials (SBOM) requirements as outlined by the U.S. Office of Management and Budget (OMB) Memo M-22-18, Executive Order 14028, and…

A survey of 100 security professionals indicates that nearly half (48%) of organizations are not meeting Software Bill of Materials (SBOM) requirements as outlined by the U.S. Office of Management and Budget (OMB) Memo M-22-18, Executive Order 14028, and the European Union (EU) Cyber Resilience Act.

47% have not started SBOM integration or are still evaluating tools and practices. Over a third struggle with accurately identifying and tracking open-source components. 29% lack tools and processes to analyze SBOMs for vulnerabilities. Only 38% prioritize fixing the most vulnerable application areas. 88% expect AI to enhance software supply chain security visibility significantly. 35% are aware of AI-related data security and privacy risks. 26% acknowledge potential vulnerabilities in AI-generated code.

Lineaje CISO Nick Mistry noted that AI can facilitate the identification of available fixes for vulnerabilities. However, AI also poses risks, such as the potential for creating exploits for known vulnerabilities, which may increase the number of exploitable vulnerabilities.

Office of Management and Budget (OMB) Memo M-22-18, Executive Order 14028, and the European Union (EU) Cyber Resilience Act.
Leo Underwood · Thehackingpost

AI can experience hallucinations, referencing non-existent software packages, which cybercriminals may exploit by creating similarly named malicious packages.

32% of respondents believe their organization will eventually produce software with no vulnerabilities, while 68% are uncertain. Mistry emphasized that secure application development depends on effective processes, which are currently flawed. Vulnerability lists are often extensive and inefficiently managed.

Advertisement

70% of respondents admit to lacking alternative remediation plans when fixes are unavailable. Mistry stressed the need for a unified view of vulnerabilities to enhance collaboration between cybersecurity and application development teams.

Based on reporting by devops.com.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories