[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDA8NFh4NtdFITP7X1gypzikqlDxcLAyMrFCKtW3jd3s":3},{"article":4,"iocs":43},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":23,"category":24,"article_tags":27},"6b6ed317-4b0d-426a-9489-40b6e4e8a59a","When AppSec Scanners Become a Supply Chain Attack Vector","when-appsec-scanners-become-a-supply-chain-attack-vector-fbaca3","New research shows how security scanners embedded in the software supply chain can be attacked to serve as a foothold for downstream attacks.","Researchers have discovered that application security (AppSec) scanners, commonly embedded in CI\u002FCD pipelines and the software supply chain, can be compromised and weaponized to attack downstream targets. These scanners, intended to detect vulnerabilities, become attack vectors when exploited, allowing threat actors to inject malicious code or gain access to dependent systems. This represents a critical blind spot in supply chain security where trust in security tooling itself becomes a vulnerability.","Security scanners in software supply chain found vulnerable to attacks serving as downstream exploit vectors.",null,"https:\u002F\u002Fwww.darkreading.com\u002Fapplication-security\u002Fwhen-appsec-scanners-become-supply-chain-attack-vector","https:\u002F\u002Feu-images.contentstack.com\u002Fv3\u002Fassets\u002Fblt6d90778a997de1cd\u002Fblte3ee632c446d5f42\u002F6a6a3d1bf118fd682ddbc4c8\u002Fsupplychain_IncrediVFX_shutterstock.jpg?width=720&quality=80&disable=upscale","2026-07-29T17:06:52+00:00","2026-07-29T18:00:07.564646+00:00",8,[18,21],{"name":19,"type":20},"AppSec Scanners","technology",{"name":22,"type":20},"CI\u002FCD Pipelines","26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":23,"icon":11,"name":25,"slug":26},"Supply Chain","supply-chain",[28,33,38],{"category":29},{"id":30,"icon":11,"name":31,"slug":32},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":34},{"id":35,"icon":11,"name":36,"slug":37},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":39},{"id":40,"icon":11,"name":41,"slug":42},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]