Security leadership-focused reporting highlighted rising concern over third-party and software supply chain risk, with a Panorays survey of 200 US CISOs reporting that 60% observed an increase in third-party security incidents and that more than three-quarters view third-party software risk as a major concern. The same coverage pointed to expanding dependency on external services (often 100–300 SaaS apps per enterprise) and noted that broader AI adoption is increasing attack surface while also being used defensively to improve detection and response.
Separate CISO-oriented content emphasized organizational and programmatic pressures rather than a discrete incident: Dark Reading described a CISO succession/turnover problem (average tenure cited at 18–26 months) and linked rapid leadership churn—especially during M&A integration—to compounding security risk and burnout. Other items in the set were not incident-driven: one was a CSO Online navigation/feature listing around application security approaches (e.g., SCA/SAST/DAST/MAST), and another was a TechTarget roundup promoting cybersecurity conferences to attend in 2026; neither provided specific breach, vulnerability disclosure, or actionable threat intelligence.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
The Panorays survey reported that two-thirds of CISOs are already adopting AI-powered tools to modernize vendor risk assessment, while nearly all remaining respondents plan to do so in response to growing third-party vulnerabilities.
Panorays' latest annual survey of 200 U.S.-based CISOs found that 60% observed an increase in third-party security incidents this year, with software supply chain risk ranking among the top cybersecurity concerns. The report also found only 15% had full visibility into their software supply chains and just 21% had incident response plans for breaches originating from external software suppliers.
Industry estimates cited in the report placed average CISO tenure at roughly 18 to 26 months, with experts describing how leadership churn pauses projects, delays controls, and erodes institutional knowledge. The article framed rapid CISO turnover as a structural risk that can repeatedly reset long-term security programs.
A 2024 Heidrick & Struggles survey found that 47% of CISOs reported having no adequate internal successor, highlighting weak succession planning in security leadership pipelines.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.