
US Chip Ambitions Face A Major Talent Gap
The US is projected to face a 157,000 semiconductor worker shortage by 2030. This talent gap threatens to undermine the CHIPS Act and could disrupt the domestic tech supply chain for years to come.
25 verified briefings on Supply Chain. Each story includes a plain-English summary, why it matters, and the concrete action engineering teams should take.

The US is projected to face a 157,000 semiconductor worker shortage by 2030. This talent gap threatens to undermine the CHIPS Act and could disrupt the domestic tech supply chain for years to come.

Samsung is shifting production of consumer memory like DDR5 and SSDs to third-party partners. This move frees up its own factories to produce high-demand HBM memory, a critical component for AI hardware.

Major PC makers like HP and Asus are now using memory chips from Chinese supplier CXMT. This move diversifies their supply chain away from the few dominant players, signaling a potential shift in the global semiconductor market.

Samsara has launched a smart, single-use Bluetooth adhesive label for packages. The Samsara Tracking Label provides near-real-time visibility into a shipment's location, making it easier than ever to track deliveries from dispatch to destination.

DepsGuard is a new open-source tool that simplifies securing JavaScript projects. It applies recommended security settings, like package cooldowns and disabling install scripts, across multiple package managers (npm, pnpm, yarn, bun, uv) with a single command, addressing common supply chain vulnerabilities.

Extreme heat is no longer just a climate issue; it's a growing economic problem. Rising temperatures are reducing worker productivity, slowing supply chains, and threatening economic growth in countries like India.

A series of high-impact security incidents, including a mail server zero-day, poisoned npm packages, and a fake AI repository, highlight a dangerous trend. Attackers are exploiting single points of failure in software supply chains and cloud infrastructure to launch widespread, cascading attacks.

The price for 32GB of DDR5 RAM has surged to a minimum of $375, a significant increase from previous levels. This price hike is driven by massive demand from the AI industry, which is consuming memory supply and impacting the PC building market for consumers and businesses.

Security firm Minimus released two new tools to help teams manage software supply chain risks and container security together. The products aim to simplify protecting applications from third-party code vulnerabilities and misconfigurations.

The Pentagon has added Alibaba, Baidu, and other major Chinese tech companies to a list of firms allegedly supporting China's military. This move bars them from U.S. defense contracts and raises supply chain security concerns.

This week's security landscape saw the discovery of new Linux vulnerabilities and a zero-day flaw in Microsoft Defender. The incidents highlight ongoing risks from unpatched systems and complex supply chains. Additionally, old bugs resurfaced, and phishing attacks have become more targeted, posing a continued threat.

Researchers have developed a new, more environmentally friendly, and potentially cheaper method for extracting lithium, a critical component for batteries. The process, detailed in the journal Science, is being commercialized by a startup named Rock Zero, aiming to address future supply chain challenges for EVs and energy storage.

A new malware campaign named TrapDoor is targeting developers across npm, PyPI, and Crates.io. Researchers found over 34 malicious packages designed to compromise developer workstations and workflows, specifically targeting credentials and files related to AI coding assistants, highlighting ongoing software supply chain risks.

GitHub has enhanced npm security with a new "staged publishing" feature. It requires maintainers to approve new package versions using two-factor authentication (2FA) before they are publicly available. This measure aims to prevent malicious package publications and strengthen the software supply chain against attacks.

CrowdStrike, Google, and the Shadowserver Foundation have successfully disrupted the GlassWorm malware campaign. This operation dismantled the command-and-control infrastructure used in a persistent software supply chain attack that targeted developers with malicious packages and extensions since at least early 2025.

Multiple high-severity vulnerabilities have been discovered in NLTK, a popular Python library for natural language processing. The flaws could allow for remote code execution and arbitrary file writes, posing a significant supply chain security risk for applications using the library. Developers should update immediately.

GitHub is rolling out security updates for npm, the popular JavaScript package manager. The changes will block malicious scripts from running automatically during installation, helping to protect developers and their projects from common supply-chain attacks.

Several popular Laravel-Lang PHP packages were compromised in a software supply chain attack. Malicious code was injected to deliver a credential-stealing malware, posing a significant risk to applications using these packages and potentially exposing sensitive login information.

Microsoft has identified an active supply chain attack on the npm ecosystem. Attackers are publishing malicious packages that mimic internal corporate libraries. Using a technique called dependency confusion, these packages are designed to infiltrate and gather information from developer environments, posing a significant risk to organizations.

Microsoft has uncovered a software supply chain attack using typosquatted npm packages to steal cloud and CI/CD credentials. The attack uses npm lifecycle hooks for execution and abuses the legitimate Bun runtime as a loader to deploy credential-stealing malware, targeting developers and their environments.

A coordinated supply chain attack named TrapDoor has been discovered across npm, PyPI, and Crates.io. The campaign used over 34 malicious packages to distribute credential-stealing malware, highlighting ongoing risks in open-source registries and the developers who rely on them.

Google Cloud published a guide on using its BigQuery Graph feature to create digital twins of complex systems, like a food supply chain. The approach helps businesses model and analyze relationships within their operations, moving beyond the limitations of traditional spreadsheets to manage growth and complexity effectively.

Grafana Labs confirmed a security breach limited to its GitHub environment, exposing public and private source code. The company stated that its investigation found no evidence of customer production systems being compromised. The incident was linked to a supply chain attack involving a TanStack npm package.

GitHub has disclosed a security breach where an attacker gained unauthorized access to its internal repositories. The compromise originated from a malicious third-party VS Code extension on an employee's device. While thousands of internal repos were exfiltrated, GitHub reports no evidence of impact on customer data.

GitHub has confirmed that a recent breach of 3,800 internal repositories was caused by a malicious VS Code extension. The extension was compromised in a wider supply-chain attack targeting the popular TanStack npm packages, highlighting the growing risks of software dependencies.