
Bloom Security’s Extension Resurrection research exposes a blind spot in developer security
THE SO WHAT
Bloom Security’s work on resurrected VS Code extensions highlights a neglected attack surface: the IDE itself as a supply-chain vector. If your developers rely on rich extension ecosystems, treat extension policies and provenance checks as part of your core AppSec program, not a nice-to-have.
READ THE SOURCE
MORE FROM THE WIRE
Deep & Emerging TechFlock backpedals as nation revolts against surveillance devices
Flock adding new privacy guardrails under public pressure shows how quickly sentiment can flip against ambient sensing infrastructure. If your product touches surveillance or location data, assume opt-in, auditability, and deletion controls will become table stakes—design them now rather than under protest.
Deep & Emerging TechFintech Chime Explores Stablecoins as New Feature on Its App
If Chime brings stablecoins into a mainstream neobank app, stable-value tokens move from crypto rail to consumer UX primitive. Banks and fintechs need a view on where they’ll plug into stablecoin issuance, custody, and compliance—or risk watching their users' payment behavior shift into someone else’s closed loop.
Deep & Emerging TechEurope built the world’s largest electric plane. It flew in New York
Heart Aerospace getting a >1 MW, 335-meter flight out of the X1 demonstrator shows electric propulsion scaling beyond small commuter craft into regional aircraft territory. Airport operators, regional carriers, and grid planners should start modeling what multi-megawatt charging cycles look like on their ramps and substations.
Deep & Emerging TechFord on track to complete $2B factory overhaul for Fathom EV truck
A $2B factory overhaul with prototypes not expected until Q1 2027 shows how long and capital-intensive EV platform shifts remain, even for incumbents. If you’re in the supply chain, align your own automation and capacity bets to these multi-year ramps—not quarterly headlines.