A new academic paper, published on arXiv in September 2026, challenges the reliability of SHAP (SHapley Additive exPlanations) as a standalone tool for explaining malware detection decisions. The…
arXiv: Propagation Model for SSC attacks: Why SBOM (tools) don't tell the whole truth
AI_SAFETY. Sourced from arxiv_cscr, summarised by Matproof.
AI Analysis
What changed and what to do.
The publication introduces a propagation model for Software Supply Chain (SSC) attacks, arguing that current Software Bill of Materials (SBOM) tools fail to capture the full risk picture. The paper demonstrates that SBOMs, while useful for inventorying known components, do not accurately model how vulnerabilities propagate through transitive dependencies, build processes, or runtime environments. This means an organization can have a complete SBOM yet still be exposed to attack paths that are invisible to standard compliance checks.
The findings affect any organization that relies on SBOMs for regulatory compliance, particularly those in critical infrastructure, financial services, healthcare, and public sector procurement. Regulators in the EU and US are increasingly mandating SBOMs under frameworks like the Cyber Resilience Act and Executive Order 14028, so any compliance team using SBOMs as a primary control should treat this as a warning that their current evidence may be insufficient.
Compliance teams should immediately review their SBOM generation and validation processes to ensure they include runtime context, build provenance, and transitive dependency analysis. They should also begin planning for supplementary controls, such as continuous vulnerability monitoring and attestation of build integrity, rather than relying solely on static SBOM snapshots. Finally, they should track this research closely, as it may influence upcoming regulatory guidance on what constitutes adequate supply chain risk management.
This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.
More AI_SAFETY updates
Latest in AI_SAFETY.
This publication, dated September 2026, is a technical research paper proposing a new framework for managing digital credentials in a post-quantum computing environment. It argues that as quantum…
This publication is not a regulatory change but a research paper analyzing the effectiveness of the static analysis tool CodeQL in detecting Java vulnerabilities. The study empirically evaluates…
A new academic paper, published on arXiv in September 2026, demonstrates a novel method for "black-box adaptive visual prompt injection" attacks against multimodal AI systems. Unlike previous prompt…
Map this to your controls
Connect regulatory changes to your compliance work.
Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.