
Alice in Supply Chains
Episode 21 | September, 2026
In this episode of the Alice in Supply Chains Podcast, hosts Adrian Sanabria and Alexandre Sieira discuss the latest news related to third party cyber risk management. - Story one focuses on a wild BGP hijacking incident that compromised updates for a vendor that makes hypervisor management software (Virtualizor by Softaculous). Attackers were able to take over part of hosting company Hetzner’s IP space, create a valid TLS certificate for Softaculous’s website and serve up an identical copy of the website. Softaculous didn’t cryptographically check the integrity of updates, so the attack succeeded in compromising customers. - In story two, the Financial Stability Board, an organization created by the G20 after the 2008 financial crisis, warns of risks from AI. The risks were twofold: the AI bubble and threats directly from rogue AI agents. - In story three, Alexandre shares an observation that, at least in Latin America, financial institutions are writing inside-out scanning into their MSAs. - Finally, in story four, UK politicians propose to amend the Cyber Security and Resilience bill to expand restrictions on tech suppliers seen as ‘risky’. A troubling addition aims to remove transparency at the same time. Links - for reference: Story 1: https://arstechnica.com/security/2026/09/well-executed-bgp-attack-uses-hijacked-ips-to-infect-real-networks/ Story 2: https://therecord.media/cyber-risk-from-frontier-ai-most-immediate-concern-to-global-finance Story 3: No link Story 4: https://therecord.media/uk-technology-national-security

