TLDRocket
Sign in

The software supply chain is the new battlefield. AI just changed the rules.

The New Stack Carly Page

AI coding tools are speeding up software and attacks at the same time. That’s pushing security toward the supply chain, where one bad component can ripple everywhere.

Based on reporting by The New Stack, Carly Page — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

AI has sped up developers, but it has also sped up attackers, and the software supply chain is where that collision is becoming hardest to ignore. GitHub handled around one billion commits in 2025, then roughly 275 million commits a week by April 2026, according to COO Kyle Daigle. GitHub Actions usage also jumped from 500 million compute minutes per week in 2023 to 2.1 billion in part of a single week this year. That is a lot of code moving through a system that was never built for this pace.

Quincy Castro, CISO at Chainguard, says the change is obvious inside his own shop. He says Chainguard engineers have not written a line of code by themselves in the past year, because AI now does so much of the work. But the bigger shift is outside classic engineering teams. HR, finance, and business intelligence groups can now build their own software, often with AI making choices about libraries and packages the human requester never sees.

That matters because the old mental model assumed humans were still making the important dependency decisions. Now, Castro says, AI is deciding what gets pulled into an application and how a task gets done. Attackers are leaning on the same tools. He points to models that can find vulnerabilities, chain together medium and low severity issues, and turn them into a route to domain admin or root. Mandiant says mean time-to-exploit has fallen from 63 days in 2018–19 to an estimated minus seven days in 2025, which is a grim way of saying defenders may be behind before they even start.

The third pressure point is open source. Castro points to the TeamPCP campaign, which compromised widely used projects including Aqua Security’s Trivy, showing how malicious code can enter trusted components and spread downstream. He says many organizations still have limited controls around CI/CD and keep pulling in outside components to move faster, which makes the risk worse when AI agents are doing more of the picking. The point is not that open source is broken. It’s that trust in its distribution path is.

Chainguard’s answer is to build from verified, buildable source and push more of the defense to the front of the process, not the back. The company’s Athena coalition has already processed more than 40,000 vulnerabilities as of July, with 42% critical or high severity and 86% network reachable. That is a lot of findings, but Castro’s argument is simple: finding more bugs is easy now. Fixing them, and keeping them from entering the pipeline in the first place, is the real job.

My take — AI-written commentary, not fact-checked reporting

The comforting part of AI security talk is usually the scanning. Scan more, alert more, soothe everyone with dashboards. That’s not a strategy; it’s a support group for bad inputs. The grown-up move is to control what enters the pipeline and stop pretending every package is a friendly little box of code just because it has a popular badge on it.

Read more about this at: The New Stack

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.