AI-Powered Threats to the Software Supply Chain

AI-Powered Threats to the Software Supply Chain

Author: Software Engineering Daily August 4, 2026 Duration: 57:21

Open source software underpins virtually every modern application. That ubiquity is a superpower for developers, but it is also an expanding attack surface. Software supply chain attacks were once rare but are now happening daily, with malicious actors exploiting the trust developers place in public registries, package managers, and CI/CD pipelines.

Chainguard is a secure software supply chain platform. The company started with hardened container images and has expanded to cover domains including VMs, language libraries, GitHub Actions, and agent skills.

Matt Moore is a co-founder and CTO of Chainguard, and a veteran of Google’s open source, container, and security infrastructure work. In this episode, Matt joins Gregor Vand to discuss lessons from recent supply chain attacks, why CI/CD pipelines are now a primary attack surface, the challenge of meaningful software inventories, the EU Cyber Resilience Act, and what the arrival of Anthropic’s Mythos model means for the pace of vulnerability discovery and the urgency of patching at machine speed.

Sponsorship inquiries:
sponsor@softwareengineeringdaily.com

The post AI-Powered Threats to the Software Supply Chain appeared first on Software Engineering Daily.


Dive deep into the conversations that shape how we build and understand complex systems with Data Archives-Software Engineering Daily. This podcast pulls from a rich library of technical discussions, each one a focused exploration into the specific tools, architectures, and challenges that define modern software engineering. Rather than surface-level news, these episodes offer sustained, thoughtful dialogues with the engineers and thinkers who are working on the front lines of data infrastructure, distributed systems, and emerging technologies. You'll hear detailed breakdowns of real-world problems and the nuanced solutions teams are implementing, providing a practical sense of how theoretical concepts translate into production code and resilient platforms. The archive serves as an enduring resource, whether you're looking to grasp the fundamentals of a new database or understand the intricate trade-offs in a system design. Tune in for a consistently substantive listen that treats software engineering with the depth and seriousness it deserves, all through the unfiltered lens of expert conversation.
Author: Language: en-us Episodes: 50

Software Engineering Daily
Podcast Episodes
The Terminal as an Agentic Interface [not-audio_url] [/not-audio_url]

Duration: 52:21
The terminal has been a constant in software development for decades. It has remained largely unchanged while everything around it transformed. However, as AI agents have become central to the developer workflow, the ter…
Docker and Sandboxing AI Agents [not-audio_url] [/not-audio_url]

Duration: 50:50
The most useful coding agents can mutate their environments by downloading packages, writing files, and connecting to services across the network. However, that freedom also presents dangers, and promises to usher in a n…
The Startup Scene in Southeast Asia [not-audio_url] [/not-audio_url]

Duration: 43:50
Golden Gate Ventures is one of Southeast Asia’s most established early-stage venture firms, having backed companies across the region since 2011. They have invested in companies that are now household names in the region…
NanoClaw and the Rise of Personal AI Agents [not-audio_url] [/not-audio_url]

Duration: 1:03:35
AI agents have shown remarkable potential to function as persistent digital assistants that are capable of monitoring data, managing communications, and taking action autonomously over long periods. OpenClaw was one of t…
Agentic DevOps at AWS [not-audio_url] [/not-audio_url]

Duration: 51:56
AI agents have become capable of reasoning across large amounts of data, calling tools, and taking sequences of actions autonomously. These qualities make them well suited to some of the most persistent pain points in De…
AURA and Open-Source Agents for Production Operations [not-audio_url] [/not-audio_url]

Duration: 53:04
AI agents have transformed how software gets written, but the operational side of running software in production has not yet experienced a similar revolution. The same teams responsible for keeping systems healthy, inves…
Eric Ries on Why Good Companies Go Bad [not-audio_url] [/not-audio_url]

Duration: 50:28
Eric Ries is the creator of the Lean Startup method and the author of the New York Times bestseller The Lean Startup, which transformed how a generation of founders and engineers think about building products. It introdu…
SED News: Restricted Models, IDE Wars, and the DeepMind Mafia [not-audio_url] [/not-audio_url]

Duration: 51:58
SED News is a monthly podcast from Software Engineering Daily where hosts Gregor Vand and Sean Falconer break down the biggest stories shaping software engineering, Silicon Valley, and the broader tech industry. In this…
Grafana’s Approach to AI-Native Observability [not-audio_url] [/not-audio_url]

Duration: 48:29
Advanced software systems have long been more complex than any single engineer can fully understand. Observability is the established solution to this problem, but with AI agents now generating code, deploying changes, a…
Building Software That People Love [not-audio_url] [/not-audio_url]

Duration: 46:26
Building great software always involves technical problem solving, but the best software goes beyond function. It feels fluid, coherent, and genuinely fun to use. This quality lives at the intersection of engineering and…