AI-Powered Threats to the Software Supply Chain

AI-Powered Threats to the Software Supply Chain

Author: Software Engineering Daily August 4, 2026 Duration: 57:21

Open source software underpins virtually every modern application. That ubiquity is a superpower for developers, but it is also an expanding attack surface. Software supply chain attacks were once rare but are now happening daily, with malicious actors exploiting the trust developers place in public registries, package managers, and CI/CD pipelines.

Chainguard is a secure software supply chain platform. The company started with hardened container images and has expanded to cover domains including VMs, language libraries, GitHub Actions, and agent skills.

Matt Moore is a co-founder and CTO of Chainguard, and a veteran of Google’s open source, container, and security infrastructure work. In this episode, Matt joins Gregor Vand to discuss lessons from recent supply chain attacks, why CI/CD pipelines are now a primary attack surface, the challenge of meaningful software inventories, the EU Cyber Resilience Act, and what the arrival of Anthropic’s Mythos model means for the pace of vulnerability discovery and the urgency of patching at machine speed.

Sponsorship inquiries:
sponsor@softwareengineeringdaily.com

The post AI-Powered Threats to the Software Supply Chain appeared first on Software Engineering Daily.


Dive deep into the conversations that shape how we build and understand complex systems with Data Archives-Software Engineering Daily. This podcast pulls from a rich library of technical discussions, each one a focused exploration into the specific tools, architectures, and challenges that define modern software engineering. Rather than surface-level news, these episodes offer sustained, thoughtful dialogues with the engineers and thinkers who are working on the front lines of data infrastructure, distributed systems, and emerging technologies. You'll hear detailed breakdowns of real-world problems and the nuanced solutions teams are implementing, providing a practical sense of how theoretical concepts translate into production code and resilient platforms. The archive serves as an enduring resource, whether you're looking to grasp the fundamentals of a new database or understand the intricate trade-offs in a system design. Tune in for a consistently substantive listen that treats software engineering with the depth and seriousness it deserves, all through the unfiltered lens of expert conversation.
Author: Language: en-us Episodes: 50

Software Engineering Daily
Podcast Episodes
React Native at Scale [not-audio_url] [/not-audio_url]

Duration: 45:35
React Native is an open source framework developed by Meta that allows engineers to build mobile applications for both iOS and Android using a single JavaScript codebase. The framework bridges the gap between web develop…
Formal Methods as Agent Guardrails [not-audio_url] [/not-audio_url]

Duration: 48:32
Formal methods are a branch of mathematics and computer science focused on proving the correctness of systems, and they have long promised a more rigorous foundation for software. However, their complexity has kept them…
Open Source Sustainability [not-audio_url] [/not-audio_url]

Duration: 58:43
Open source software underpins nearly every modern application, including frameworks powering the most popular websites, to the libraries securing financial backend systems. However, while open source drives collaboratio…
Vespa AI and Surpassing the Limits of Vector Search [not-audio_url] [/not-audio_url]

Duration: 38:35
Vector search has risen to become a foundational tool in modern search and retrieval systems, including the RAG pipelines that power many AI applications. However, the demands on retrieval systems are growing more sophis…
SmartBear and Multi-Agent QA [not-audio_url] [/not-audio_url]

Duration: 55:15
AI coding tools have dramatically accelerated the pace of development, and the bottleneck in the software development lifecycle has shifted to code validation and testing. However, the conventional tools and workflows th…
The Ethics of Autonomous Weapons Systems [not-audio_url] [/not-audio_url]

Duration: 1:06:40
Artificial intelligence is transforming warfare faster than the legal and ethical frameworks designed to govern it. Militaries around the world are deploying AI-powered decision support systems to identify targets, asses…
Open-Weight AI Models [not-audio_url] [/not-audio_url]

Duration: 50:14
Open-weight models are AI systems whose trained parameters are publicly released, which allows developers to run, fine-tune, and deploy them independently rather than accessing them only through a hosted API. While close…
Hype and Reality of the AI Coding Shift [not-audio_url] [/not-audio_url]

Duration: 57:05
AI coding tools have gone from novelty to core infrastructure in under three years. Today, many devs use AI daily, a substantial share of new code is AI-generated, and expectations for automation are rapidly increasing.…
Unlocking the Data Layer for Agentic AI with Simba Khadder [not-audio_url] [/not-audio_url]

Duration: 49:04
AI agents are increasingly capable of reasoning and performing autonomous work over long periods. However, as agents take on more complex, longer-horizon tasks, keeping them supplied with the right information becomes th…