AI-Powered Threats to the Software Supply Chain

AI-Powered Threats to the Software Supply Chain

Author: Software Engineering Daily August 4, 2026 Duration: 57:21

Open source software underpins virtually every modern application. That ubiquity is a superpower for developers, but it is also an expanding attack surface. Software supply chain attacks were once rare but are now happening daily, with malicious actors exploiting the trust developers place in public registries, package managers, and CI/CD pipelines.

Chainguard is a secure software supply chain platform. The company started with hardened container images and has expanded to cover domains including VMs, language libraries, GitHub Actions, and agent skills.

Matt Moore is a co-founder and CTO of Chainguard, and a veteran of Google’s open source, container, and security infrastructure work. In this episode, Matt joins Gregor Vand to discuss lessons from recent supply chain attacks, why CI/CD pipelines are now a primary attack surface, the challenge of meaningful software inventories, the EU Cyber Resilience Act, and what the arrival of Anthropic’s Mythos model means for the pace of vulnerability discovery and the urgency of patching at machine speed.

Sponsorship inquiries:
sponsor@softwareengineeringdaily.com

The post AI-Powered Threats to the Software Supply Chain appeared first on Software Engineering Daily.


Dive into the vast Podcast Archives-Software Engineering Daily, a curated collection of in-depth technical conversations that have defined the landscape of modern software development. This archive goes beyond surface-level news, offering a permanent record of deep-dive discussions with engineers, researchers, and founders who are building the tools and platforms shaping our digital world. Each episode is a focused exploration, unpacking complex topics like distributed systems, machine learning infrastructure, programming language design, and the practical challenges of scaling technology. You'll hear firsthand accounts of architectural decisions, post-mortems on system failures, and thoughtful debates on emerging paradigms. It’s a resource built for the curious professional who values substance over soundbites, providing context and depth that shorter formats simply cannot. Whether you're looking to understand the historical context behind a current technology, reinforce your foundational knowledge, or discover niche specialties, this podcast archive serves as an essential, ever-growing library. The conversations are detailed, technical, and assume a level of familiarity with the field, making it a trusted companion for continuous learning. Listen to this podcast not for fleeting headlines, but for the enduring insights and nuanced expertise that come from thoughtful, long-form dialogue with the people writing the code and designing the systems that run our world.
Author: Language: en-us Episodes: 50

Software Engineering Daily
Podcast Episodes
Rebuilding the Cloud for AI Agent Code [not-audio_url] [/not-audio_url]

Duration: 49:57
For two decades, the cloud has been shaped by human developers writing code and managing its deployment. Now a growing share of production code is generated by LLMs with little human review. Because that code is not full…
SED News: The Kimi Moment, Runaway AI, and Tokenmaxxing [not-audio_url] [/not-audio_url]

Duration: 48:28
SED News is a monthly podcast from Software Engineering Daily where hosts Gregor Vand and Sean Falconer break down the biggest stories shaping software engineering, Silicon Valley, and the broader tech industry. In this…
The Terminal as an Agentic Interface [not-audio_url] [/not-audio_url]

Duration: 52:21
The terminal has been a constant in software development for decades. It has remained largely unchanged while everything around it transformed. However, as AI agents have become central to the developer workflow, the ter…
Docker and Sandboxing AI Agents [not-audio_url] [/not-audio_url]

Duration: 50:50
The most useful coding agents can mutate their environments by downloading packages, writing files, and connecting to services across the network. However, that freedom also presents dangers, and promises to usher in a n…
The Startup Scene in Southeast Asia [not-audio_url] [/not-audio_url]

Duration: 43:50
Golden Gate Ventures is one of Southeast Asia’s most established early-stage venture firms, having backed companies across the region since 2011. They have invested in companies that are now household names in the region…
NanoClaw and the Rise of Personal AI Agents [not-audio_url] [/not-audio_url]

Duration: 1:03:35
AI agents have shown remarkable potential to function as persistent digital assistants that are capable of monitoring data, managing communications, and taking action autonomously over long periods. OpenClaw was one of t…
Agentic DevOps at AWS [not-audio_url] [/not-audio_url]

Duration: 51:56
AI agents have become capable of reasoning across large amounts of data, calling tools, and taking sequences of actions autonomously. These qualities make them well suited to some of the most persistent pain points in De…
AURA and Open-Source Agents for Production Operations [not-audio_url] [/not-audio_url]

Duration: 53:04
AI agents have transformed how software gets written, but the operational side of running software in production has not yet experienced a similar revolution. The same teams responsible for keeping systems healthy, inves…
Eric Ries on Why Good Companies Go Bad [not-audio_url] [/not-audio_url]

Duration: 50:28
Eric Ries is the creator of the Lean Startup method and the author of the New York Times bestseller The Lean Startup, which transformed how a generation of founders and engineers think about building products. It introdu…
SED News: Restricted Models, IDE Wars, and the DeepMind Mafia [not-audio_url] [/not-audio_url]

Duration: 51:58
SED News is a monthly podcast from Software Engineering Daily where hosts Gregor Vand and Sean Falconer break down the biggest stories shaping software engineering, Silicon Valley, and the broader tech industry. In this…