Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Why Open Source Is the Easiest Target for Supply Chain Attacks

Attackers targeting open source dependencies already have all the code they need. Curtis Koenig, Head of Application Security at Gen, explains the fundamental asymmetry and why building quality fixes at speed is the real challenge for defenders. "An attacker can produce very fast, very ugly code that propagates through as an attack. When we're trying to fix something, the challenge we have is we're always trying to build for quality.".

The 3 Layers of a Mature Software Supply Chain Security Program

There are lots of terms used to generalize what a mature application security program looks like. Find & Fix. Continuous Remediation. Code to Cloud, Unified Risk. The underlying message in these buzzwords is the same: security needs to be systemic. Defense in Depth is preached as a security best practice by leading cybersecurity agencies like NIST and CISA, and these principles are especially relevant to the metastasizing software supply chain risk seen across enterprises.
Featured Post

Why Data Governance Has Become a Critical Defence Against Ransomware in Healthcare

Ransomware and ransomware-style attacks can have a catastrophic impact within healthcare, where disruption directly impacts safety and continuity. Today's ransomware groups increasingly operate as sophisticated criminal enterprises, sharing tools, infrastructure, and expertise through ransomware-as-a-service (RaaS) models. This lowers the barrier to entry for cybercriminals while allowing experienced threat actors to focus their efforts on identifying and exploiting high-value targets.

December 2026 Is Closer Than You Think: What the UK's Defence Cyber Directive Means for Your Organisation

The UK’s Ministry of Defence has sent a clear message to organisations within the Defence supply chain. By 31 December 2026, all Defence industry partners are expected to achieve Defence Cyber Certification (DCC) Level 0, including Cyber Essentials for all applicable business-critical systems within scope. This represents a significant step in strengthening cyber resilience across the Defence ecosystem and raising the baseline for cyber security throughout the UK’s supply chain.

Extending the Single Source of Truth to the Agentic Software Supply Chain

Every developer on your team now runs multiple agents. None of them are waiting for human sign-off to act. That’s exactly the gap we discussed and closed at swampUP 2026. JFrog unveiled new capabilities that extend the JFrog Platform as not only the Single Source of Truth for OSS and heritage software, but now the Agentic Software Supply Chain. Here’s everything we announced, and why it matters.

CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks

Software supply chain attacks pose a critical enterprise threat. In the first half of 2026, these attacks increasingly used malicious software packages uploaded to public software registries, the CrowdStrike 2026 Threat Hunting Report found. Adversaries are poisoning open-source packages and exploiting the same dependencies that AI-assisted development tools and agentic applications pull onto enterprise endpoints every day.

The dark figure of supply chain detection

During World War II, Abraham Wald was asked where to add armor to bomber planes. The military's instinct was to study the planes that came back and reinforce wherever the bullet holes were clustered. Wald said to do the opposite. The planes in front of him had already survived hits to those spots. That's exactly why he could study them. The planes that took hits to the engine or the cockpit never made it back to be studied at all.

Coding Agents Just Reopened Your Software Supply Chain Blind Spot

Most organizations spent years hardening their software supply chain. The model is familiar: dependencies flow through a controlled repository, policies determine what is allowed, scanning catches what slips through, and every action is logged for auditability. It works because human developers operate within environments that enforce these rules. AI coding agents break that assumption entirely.

Comparing Software Supply Chain Security Vendors: Key Criteria

If you’re comparing software supply chain security vendors in 2026, the market can feel deceptively crowded. Many platforms now claim broad coverage. Many specialists still lead in critical niches. And nearly every vendor can produce a long feature checklist. That is exactly why buyer discipline matters more than ever.