Why Open Source Is the Easiest Target for Supply Chain Attacks

Attackers targeting open source dependencies already have all the code they need. Curtis Koenig, Head of Application Security at Gen, explains the fundamental asymmetry and why building quality fixes at speed is the real challenge for defenders.

"An attacker can produce very fast, very ugly code that propagates through as an attack. When we're trying to fix something, the challenge we have is we're always trying to build for quality."

Curtis captures the core tension defenders face. Speed favors the attacker, while every fix has to meet a higher standard.

Open source dependencies give attackers a head start. The code is already public, making vulnerabilities far easier to find. One of the first MCP integrations Curtis saw paired with Ghidra to reverse engineer software in a day that previously would have taken weeks.

The tools are accelerating on both sides, but defenders can never cut corners on quality. That tension between speed and rigor is the problem security teams are working to solve.

Full episode: https://youtu.be/aLv52Bs8dQI