www.endorlabs.com AI Coding Agents Expand Software Supply Chain Risks
Article Content
- •Only 20% of AI-recommended dependencies are safe, increasing supply chain risks.
- •In 2025, over 454,600 new malicious packages were reported, a 75% increase.
- •Organizations must treat AI-generated code as untrusted and enforce strict security controls.
AI coding agents are introducing significant vulnerabilities into the software supply chain by selecting insecure dependencies without human oversight. Research indicates that only 20% of dependency versions recommended by these agents are safe, leading to a surge in malicious packages. In 2025, over 454,600 new malicious packages were reported, marking a 75% increase from the previous year. The Verizon 2026 DBIR revealed that third-party involvement in breaches rose to 48%, up from 30% in 2025. Organizations are advised to treat AI-generated code as untrusted and enforce rigorous security controls. The shift in dependency governance necessitates new security measures that account for AI's role in software development. As AI assets become critical, traditional security practices may not suffice to manage the evolving threat landscape.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track PhantomRaven, Cosmos and CVE-2025-54136 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…