Webinar hosted with DoNow: how AI is reshaping software supply chain attacks and how to defend against them.
Table of contents
Real-world use case
You want to understand how artificial intelligence is changing software supply chain attacks: here is the replay of the webinar I hosted with DoNow on the topic.
Key takeaways
The massive integration of AI into software development pipelines (open source dependencies, pre-trained models, coding agents, IDE plugins) considerably widens the supply chain attack surface. A compromised upstream component, a malicious package, a poisoned model, a hijacked agent, can silently propagate all the way to production environments.
Topics covered during the session
- Map your dependencies: keep an up-to-date inventory (SBOM) of the components, models and AI plugins used across your developments.
- Verify provenance: favor trusted sources and registries, sign and verify artifact integrity before deployment.
- Limit AI agent privileges: apply least privilege to coding agents and assistants that access your source code or secrets.
- Monitor continuously: set up monitoring able to detect abnormal behavior introduced by a compromised dependency or agent.
- Keep a human in the loop: maintain human review over sensitive changes, even when proposed or generated by an AI.
Going further
Cybernetics helps SMBs secure their software supply chain and their AI usage, from posture assessment to remediation. Feel free to reach out if you would like to discuss these topics.
