JFrog Report Reveals AI-Driven Security Threats in Software Supply Chain

3 Sources

JFrog's 2025 Software Supply Chain State of the Union report highlights the growing security risks associated with AI expansion in the software supply chain, emphasizing the need for improved governance and security measures.

News article

AI Growth Drives New Software Supply Chain Threats

JFrog Ltd., a leading software supply chain company, has released its 2025 Software Supply Chain State of the Union report, revealing alarming security threats emerging from the expansion of artificial intelligence (AI) technology across the software supply chain 123.

Key Findings

The report highlights a "quad-fecta" of security vulnerabilities threatening the software supply chain:

  1. Common Vulnerabilities and Exposures (CVEs)
  2. Malicious packages
  3. Secrets' exposures
  4. Misconfigurations and human errors

JFrog's Security Research Team detected a 64% year-over-year increase in exposed secrets or tokens in public registries, with 27% of them being active 1.

AI and Machine Learning Model Risks

The proliferation of AI and machine learning models has led to new security challenges:

  • Over 1 million new models and datasets were added to Hugging Face in 2024
  • A 6.5-times increase in malicious models was observed
  • 94% of organizations create certified lists of approved models
  • 37% of companies still rely on manual efforts to curate and maintain these lists, increasing security risks 12

Binary Scanning and Open-Source Security

The report reveals concerning trends in security practices:

  • Only 43% of IT professionals apply security scans at both code and binary levels, down from 56% in 2023
  • More than 70% of developers continue to download packages directly from public registries, a risky practice that can expose entire organizations 1

CVE Scoring and Security Tool Sprawl

The report highlights issues with current security practices:

  • Only 12% of CVEs rated as "critical" were actually exploitable, raising doubts about current scoring methods
  • 73% of professionals report using seven or more security tools, potentially contributing to increased complexity and risk 12

Recommendations for Organizations

Yoav Landman, CTO and Co-Founder of JFrog, emphasizes the need for organizations to adapt to the AI era:

"AI adoption will only grow more rapidly. Thus, in order for organizations to thrive in today's AI era they should automate their toolchains and governance processes with AI-ready solutions, ensuring they remain both secure and agile while maximizing their innovative potential." 23

Impact on DevSecOps Teams

Shachar Menashe, Vice President of Security Research at JFrog, warns about the consequences of inflated CVE scores:

"When DevSecOps teams are forced to remediate vulnerabilities that aren't ultimately harmful, their everyday workflows are disrupted, which can lead to developer burnout and costly mistakes." 23

The JFrog Software Supply Chain State of the Union 2025 report serves as a wake-up call for organizations to reassess their security practices and adapt to the evolving threat landscape in the AI era. As AI continues to reshape the software development landscape, companies must prioritize robust security measures and automated governance to protect their software supply chains.

Explore today's top stories

NVIDIA's Next-Gen 'Rubin' AI Architecture: A Revolutionary Leap in Compute Technology

NVIDIA CEO Jensen Huang confirms the development of the company's most advanced AI architecture, 'Rubin', with six new chips currently in trial production at TSMC.

TweakTown logoWccftech logo

2 Sources

Technology

22 hrs ago

NVIDIA's Next-Gen 'Rubin' AI Architecture: A Revolutionary

Databricks Acquires Tecton to Enhance AI Agent Capabilities

Databricks, a leading data and AI company, is set to acquire machine learning startup Tecton to bolster its AI agent offerings. This strategic move aims to improve real-time data processing and expand Databricks' suite of AI tools for enterprise customers.

Reuters logoEconomic Times logoMarket Screener logo

3 Sources

Technology

22 hrs ago

Databricks Acquires Tecton to Enhance AI Agent Capabilities

Google Offers Free Weekend Access to Gemini's Veo 3 AI Video Generation Tool

Google is providing free users of its Gemini app temporary access to the Veo 3 AI video generation tool, typically reserved for paying subscribers, for a limited time this weekend.

Android Police logo9to5Google logoTechRadar logo

3 Sources

Technology

14 hrs ago

Google Offers Free Weekend Access to Gemini's Veo 3 AI

Broadcom Rides AI Wave: Stock Surges Amid Tech Giants' Infrastructure Investments

Broadcom's stock rises as the company capitalizes on the AI boom, driven by massive investments from tech giants in data infrastructure. The chipmaker faces both opportunities and challenges in this rapidly evolving landscape.

Benzinga logoThe Motley Fool logo

2 Sources

Technology

22 hrs ago

Broadcom Rides AI Wave: Stock Surges Amid Tech Giants'

Apple Expands Enterprise AI Support with New ChatGPT Configuration Options and Beyond

Apple is set to introduce new enterprise-focused AI tools, including ChatGPT configuration options and potential support for other AI providers, as part of its upcoming software updates.

TechCrunch logo9to5Mac logo

2 Sources

Technology

22 hrs ago

Apple Expands Enterprise AI Support with New ChatGPT
TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo