JFrog Report Reveals AI-Driven Security Threats in Software Supply Chain

3 Sources

Share

JFrog's 2025 Software Supply Chain State of the Union report highlights the growing security risks associated with AI expansion in the software supply chain, emphasizing the need for improved governance and security measures.

News article

AI Growth Drives New Software Supply Chain Threats

JFrog Ltd., a leading software supply chain company, has released its 2025 Software Supply Chain State of the Union report, revealing alarming security threats emerging from the expansion of artificial intelligence (AI) technology across the software supply chain

1

2

3

.

Key Findings

The report highlights a "quad-fecta" of security vulnerabilities threatening the software supply chain:

  1. Common Vulnerabilities and Exposures (CVEs)
  2. Malicious packages
  3. Secrets' exposures
  4. Misconfigurations and human errors

JFrog's Security Research Team detected a 64% year-over-year increase in exposed secrets or tokens in public registries, with 27% of them being active

1

.

AI and Machine Learning Model Risks

The proliferation of AI and machine learning models has led to new security challenges:

  • Over 1 million new models and datasets were added to Hugging Face in 2024
  • A 6.5-times increase in malicious models was observed
  • 94% of organizations create certified lists of approved models
  • 37% of companies still rely on manual efforts to curate and maintain these lists, increasing security risks

    1

    2

Binary Scanning and Open-Source Security

The report reveals concerning trends in security practices:

  • Only 43% of IT professionals apply security scans at both code and binary levels, down from 56% in 2023
  • More than 70% of developers continue to download packages directly from public registries, a risky practice that can expose entire organizations

    1

CVE Scoring and Security Tool Sprawl

The report highlights issues with current security practices:

  • Only 12% of CVEs rated as "critical" were actually exploitable, raising doubts about current scoring methods
  • 73% of professionals report using seven or more security tools, potentially contributing to increased complexity and risk

    1

    2

Recommendations for Organizations

Yoav Landman, CTO and Co-Founder of JFrog, emphasizes the need for organizations to adapt to the AI era:

"AI adoption will only grow more rapidly. Thus, in order for organizations to thrive in today's AI era they should automate their toolchains and governance processes with AI-ready solutions, ensuring they remain both secure and agile while maximizing their innovative potential."

2

3

Impact on DevSecOps Teams

Shachar Menashe, Vice President of Security Research at JFrog, warns about the consequences of inflated CVE scores:

"When DevSecOps teams are forced to remediate vulnerabilities that aren't ultimately harmful, their everyday workflows are disrupted, which can lead to developer burnout and costly mistakes."

2

3

The JFrog Software Supply Chain State of the Union 2025 report serves as a wake-up call for organizations to reassess their security practices and adapt to the evolving threat landscape in the AI era. As AI continues to reshape the software development landscape, companies must prioritize robust security measures and automated governance to protect their software supply chains.

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo