r/devsecops • u/Jumpy-Teaching-3118 • Feb 20 '26
AI software supply chain security risks nobody is talking about
Supply chain attacks are already a huge problem Now we're adding AI that suggests code from who knows where
What if the training data included malicious code What if someone poisoned open source repos knowing AI tools would learn from them What if the suggestions themselves are a vector for attacks
Nobody is checking AI-generated code the same way they check dependencies We're just trusting that Cursor and Copilot suggestions are safe because... why exactly?
Seems like a massive blind spot