Urgent.News

What's breaking now, across thousands of outlets.

Tech

Survey: Lack of Confidence in Software Supply Chain Security Runs High

A survey of 400 platform and security engineers in the U.S and United Kingdom (UK), finds nearly three quarters (73%) are either only moderately confident (58%) or not confident (15%) in the ability of their existing tools for managing software artifacts to prevent attacks against their organization’s software supply chain. Conducted by Cloudsmith, a provider […]

Survey: Lack of Confidence in Software Supply Chain Security Runs High

A recent survey of 400 platform and security engineers reveals a significant lack of confidence in the security of software supply chains. Conducted by Cloudsmith, a provider of software artifact management platforms, the survey found that 73% of respondents are only moderately or not confident in their existing tools to prevent attacks against their organizations' supply chains.

Only 37% reported the ability to automatically detect and respond to intrusions within minutes, with 65% either investigating alternative compliance methods or evaluating security frameworks. Glenn Weinstein, Cloudsmith CEO, highlighted that as AI evolves, securing binaries after deployment will become increasingly important, as cybercriminals will leverage machine-speed attacks on these binaries.

The top concerns include AI-generated code introducing malicious dependencies, supply chain attacks disguised as normal DevOps activities, and automated systems modifying software at scale. While 61% of respondents are moderately confident AI coding tools aren't introducing vulnerabilities, only 32% scan AI models for specialized threats.

Furthermore, 95% generate Software Bill of Materials (SBOM) data but only 25% automate SBOM verification into security gatekeeping. The survey also revealed that 49% of organizations occasionally skip implementing new security/developer features. While security teams are most concerned about dependency-led attacks, responsibility for securing software supply chains is shared, with developers and centralized security teams receiving equal blame.

Written by urgent.news from DevOps.com's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at devops.com →

More in Tech

Why GrapheneOS 2026 Is Trending & How to Switch Seamlessly

GrapheneOS 2026: Why It’s Dominating Hacker News and How to Migrate Without Losing a Thing Introduction The phrase “GrapheneOS 2026” is exploding across Hacker News, Reddit, and Google Trends, and for good reason.

  • GrapheneOS 2026 gaining popularity for privacy and security.
  • Motorola rumored to include OS with Edge 30 Pro smartphone.
  • Article offers guide on compatibility, migration, performance, security.

More from Monday 28 September →