The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Podcast Archives
Podcast Archives artwork

AI-Powered Threats to the Software Supply Chain

Podcast Archives · 2026-08-04 · 57 min

0:00--:--

Episode notes

Open source software underpins virtually every modern application. That ubiquity is a superpower for developers, but it is also an expanding attack surface. Software supply chain attacks were once rare but are now happening daily, with malicious actors exploiting the trust developers place in public registries, package managers, and CI/CD pipelines. Chainguard is a secure software supply chain platform. The company started with hardened container images and has expanded to cover domains including VMs, language libraries, GitHub Actions, and agent skills. Matt Moore is a co-founder and CTO of Chainguard, and a veteran of Google's open source, container, and security infrastructure work. In this episode, Matt joins Gregor Vand to discuss lessons from recent supply chain attacks, why CI/CD pipelines are now a primary attack surface, the challenge of meaningful software inventories, the EU Cyber Resilience Act, and what the arrival of Anthropic's Mythos model means for the pace of vulnerability discovery and the urgency of patching at machine speed.

More from Podcast Archives

All episodes →
  • The Terminal as an Agentic Interface87 / 100
  • Eric Ries on Why Good Companies Go Bad92 / 100
  • Mina the Hollower70 / 100
  • Foundation Models for Structured Data77 / 100
  • Biome and the Future of JavaScript Tooling74 / 100
Explore the best B2B Engineering & DevTools podcasts →
All Podcast Archives episodes →