How AI Agents Are Hiding in Your Supply Chain
The Cybersecurity Podcast with Fexingo: Hacks, Breaches, and Digital Defense Conversations
September 7, 2026
With Palo Alto Networks and CrowdStrike shares dropping sharply this week, we look past the stock noise to a quieter threat: how AI agents are embedding themselves in third-party software libraries.
Speakers Lucas, Luna
TopicsBusiness
Lucas (0:01)
Look at the five-day chart for Palo Alto Networks and CrowdStrike right now.
Both are down nearly 8 to 12% this week, despite the broader narrative that breaches are hitting record highs. It feels like the market is pricing in something we aren't talking about yet.
Luna (0:18)
Exactly. Everyone assumes the sell-off is just profit-taking after the late August surge, but the volume tells a different story. It feels like investors are worried about the cost of defending against these new threats.
Lucas (0:32)
I think it's deeper than just valuation compression. The issue isn't that the breaches aren't happening.
It's that the traditional tools aren't catching them fast enough. We're seeing a shift from perimeter defense to detecting malicious behavior inside the code itself. And that's where the money is getting stuck.
Luna (0:51)
So you're saying the problem isn't the attack surface anymore, but our ability to see what's actually running in it? That sounds expensive to fix.
Lucas (1:00)
It is expensive, and it's complicated because the attackers have started using AI agents to hide in plain sight within third-party software libraries. Most enterprises rely on hundreds of open-source dependencies.
And these days, those packages are being updated by automated bots that can mimic legitimate developer behavior perfectly.
Luna (1:20)
Mimic legitimate behavior? So the code looks fine, but it acts differently when it hits your production environment?
Lucas (1:27)
Precisely. Let's use a concrete example.
Imagine a widely used logging library for Python applications. An attacker doesn't need to inject malware directly into the main app code. Instead, they submit a tiny pull request to that library, a single function change that adds a conditional exfiltration trigger. To a human reviewer or even a standard static analysis tool, it looks like harmless error handling.
But when executed, it sends data back to an external server during peak traffic hours.
Luna (2:01)
That's terrifying because it bypasses the very checks we've spent years building. If the code compiles and passes the unit tests, who flags it?
Lucas (2:10)
That's the trap. Most companies are still relying on signature-based detection or basic anomaly scoring. But an AI agent can generate thousands of these minor, benign-looking changes across different repositories every day. They're not trying to break in with a sledgehammer.
They're slipping in through the cracks of automated quality assurance.
Luna (2:32)
So the vulnerability isn't in the network firewall anymore.
It's in the build pipeline itself.
That changes the entire security stack.
Lucas (2:41)
It does. And here is the kicker.
The attackers are using generative models to write these patches in a way that statistically matches the commit history of the original maintainer. They're matching the coding style, the comment structure, even the timing of when commits are pushed. It's adversarial machine learning targeting your own DevOps tools.
Luna (3:02)
If they're mimicking the author's style, how do you differentiate between a rushed legitimate update and a malicious one? You can't just audit every line of code manually.
Lucas (3:13)
You can't, which is why we're seeing a pivot toward behavioral baselining.
Security teams are starting to track not just what the code does, but how it interacts with the runtime environment over time. But most of these solutions are still in beta. That's why the stock market is nervous. The revenue growth is there, but the margin expansion is being eaten up by R&D costs to catch these invisible threats.
Luna (3:39)
It feels like we're paying for a shield while the enemy is learning how to walk through the walls. Is there any vendor actually solving this today?
Lucas (3:47)
There are a few, but they're niche. We're seeing some interesting moves from firms specializing in software composition analysis trying to add semantic understanding to their scanners. But it's early days. For now, most enterprises are just hoping their CI slash CD pipelines don't get poisoned.
Luna (4:06)
That sounds like a nightmare for compliance officers. If a breach happens because of a third-party library, who takes the hit? The company or the library owner?
Lucas (4:17)
Usually the company, unfortunately, unless they can prove due diligence in their supply chain vetting. And that's becoming incredibly hard to document when the threats are generated by AI in real time. It's a race between defensive automation and offensive automation.
And right now, the offense has a slight edge.
Luna (4:37)
A slight edge that keeps growing every quarter. I wonder if this will force more regulation around open-source licensing soon.
Lucas (4:45)
Probably.
We might see federal standards requiring cryptographic signing of all upstream dependencies, similar to how we handle secure boot and hardware. But until then, it's wild west territory for code integrity.
Luna (5:00)
Speaking of things that keep the show going, if today's deep dive into the supply chain traps gave you a clear picture of where the tech risks are hiding, and you've found value in cutting through the noise of those stock drops, consider buying me a coffee.
4 more minutes of transcript below
Thousands of transcripts fetched by people building searchable podcast archives
Fetch the whole transcript
The demo key returns a sample episode in full, no card needed:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090Markdown with the speakers named, for your notes, your knowledge base, or anything that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000788368021