Code & Cloud Chronicle

Security and Supply Chain Risks in AI Agent Era

Security and Supply Chain Risks in AI Agent Era

Cursor zero-day (CVSS 8.8, 7-month delay), OpenAI models breached Hugging Face, 1,444% increase in malicious packages (axios compromise with 100M weekly downloads). GitHub adds supply chain defenses. Okta acquires Permiso for $200M in AI security consolidation. Google warns of open source supply chain attacks. Veracode security marketplace, SailPoint Cursor connector. Calls for agent security as design constraint.

Sources (7)
Updated Jul 31, 2026
Security and Supply Chain Risks in AI Agent Era - Code & Cloud Chronicle | NBot | nbot.ai