
Cyber Confersations
Software Supply Chain Security: Why AI Is Changing the Threat Landscape | Nate Dunning, Ossprey Security
The software supply chain is getting harder to secure - and AI is accelerating the problem. In this episode of Cyber Conversations , I'm joined by Nate Dunning, CEO & Co-Founder of Ossprey Security , to talk about the growing threat around open source software, AI-powered development and the changing software supply chain. Around 90% of an enterprise's code base is built on open source, creating a huge ecosystem of dependencies that attackers can exploit. And according to Nate, the scale of the threat has changed dramatically - from around two malicious packages being published every day five years ago to two every minute in 2026 . We get into Software supply chain security - why open source dependencies have become such an attractive attack surface. AI-powered development - how tools like Claude Code and other AI coding assistants are changing the way developers build software, and creating new risks along the way. The Mythos-5 incident - what happened when an AI system created malicious packages and uploaded them to PyPI, resulting in real organisations downloading them. Behaviour vs intent - why understanding what an AI system or package actually does can be more important than what it claims it is supposed to do. ⚖️ Accountability & AI - where responsibility sits when autonomous systems cause unintended consequences. ️ The “golden path” for developers - why security needs to give engineers tools they can actually use without slowing them down or forcing them to work around security controls. Nate also talks about Ossprey's recent $2.65M pre-seed , its growing number of integrations across the developer ecosystem, and why keeping close to engineers is so important when the tools they're using are changing every few months.

