Open Source, AI and the New Attack Surface

Open source and artificial intelligence are redefining the software security landscape. As AI accelerates development and exploitation, the open-source ecosystem has become a powerful engine of innovation and a growing attack surface. In this SafeDev Talks episode, security leaders from Red Hat, TikTok, and Xygeni (https://xygeni.io/) break down how AI-driven threats are targeting open-source dependencies, pipelines, and machine learning models, and what defenders must do to stay ahead. Featuring ๐‘๐จ๐ฆ๐š๐ง ๐™๐ก๐ฎ๐ค๐จ๐ฏ (๐’๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ & ๐๐ซ๐ข๐ฏ๐š๐œ๐ฒ ๐‹๐ž๐š๐๐ž๐ซ, ๐‘๐ž๐ ๐‡๐š๐ญ),๐‹๐ž๐จ๐ง ๐‰๐จ๐ก๐ง๐ฌ๐จ๐ง (๐Ž๐Ÿ๐Ÿ๐ž๐ง๐ฌ๐ข๐ฏ๐ž ๐’๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ & ๐๐ซ๐ข๐ฏ๐š๐œ๐ฒ ๐‹๐ž๐š๐, ๐“๐ข๐ค๐“๐จ๐ค), ๐š๐ง๐ ๐‹๐ฎ๐ข๐ฌ ๐‘๐จ๐๐ซรญ๐ ๐ฎ๐ž๐ณ ๐๐ž๐ซ๐ณ๐จ๐ฌ๐š (๐‚๐“๐Ž, ๐—๐ฒ๐ ๐ž๐ง๐ข), this session explores how AI is reshaping open-source software security, from AI-driven supply chain attacks and real-world exploitation examples to weaponized code, dependency poisoning, and model manipulation. The discussion highlights how AppSec and DevSecOps teams can leverage AI for detection and auto-remediation, along with best practices for securing OSS dependencies and machine learning models within CI/CD pipelines. Youโ€™ll also learn how to build AI-native, resilient, and transparent software supply chains, supported by expert insights from leaders securing high-scale, global platforms. This session delivers practical guidance for AppSec engineers, DevSecOps practitioners, security architects, and platform teams building applications in the AI era. โญ Key Takeaways โ€ข Understand the new AI-powered attack surface in open source โ€ข Detect and mitigate AI-driven OSS supply chain threats โ€ข Apply AI responsibly for vulnerability detection and remediation โ€ข Strengthen software supply chain resilience with modern security controls โ€ข Learn from experts securing AI-native systems in production This episode is essential for anyone focused on: AI Security, Open Source Security, Software Supply Chain Security, DevSecOps, AppSec, ML Security, CI/CD Security, and Continuous Security. Subscribe to SafeDev Talks and follow Xygeni (ย ย /ย xygeniย ย ) for more insights on AI Security, DevSecOps, and secure software development. #SafeDevTalks #OpenSourceSecurity #AISecurity #AppSec #DevSecOps #SoftwareSupplyChain #CyberSecurity #OSS #ThreatDetection #SecurityAutomation #MLSecurity #AIThreats #SecureByDesign #ContinuousSecurity #Xygeni

Software Supply Chains Under Pressure: What 2025 Taught Us About Malware & AI and What Comes Next
โ–ถ๏ธŽ

Software Supply Chains Under Pressure: What 2025 Taught Us About Malware & AI and What Comes Next

AI-Powered DevSecOps. Orchestrating Security at Cloud Scale
โ–ถ๏ธŽ

AI-Powered DevSecOps. Orchestrating Security at Cloud Scale

Exposing The Solid State Donut Battery. It's Over.
โ–ถ๏ธŽ

Exposing The Solid State Donut Battery. It's Over.

Something is jamming GPS over Europe. Here's what we found
โ–ถ๏ธŽ

Something is jamming GPS over Europe. Here's what we found

AI Is Already Inside Your SDLC. Now What?
โ–ถ๏ธŽ

AI Is Already Inside Your SDLC. Now What?

Attacking AI - Jason Haddix - NDC Security 2026
โ–ถ๏ธŽ

Attacking AI - Jason Haddix - NDC Security 2026

The Uncomfortable Truth About AI โ€œReasoningโ€ | World Science Festival
โ–ถ๏ธŽ

The Uncomfortable Truth About AI โ€œReasoningโ€ | World Science Festival

Trump Gets Booed & Falls Asleep During NBA Finals, Claims War is Almost Over & Goodbye Spencer Pratt
โ–ถ๏ธŽ

Trump Gets Booed & Falls Asleep During NBA Finals, Claims War is Almost Over & Goodbye Spencer Pratt

AI Unleashed: Navigating Emerging Threats and Defenses in AppSec
โ–ถ๏ธŽ

AI Unleashed: Navigating Emerging Threats and Defenses in AppSec

Nicholas Carlini - Black-hat LLMs | [un]prompted 2026
โ–ถ๏ธŽ

Nicholas Carlini - Black-hat LLMs | [un]prompted 2026

What about Software Supply Chain Security? Essential Insights & Predictions
โ–ถ๏ธŽ

What about Software Supply Chain Security? Essential Insights & Predictions

How to Pass the Audit? Building Real AppSec aligned with ISO, NIST & CRA
โ–ถ๏ธŽ

How to Pass the Audit? Building Real AppSec aligned with ISO, NIST & CRA

Andrew Ng: Building Faster with AI
โ–ถ๏ธŽ

Andrew Ng: Building Faster with AI

OWASP's Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed
โ–ถ๏ธŽ

OWASP's Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed

The World's Most Important Machine
โ–ถ๏ธŽ

The World's Most Important Machine

This is not the AI we were promised | The Royal Society
โ–ถ๏ธŽ

This is not the AI we were promised | The Royal Society

From Code to Runtime: Why SAST + DAST Are Both Essential for Modern AppSec
โ–ถ๏ธŽ

From Code to Runtime: Why SAST + DAST Are Both Essential for Modern AppSec

HOMILรA DE HOY | DIOS AYรšDAME A CONFIAR AUNQUE NO ENTIENDA NADA | PADRE FREDDY BUSTAMANTE
โ–ถ๏ธŽ

HOMILรA DE HOY | DIOS AYรšDAME A CONFIAR AUNQUE NO ENTIENDA NADA | PADRE FREDDY BUSTAMANTE

Modular DS Connect 2026
โ–ถ๏ธŽ

Modular DS Connect 2026

Nothing has changed about software engineering | Ben Eggers | Bug Bash 2026
โ–ถ๏ธŽ

Nothing has changed about software engineering | Ben Eggers | Bug Bash 2026