Securing Open-Source Software in the Frontier AI Era

Oct 07, 2026
5 minutes

As frontier AI accelerates software development, reliance on open-source software (OSS) continues to grow. AI coding agents can pull vulnerable or malicious packages directly into codebases, increasing risk while reducing developer oversight.

Palo Alto Networks Unit 42 recently demonstrated how quickly frontier AI is changing vulnerability discovery. Using NOVA—an agentic research system powered by frontier AI—researchers identified more than 14,000 confirmed vulnerabilities across 3,915 open-source projects in just two months. Nearly all (99.4%) were zero-days, and 40% were rated high or critical severity.

As vulnerability discovery accelerates, threat actors have more opportunities to exploit weaknesses across the software supply chain at greater speed and scale. Security teams need continuous visibility into open-source risk and the ability to identify and remediate issues before they reach production.

Cortex® Cloud™ Software Composition Analysis (SCA) helps teams secure open-source software from code to cloud by combining preproduction scanning with live cloud runtime context to identify risk, prioritize what matters and drive remediation.

The Hidden Risk in Your Software Supply Chain

Today, only 32% of commercial software manufacturers produce a software bill of materials (SBOM) for all their products. Limited visibility makes it difficult to identify vulnerabilities, malicious packages and other risks across open-source software. Outdated components and license violations can create additional security and compliance blind spots across the application lifecycle.

Traditional SCA can compound the challenge by generating large volumes of findings without the runtime context needed to understand which risks pose the greatest threat. Critical vulnerabilities can get buried in the noise, slowing remediation and leaving applications exposed.

The Three Core Capabilities of Cortex Cloud’s SCA

Cortex Cloud allows organizations to secure open-source components without slowing innovation. By combining total visibility into open-source dependencies with context-driven prioritization and automated remediation, teams can mitigate supply chain risks at scale:

1. Complete Visibility

Cloud’s SCA automatically detects and inventories all open-source packages across your organization. It performs an in-depth scan across your repositories to continuously monitor environments and tracks pull requests to monitor any changes. Uncovering all open-source dependencies allows it to generate a detailed SBOM for total supply chain transparency.

Detecting Vulnerabilities

Cortex Cloud automatically scans all your open-source packages to find security risks, outdated versions, and hidden dependencies. This complete visibility helps you spot dangerous vulnerabilities across your code so you can fix them before they reach production.

Detecting vulnerabilities with Cortex Cloud
Image 1: Detecting vulnerabilities with Cortex Cloud

Malicious Package Detection

AI coding agents can sometimes pull dangerous code into your projects in the form of malicious packages.

Malicious package detection with Cortex Cloud
Image 2: Malicious package detection with Cortex Cloud

Cortex Cloud constantly checks your software supply chain for hidden malware. It automatically spots and blocks these malicious packages from making it into your live applications.

License Compliance & Operational Risk

Using outdated or unlicensed software can create hidden security blind spots and legal issues. Cortex Cloud tracks all your software licenses and flags old, abandoned packages to keep your applications safe, healthy, and fully compliant.

CVE in package operational risk
Image 3: CVE in package operational risk

Beyond detecting CVEs, it tracks open-source license compliance, monitors package operational health, and blocks malicious packages. Continuous enforcement mitigates legal exposure from non-compliant software, prevents operational risks from abandoned or insecure packages, and stops malicious code before deployment to eliminate the possibility of supply chain attacks.

2. Contextual Prioritization

Finding risks isn't enough. Teams need to know which vulnerabilities pose the biggest threats in real time. By calculating urgency metrics using severity and context like exploitability, Cortex Cloud’s SCA automatically highlights high-priority issues so security teams know where to focus first. Prioritization by urgency in code condenses the volume of CVEs and significantly decreases remediation time.

3. Remediation at Scale

After identifying and prioritizing CVEs, fixing them fast is crucial to keeping applications secure. Cortex Cloud streamlines dependency maintenance by guiding developers to bulk-upgrade software dependencies to their most secure version to eliminate vulnerabilities across thousands of repositories. Automating pull request fixes and providing clear manual guidance cuts the time developers spend on remediation.

For every registry container image, Cortex Cloud now automatically identifies the underlying base OS image and evaluates newer, more secure versions already approved within your corporate registry. Cortex Cloud calculates a container image migration score, which weighs security posture improvements against potential operational risks, and automatically recommends the optimal upgrade path with the highest security yield and lowest friction.

The CNAPP Advantage

Traditional application security tools often operate in silos, functioning exclusively during the preproduction phase. The fragmented approach creates critical security blind spots, leaving organizations with an ever-expanding attack surface and an overwhelming volume of alert noise that diverts teams from genuine threats. Without visibility across the entire lifecycle, security efforts can lack accurate prioritization, and remediation is often slow. With government regulations like the EU's Cyber Resilience Act (CRA) now mandating SBOMs, this lack of visibility is a compliance risk.

Cortex Cloud SCA solves the problem by embedding software composition analysis directly into a unified cloud-native application protection platform (CNAPP). By securing open-source components across every stage—before build, during deployment and after going live—it maintains consistent policy enforcement from the first line of code to production. Natively linking code scans with runtime intelligence eliminates friction and prioritizes real threats by reachability, accelerating remediation of high-risk vulnerabilities before deployment.

Ready to Secure Your Open-Source Software?

Help your engineering teams innovate faster while maintaining a secure software supply chain. Request a personalized demo of Cortex Cloud today.


Subscribe to Cloud Security Blogs!

Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more.