{"id":25658,"date":"2025-11-11T06:43:49","date_gmt":"2025-11-11T06:43:49","guid":{"rendered":"http:\/\/localhost\/?p=25658"},"modified":"2025-11-11T06:43:49","modified_gmt":"2025-11-11T06:43:49","slug":"cisos-expert-guide-to-ai-supply-chain-attacks","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=25658","title":{"rendered":"CISO&#8217;s Expert Guide To AI Supply Chain Attacks_THN:410D365E05923BD71AC0844A1D6E9BF6"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-11-11T12:02:47&#8243;,&#8221;description&#8221;:&#8221;![](data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)\\n\\nAI-enabled supply chain attacks jumped 156% last year. Discover why traditional defenses are failing and what CISOs must do now to protect their organizations.\\n\\nDownload the full CISO\u2019s expert guide to AI Supply chain attacks here. \\n\\n## **TL;DR**\\n\\n  * **AI-enabled supply chain attacks are exploding in scale and sophistication** \\\\- Malicious package uploads to open-source repositories jumped 156% in the past year.\\n  * **AI-generated malware has game-changing characteristics** \\\\- It&#8217;s polymorphic by default, context-aware, semantically camouflaged, and temporally evasive.\\n  * **Real attacks are already happening** \\\\- From the 3CX breach affecting 600,000 companies to NullBulge attacks weaponizing Hugging Face and GitHub repositories.\\n  * **Detection times have dramatically increased** \\\\- IBM&#8217;s 2025 report shows breaches take an average of 276 days to identify, with AI-assisted attacks potentially extending this window.\\n  * **Traditional security tools are struggling** \\\\- Static analysis and signature-based detection fail against threats that actively adapt.\\n  * **New defensive strategies are emerging** \\\\- Organizations are deploying AI-aware security to improve threat detection.\\n  * **Regulatory compliance is becoming mandatory** \\\\- The EU AI Act imposes penalties of up to \u20ac35 million or 7% of global revenue for serious violations.\\n  * **Immediate action is critical** \\\\- This isn&#8217;t about future-proofing but present-proofing.\\n\\n\\n\\n![](data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)\\n\\n## **The Evolution from Traditional Exploits to AI-Powered Infiltration**\\n\\nRemember when supply chain attacks meant stolen credentials and tampered updates? Those were simpler times. Today&#8217;s reality is far more interesting and infinitely more complex.\\n\\nThe software supply chain has become ground zero for a new breed of attack. Think of it like this: if traditional malware is a burglar picking your lock, AI-enabled malware is a shapeshifter that studies your security guards&#8217; routines, learns their blind spots, and transforms into the cleaning crew.\\n\\nTake the PyTorch incident. Attackers uploaded a malicious package called torchtriton to PyPI that masqueraded as a legitimate dependency. Within hours, it had infiltrated thousands of systems, exfiltrating sensitive data from machine learning environments. The kicker? This was still a \\&#8221;traditional\\&#8221; attack.\\n\\nFast forward to today, and we&#8217;re seeing something fundamentally different. Take a look at these three recent examples \u2013 \\n\\n## **1\\\\. NullBulge Group &#8211; Hugging Face \\u0026 GitHub Attacks (2024)**\\n\\nA threat actor called NullBulge conducted supply chain attacks by weaponizing code in open-source repositories on Hugging Face and GitHub, targeting AI tools and gaming software. The group compromised the ComfyUI_LLMVISION extension on GitHub and distributed malicious code through various AI platforms, using Python-based payloads that exfiltrated data via Discord webhooks and delivered customized LockBit ransomware.\\n\\n![](data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)\\n\\n## **2\\\\. Solana Web3.js Library Attack (December 2024)**\\n\\nOn December 2, 2024, attackers compromised a publish-access account for the @solana\/web3.js npm library through a phishing campaign. They published malicious versions 1.95.6 and 1.95.7 that contained backdoor code to steal private keys and drain cryptocurrency wallets, resulting in the theft of approximately $160,000\u2013$190,000 worth of crypto assets during a five-hour window.\\n\\n## **3\\\\. Wondershare RepairIt Vulnerabilities (September 2025)**\\n\\nThe AI-powered image and video enhancement application Wondershare RepairIt exposed sensitive user data through hardcoded cloud credentials in its binary. This allowed potential attackers to modify AI models and software executables and launch supply chain attacks against customers by replacing legitimate AI models retrieved automatically by the application.\\n\\nDownload the CISO\u2019s expert guide for full vendor listings and implementation steps. \\n\\n## **The Rising Threat: AI Changes Everything**\\n\\nLet&#8217;s ground this in reality. The 3CX supply chain attack of 2023 compromised software used by 600,000 companies worldwide, from American Express to Mercedes-Benz. While not definitively AI-generated, it demonstrated the polymorphic characteristics we now associate with AI-assisted attacks: each payload was unique, making signature-based detection useless.\\n\\nAccording to Sonatype&#8217;s data, malicious package uploads jumped 156% year-over-year. More concerning is the sophistication curve. MITRE&#8217;s recent analysis of PyPI malware campaigns found increasingly complex obfuscation patterns consistent with automated generation, though definitive AI attribution remains challenging.\\n\\nHere&#8217;s what makes AI-generated malware genuinely different:\\n\\n  * **Polymorphic by default:** Like a virus that rewrites its own DNA, each instance is structurally unique while maintaining the same malicious purpose.\\n  * **Context-aware:** Modern AI malware includes sandbox detection that would make a paranoid programmer proud. One recent sample waited until it detected Slack API calls and Git commits, signs of a real development environment, before activating.\\n  * **Semantically camouflaged:** The malicious code doesn&#8217;t just hide; it masquerades as legitimate functionality. We&#8217;ve seen backdoors disguised as telemetry modules, complete with convincing documentation and even unit tests.\\n  * **Temporally evasive:** Patience is a virtue, especially for malware. Some variants lie dormant for weeks or months, waiting for specific triggers or simply outlasting security audits.\\n\\n\\n\\n## **Why Traditional Security Approaches Are Failing**\\n\\nMost organizations are bringing knives to a gunfight, and the guns are now AI-powered and can dodge bullets.\\n\\nConsider the timeline of a typical breach. IBM&#8217;s Cost of a Data Breach Report 2025 found it takes organizations an average of 276 days to identify a breach and another 73 days to contain it. That&#8217;s nine months where attackers own your environment. With AI-generated variants that mutate daily, your signature-based antivirus is essentially playing whack-a-mole blindfolded.\\n\\nAI isn&#8217;t just creating better malware, it&#8217;s revolutionizing the entire attack lifecycle:\\n\\n  * **Fake Developer Personas:** Researchers have documented \\&#8221;SockPuppet\\&#8221; attacks where AI-generated developer profiles contributed legitimate code for months before injecting backdoors. These personas had GitHub histories, Stack Overflow participation, and even maintained personal blogs \u2013 all generated by AI.\\n  * **Typosquatting at Scale:** In 2024, security teams identified thousands of malicious packages targeting AI libraries. Names like openai-official, chatgpt-api, and tensorfllow (note the extra &#8216;l&#8217;) trapped thousands of developers.\\n  * **Data Poisoning:** Recent Anthropic Research demonstrated how attackers could compromise ML models at training time, inserting backdoors that activate on specific inputs. Imagine your fraud detection AI suddenly ignoring transactions from specific accounts.\\n  * **Automated Social Engineering:** Phishing isn&#8217;t just for emails anymore. AI systems are generating context-aware pull requests, comments, and even documentation that appears more legitimate than many genuine contributions.\\n\\n\\n\\n![](data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)\\n\\n## A New Framework for Defense\\n\\nForward-thinking organizations are already adapting, and the results are promising.\\n\\nThe new defensive playbook includes:\\n\\n  * **AI-Specific Detection:** Google&#8217;s OSS-Fuzz project now includes statistical analysis that identifies code patterns typical of AI generation. Early results show promise in distinguishing AI-generated from human-written code \u2013 not perfect, but a solid first line of defense.\\n  * **Behavioral Provenance Analysis:** Think of this as a polygraph for code. By tracking commit patterns, timing, and linguistic analysis of comments and documentation, systems can flag suspicious contributions. \\n  * **Fighting Fire with Fire:** Microsoft&#8217;s Counterfit and Google&#8217;s AI Red Team are using defensive AI to identify threats. These systems can identify AI-generated malware variants that evade traditional tools.\\n  * **Zero-Trust Runtime Defense:** Assume you&#8217;re already breached. Companies like Netflix have pioneered runtime application self-protection (RASP) that contains threats even after they execute. It&#8217;s like having a security guard inside every application.\\n  * **Human Verification:** The \\&#8221;proof of humanity\\&#8221; movement is gaining traction. GitHub&#8217;s push for GPG-signed commits adds friction but dramatically raises the bar for attackers.\\n\\n\\n\\n## The Regulatory Imperative\\n\\nIf the technical challenges don&#8217;t motivate you, perhaps the regulatory hammer will. The EU AI Act isn&#8217;t messing around, and neither are your potential litigators.\\n\\nThe Act explicitly addresses AI supply chain security with comprehensive requirements, including:\\n\\n  * **Transparency obligations:** Document your AI usage and supply chain controls\\n  * **Risk assessments:** Regular evaluation of AI-related threats\\n  * **Incident disclosure:** 72-hour notification for AI-involved breaches\\n  * **Strict liability:** You&#8217;re responsible even if \\&#8221;the AI did it\\&#8221;\\n\\n\\n\\nPenalties scale with your global revenue, up to \u20ac35 million or 7% of worldwide turnover for the most serious violations. For context, that would be a substantial penalty for a large tech company.\\n\\nBut here&#8217;s the silver lining: the same controls that protect against AI attacks typically satisfy most compliance requirements.\\n\\n## Your Action Plan Starts Now\\n\\nThe convergence of AI and supply chain attacks isn&#8217;t some distant threat \u2013 it&#8217;s today&#8217;s reality. But unlike many cybersecurity challenges, this one comes with a roadmap.\\n\\n**Immediate Actions (This Week):**\\n\\n  * Audit your dependencies for typosquatting variants.\\n  * Enable commit signing for critical repositories.\\n  * Review packages added in the last 90 days.\\n\\n\\n\\n**Short-term (Next Month):**\\n\\n  * Deploy behavioral analysis in your CI\/CD pipeline.\\n  * Implement runtime protection for critical applications.\\n  * Establish \\&#8221;proof of humanity\\&#8221; for new contributors.\\n\\n\\n\\n**Long-term (Next Quarter):**\\n\\n  * Integrate AI-specific detection tools.\\n  * Develop an AI incident response playbook.\\n  * Align with regulatory requirements.\\n\\n\\n\\nThe organizations that adapt now won&#8217;t just survive, they&#8217;ll have a competitive advantage. While others scramble to respond to breaches, you&#8217;ll be preventing them.\\n\\nFor the full action plan and recommended vendors, download the CISO\u2019s guide PDF here.\\n\\nFound this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.\\n&#8221;,&#8221;published&#8221;:&#8221;2025-11-11T11:58:00&#8243;,&#8221;modified&#8221;:&#8221;2025-11-11T11:58:00&#8243;,&#8221;type&#8221;:&#8221;thn&#8221;,&#8221;title&#8221;:&#8221;CISO&#8217;s Expert Guide To AI Supply Chain Attacks&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;THN:410D365E05923BD71AC0844A1D6E9BF6&#8243;,&#8221;bulletinFamily&#8221;:&#8221;info&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/thehackernews.com\/2025\/11\/cisos-expert-guide-to-ai-supply-chain.html&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-11-11T12:02:47&#8243;,&#8221;description&#8221;:&#8221;![](data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)\\n\\nAI-enabled supply chain attacks jumped 156% last year. Discover why traditional defenses are failing and what CISOs must do now to protect their organizations.\\n\\nDownload the&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,12,13,33,7,11,43,5],"class_list":["post-25658","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-exploit","tag-news","tag-none","tag-security","tag-tapic","tag-thn","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CISO&#039;s Expert Guide To AI Supply Chain Attacks_THN:410D365E05923BD71AC0844A1D6E9BF6 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=25658\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CISO&#039;s Expert Guide To AI Supply Chain Attacks_THN:410D365E05923BD71AC0844A1D6E9BF6 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-11-11T12:02:47&#8243;,&#8221;description&#8221;:&#8221;![](data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)nnAI-enabled supply chain attacks jumped 156% last year. Discover why traditional defenses are failing and what CISOs must do now to protect their organizations.nnDownload the...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=25658\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-11T06:43:49+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=25658#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=25658\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"CISO&#8217;s Expert Guide To AI Supply Chain Attacks_THN:410D365E05923BD71AC0844A1D6E9BF6\",\"datePublished\":\"2025-11-11T06:43:49+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=25658\"},\"wordCount\":1717,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"news\",\"NONE\",\"Security\",\"tapic\",\"thn\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=25658#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=25658\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=25658\",\"name\":\"CISO's Expert Guide To AI Supply Chain Attacks_THN:410D365E05923BD71AC0844A1D6E9BF6 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-11-11T06:43:49+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=25658#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=25658\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=25658#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CISO&#8217;s Expert Guide To AI Supply Chain Attacks_THN:410D365E05923BD71AC0844A1D6E9BF6\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CISO's Expert Guide To AI Supply Chain Attacks_THN:410D365E05923BD71AC0844A1D6E9BF6 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=25658","og_locale":"en_US","og_type":"article","og_title":"CISO's Expert Guide To AI Supply Chain Attacks_THN:410D365E05923BD71AC0844A1D6E9BF6 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-11-11T12:02:47&#8243;,&#8221;description&#8221;:&#8221;![](data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)nnAI-enabled supply chain attacks jumped 156% last year. Discover why traditional defenses are failing and what CISOs must do now to protect their organizations.nnDownload the...","og_url":"https:\/\/zero.redgem.net\/?p=25658","og_site_name":"zero redgem","article_published_time":"2025-11-11T06:43:49+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=25658#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=25658"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"CISO&#8217;s Expert Guide To AI Supply Chain Attacks_THN:410D365E05923BD71AC0844A1D6E9BF6","datePublished":"2025-11-11T06:43:49+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=25658"},"wordCount":1717,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","news","NONE","Security","tapic","thn","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=25658#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=25658","url":"https:\/\/zero.redgem.net\/?p=25658","name":"CISO's Expert Guide To AI Supply Chain Attacks_THN:410D365E05923BD71AC0844A1D6E9BF6 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-11-11T06:43:49+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=25658#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=25658"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=25658#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"CISO&#8217;s Expert Guide To AI Supply Chain Attacks_THN:410D365E05923BD71AC0844A1D6E9BF6"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/25658","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=25658"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/25658\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=25658"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=25658"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=25658"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}