AI-Powered Threats to the Software Supply Chain
Open source software underpins virtually every modern application. That ubiquity is a superpower for developers, but it is also an expanding attack surface. Software supply chain attacks were once rare but are now happening daily, with malicious actors exploiting the trust developers place in public registries, package managers, and CI/CD pipelines.
Chainguard is a secure software supply chain platform. The company started with hardened container images and has expanded to cover domains including VMs, language libraries, GitHub Actions, and agent skills.
Matt Moore is a co-founder and CTO of Chainguard, and a veteran of Google’s open source, container, and security infrastructure work. In this episode, Matt joins Gregor Vand to discuss lessons from recent supply chain attacks, why CI/CD pipelines are now a primary attack surface, the challenge of meaningful software inventories, the EU Cyber Resilience Act, and what the arrival of Anthropic’s Mythos model means for the pace of vulnerability discovery and the urgency of patching at machine speed.
Sponsorship inquiries:
sponsor@softwareengineeringdaily.com
The post AI-Powered Threats to the Software Supply Chain appeared first on Software Engineering Daily.
Keeping the lights on for open source
Ryan sits down with Chainguard CEO Dan Lorenc to chat about how his team is keeping the foundation of the internet—open source projects—alive by forking archived but widely-used repos to provide security maintenance and dependency upgrades. They also discuss open source’s sustainability problems when it comes to funding, security, and maintainer burnout, and how trusted stewardship can reduce risk when maintainers step away.
Episode notes:
Chainguard provides secure-by-default open source artifacts for the modern software stack, keeping important open source projects maintained instead of archived.
Chainguard just announced a whole bunch of new stuff at their user conference, Assemble.
Connect with Dan on LinkedIn.
Congrats to user Andreas Grapentin for winning a Lifejacket badge for their answer to Nested if-statement in loop vs two separate loops.
TRANSCRIPT
See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.
Lessons Going Zero to $40M ARR in Two Years | Dan Lorenc, Chainguard
Dan Lorenc is the Co-founder and CEO of Chainguard, the safe source for open source.
The internet runs on free, open source software. But as its risen in popularity, its become the latest attack point targeted by hackers and nation states.
This conversation with Dan gets into the history of open source software, cloud computing, Linux, the software supply chain, how AI will impact it, and what the next big cyber attack will look like.
Dan is an engineer, but he also loves sales and go-to-market. We unpack how Chainguard went from zero to 150 customers and a $40m ARR in two years.
Chainguard just announced a $350 million Series D led by Kleiner and IVP, and Dan unpacks the round, plus shares his secret methodology for valuing the company.
A big thank you to Dan’s Co-founder Kim Lewandowski, to Clay Fisher @ Spark, Bogomil Balkansky & Andrew Reed @ Sequoia, and Tom Loverro @ IVP for their help brainstorming topics for Dan.
Thanks to Numeral for supporting this episode, the end-to-end platform for sales tax and compliance. Try it here: https://bit.ly/NumeralThePeel
Timestamps:
(3:26) A safe source for open source
(4:57) The software supply chain
(7:19) Can you trust open source code with contributors in Russia?
(9:43) Malware attack that almost took down the entire internet
(12:40) What the next big cyber attack will look like
(15:12) How will AI impact the software supply chain
(17:53) The history of cloud computing
(21:42) Why all cloud computing runs on Linux
(23:16) How Linux + Linux distros work
(29:28) Automating open source security
(32:43) Chainguard roadmap: Libraries and VMs
(36:40) Focusing on FedRAMP
(42:44) Impact of DOGE
(44:06) Zero to $40m ARR in two years
(45:40) Learning to love sales as a technical founder
(47:24) Lessons from Frank Slootman
(51:15) How to create urgency in sales
(53:16) How to build a sales team
(58:23) Hiring Ryan Carlson from Wiz & Okta
(1:01:45) Inside Chainguard’s $350m Series D
(1:07:41) Vibe coding + Dan’s software stack
(1:09:51) Cutting his hair in front of the entire company
(1:10:27) Wearing a different suit to each board meeting
(1:12:32) Bogomil, world’s best SDR
Referenced
Check out Chainguard: https://www.chainguard.dev/
Jobs at Chainguard: https://www.chainguard.dev/careers
Prior episode with Dan: https://www.youtube.com/watch?v=AC4cOJ9n_Z8
Linux Origin Email: https://www.reddit.com/r/linux/comments/mmmlh3/linux_has_a_interested_history_this_is_one_of/
The Qualified Sales Leader: https://www.amazon.com/Qualified-Sales-Leader-Proven-Lessons/dp/0578895064
Julius, AI data analysis: https://julius.ai/
Claude Code: https://www.anthropic.com/claude-code
World’s best SDR: https://x.com/BogieBalkansky/status/1913269714882814350
2025 Chainguard Assemble Keynote: https://www.youtube.com/watch?v=adfU9LJg3I0
Follow Dan
Twitter: https://x.com/lorenc_dan
LinkedIn: https://www.linkedin.com/in/danlorenc/
Follow Turner
Twitter: https://twitter.com/TurnerNovak
LinkedIn: https://www.linkedin.com/in/turnernovak
Subscribe to my newsletter to get every episode + the transcript in your inbox every week: https://www.thespl.it/
Container Security and AI: A Talk with Chainguard's Founder
In this episode of The New Stack Makers, recorded at KubeCon + CloudNativeCon Europe, Alex Williams speaks with Ville Aikas, Chainguard founder and early Kubernetes contributor. They reflect on the evolution of container security, particularly how early assumptions—like trusting that users would validate container images—proved problematic. Aikas recalls the lack of secure defaults, such as allowing containers to run as root, stemming from the team’s internal Google perspective, which led to unrealistic expectations about external security practices.
The Kubernetes community has since made strides with governance policies, secure defaults, and standard practices like avoiding long-lived credentials and supporting federated authentication. Aikas founded Chainguard to address the need for trusted, minimal, and verifiable container images—offering zero-CVE images, transparent toolchains, and full SBOMs. This security-first philosophy now extends to virtual machines and Java dependencies via Chainguard Libraries.
The discussion also highlights the rising concerns around AI/ML security in Kubernetes, including complex model dependencies, GPU integrations, and potential attack vectors—prompting Chainguard’s move toward locked-down AI images.
Learn more from The New Stack about Container Security and AI
Chainguard Takes Aim At Vulnerable Java Libraries
Clean Container Images: A Supply Chain Security Revolution
Revolutionizing Offensive Security: A New Era With Agentic AI
Join our community of newsletter subscribers to stay on top of the news and at the top of your game.
Securing Open Source Software with Dan Lorenc, Co-founder & CEO of Chainguard
Dan Lorenc is the Co-founder and CEO of Chainguard, the best way to secure your open source software. Dan and his co-founders Kim, Matt, and Ville started the company in 2021 after spending a decade working together at Google on all things open source and software security.
They’ve since raised $116 million from investors including Spark (led Series B), Sequoia (led Series A), Amplify (led Seed), The Chainsmoker’s Mantis VC, Banana Capital, and dozens of angels in the cyber security and open source communities.
—
Topics discussed:
What is the “software supply chain”?
How the SolarWinds breach created the software supply chain security market
The history of open source software
Why open source software makes software supply chains even less secure
The moment Dan and his co-founders decided to start Chainguard
Why they started selling consulting services before even building a product
The reason their first two products solved completely different problems (top-down and bottoms-up), and why the one that didn’t work at first is now their main business
Why Chainguard decided to focus on a broad communications and marketing strategy so early on
How Dan gets quoted in major media publications as an early stage startup founder
Why Chainguard uses memes for marketing
Why Dan thinks startups should “make content optimized for the group chat”
How they raised their Seed round from Amplify a week after leaving Google
Raising a Series A from Sequoia as the market started collapsing in Spring of 2022
Dan’s advice for founders on dealing with investor inbound when not fundraising
Why he wish he hired sales reps sooner
Raising a Series B from Spark Capital to accelerate their enterprise sales process
—
Referenced:
https://www.chainguard.dev
https://www.sigstore.dev/
Battling the Trojan Horse in Open Source: https://www.sequoiacap.com/article/dan-lorenc-chainguard-spotlight/
Chainguard Series B Announcement: https://www.chainguard.dev/unchained/series-b-funding
Dan’s favorite open source project: https://github.com/jqlang/jq
Reflections on Trusting Trust: https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf
—
Where to find Dan:
Twitter: https://twitter.com/lorenc_dan
LinkedIn: https://www.linkedin.com/in/danlorenc
—
Where to find Turner:
Newsletter: https://www.thespl.it
Twitter: https://twitter.com/TurnerNovak
Banana Capital: https://bananacapital.vc
—
Production and distribution by: https://www.supermix.io
—
Want to sponsor the show? https://docs.google.com/forms/d/e/1FAIpQLSebvhBlDDfHJyQdQWs8RwpFxWg-UbG0H-VFey05QSHvLxkZPQ/viewform
The Stone Ages of Open Source Security
Ask a developer about how they got into programming, and you learn so much about them.
In this week's episode of The New Stack Makers, Chainguard founder Dan Lorenc said he got into programming halfway through college while studying mechanical engineering.
"I got into programming because we had to do simulations and stuff in MATLAB," Lorenc said. And then I switched over to Python because it was similar. And we didn't need those licenses or whatever that we needed. And then I was like, Oh, this is much faster than you know, ordering parts and going to the machine shop and reserving time, so I got into it that way."
It was three or four years ago that Lorenc got into the field of open source security.
"Open source security and supply chain security weren't buzzwords back then," Lorenc said. "Nobody was talking about it. And I kind of got paranoid about it."
Lorenc worked on the Minikube open source project at Google where he first saw how insecure it could be to work on open source projects. In the interview, he talks about the threats he saw in that work.
It was so odd for Lorenc. State of art for open source security was not state of the art at all. It was the stone age.
Lorenc said it felt weird for him to build the first release in MiniKube that did not raise questions about security.
"But I mean, this is like a 200 megabyte Go binary that people were just running as root on their laptops across the Kubernetes community," Lorenc said. "And nobody had any idea what I put in there if it matched the source on GitHub or anything. So that was pretty terrifying. And that got me paranoid about the space and kind of went down this long rabbit hole that eventually resulted in starting Chainguard.
Today, the world is burning down, and that's good for a security startup like Chainguard.
"Yeah, we've got a mess of an industry to tackle here," Lorenc said. "If you've been following the news at all, it might seem like the software industry is burning on fire or falling down or anything because of all of these security problems. It's bad news for a lot of folks, but it's good news if you're in the security space."
Good news, yes ,but how does it fit into a larger story?
"Right now, one of our big focuses is figuring out how do we explain where we fit into the bigger landscape," Lorenc. said. "Because the security market is massive and confusing and full of vendors, putting buzzwords on their websites, like zero trust and stuff like that. And it's pretty easy to get lost in that mess. And so figuring out how we position ourselves, how we handle the branding, the marketing, and making it clear to prospective customers and community members, everything exactly what it is we do and what threats our products mitigate, to make sure we're being accurate there. And conveying that to our customers. That's my big focus right now."
Knative 1.0, with Ville Aikas
We celebrate the launch of Knative 1.0 with Ville Aikas, who has been with the project since the beginning. He was also with the Kubernetes team at the beginning, and thus we cannot resist a Pete Best comparison. We also celebrate Jimmy's last show as our guest host with a rapid-fire Kubernetes quiz.
Do you have something cool to share? Some questions? Let us know:
web: kubernetespodcast.com
mail: kubernetespodcast@google.com
twitter: @kubernetespod
Chatter of the week Jimmy graduates! CNCF Landscape
The menu at the Cheesecake Factory
In-n-Out Secret Menu
Links from the interview Important programmers from Finland
Paddington Bear
University of Washington
Google Voice
Google Cloud Storage Read-after-write consistency
The Fifth Beatle
Knative Serving
Eventing
Build, which became Tekton Pipelines
Did we market Knative wrong? by Ahmet Alp Balkan
Duck typing Rubber duck debugging
Extending Knative for Fun and Profit, by Matt Moore & Ville Aikas
Subresources
Proposal for custom subresources for CRDs
Google Cloud Run
IBM Cloud Code Engine
Knative steering committee and technical oversight committee
Great artists steal
Chainguard Episode 152, guest hosted by Dan Lorenc
Episode 47, with Kim Lewandowski
SLSA
Sigstore
Ville to present at Knative community meetup on November 17 Craig presented Knative at the Kubernetes Colorado meetup in July 2018
Seattle Kraken
Ville Aikas on Twitter
Minikube, with Dan Lorenc
Minikube is a tool that makes it easy to run Kubernetes locally, by running a single-node Kubernetes cluster inside a VM on your desktop or laptop. Craig and Adam talk to author and maintainer Dan Lorenc from Google Cloud, and in the wake of the Super Bowl, discuss how "football" means something different to each of them.
Do you have something cool to share? Some questions? Let us know:
web: kubernetespodcast.com
mail: kubernetespodcast@google.com
twitter: @kubernetespod
Chatter of the week Adam watched the Super Bowl
Craig watched some Superb Owls Outside the UK, you can watch them here
You can watch some ads But not the ad for Blue Origin, which was pulled
Snow day in Seattle!
Jeff Bezos at the Super Bowl
The Daily Mail is not really news
Jeff Bezos's earnings per minute
News of the week Spark Operator for Kubernetes now in Beta IBM Cloud Databases report on the Operator Pattern
New members in the CNCF TOC Alexis Richardson from Weaveworks
Brendan Burns from Microsoft
Joe Beda from VMware
Matt Klein from Lyft
Xiang Li from Alibaba
Kelsey Hightower from Google
Google Kubernetes Engine usage metering
Advanced application deployments and traffic management with Istio on GKE GitHub repo
Megan's development workflow for Kubernetes
Ambassador 0.5.0 API Gateways are going through an identity crisis
Kubernetes as an API standard; looking toward a Rust implementation
Links from the interview Dan leads a team working on: Minikube
Skaffold
Kaniko
Knative Build
Minikube was helped in the early days by Localkube from RedSpread, who were acquired by CoreOS (who were acquired by Red Hat, who were acquired by IBM) There was also Boot2docker, but Kubernetes didn't like Docker-in-Docker much back then
Guide for developing Minikube
Other similar projects: Microk8s
Docker Desktop
Things it was hard to get working: Load balancers; solved via tunneling
Persistent volume provisioning, solved with a custom hostpath provisioner
Minikube Roadmap
Dan Lorenc on GitHub and on the web