Extend security across the AI-powered development ecosystem—from developer tools and identities to code artifacts and production.
AI is transforming software development. Today's software supply chain extends beyond source code and open-source dependencies to include the tools, identities and processes that support software delivery across the entire SDLC. As organizations adopt coding assistants, AI models, MCP servers, skills and agents, they introduce new components that expand the attack surface.
As development accelerates, threat actors target software supply chains at an unprecedented rate. In 2025, malicious open-source packages increased by 75%, while the involvement of a third-party environment in breaches doubled from 15% to 30%.
Responding to these attacks remains a challenge. Software supply chain compromises take an average of 267 days to identify and contain. When a compromise results in a data breach, the average costs reach approximately $4.91 million.
Organizations need a new approach to supply chain security that builds trust into every stage of software development.
We’re excited to introduce Software Supply Chain Security as a dedicated module within Cortex Cloud, along with two new capabilities: Software Supply Chain Trust Scores and the Supply Chain Attack Threat Center. Together, they help organizations prevent risk and respond faster to threats across the AI-powered software development lifecycle.
What Modern Software Supply Chain Security Requires
Modern software supply chain security requires more than dependency scanning. It must provide visibility into everything that enters or modifies the software supply chain, prevent risk throughout development and give teams the context to respond quickly when new threats emerge.
Complete Visibility Across the Development Ecosystem
Security teams need a continuous inventory spanning agentic tools, AI models, MCP servers and skills, IDEs, version control systems, pipelines, code artifacts, identities and developer endpoints. That visibility must reveal what is being built, who or what can modify it and what ultimately runs in production.
Prevention Throughout the Development Lifecycle
Effective prevention stops vulnerable dependencies, exposed secrets, insecure code and untrusted artifacts before they reach production. Automated guardrails must operate throughout the development lifecycle without impeding developer velocity.
Automated Environment Mapping for Rapid Response
When new software supply chain threats emerge, teams need to determine whether their organization is affected, identify impacted assets across endpoints, development environments and production, and prioritize remediation according to exposure.
Build Trust into the AI-Powered Software Supply Chain with Cortex Cloud
As software supply chains have evolved, so has Cortex Cloud.
Software Supply Chain Security extends Cortex Cloud across the development ecosystem, connecting the tools, identities, code artifacts and production assets that determine whether builds should be trusted.
By connecting development context with production exposure, Cortex Cloud gives security and development teams a complete view of the risks affecting each software release.
Measure Software Integrity with Trust Scores
Understanding supply chain risk shouldn't require reviewing hundreds of individual findings.
New Software Supply Chain Trust Scores provide an intuitive measure of software integrity across the development lifecycle. Trust Scores evaluate the security posture of the dependencies in a software bill of materials (SBOM) and the development environment that produced the code artifact, helping teams determine which applications meet their security standards.
Trust Scores express software integrity on a 0–100 scale, with 100 indicating the highest level of trust. If a malicious package is detected in the SBOM, the Trust Score automatically drops to 0.
Rather than chasing individual alerts, teams can focus on improving the trustworthiness of code artifacts and prioritize remediation where it will have the greatest impact.
Respond Faster with the New Supply Chain Attack Threat Center
Newly disclosed CVEs, compromised developer tools and malicious packages can expose organizations to software supply chain attacks with little warning.
Each new threat raises three urgent questions:
- What happened?
- Am I affected?
- What should I do next?
Answering those questions often requires security teams to understand the threat, search their environments for affected tools and dependencies and determine whether production applications are exposed.
The Supply Chain Attack Threat Center continuously tracks emerging software supply chain threats—including newly disclosed CVEs, compromised developer tools, malicious packages and dependency attacks—and automatically maps them to your environment. Teams can immediately identify affected assets, confirm where exposure exists and prioritize the actions required to reduce it.

Instead of spending hours investigating each new software supply chain attack, teams can move directly from threat discovery to targeted remediation.
Secure Every Release from Development to Production
Software Supply Chain Trust Scores give teams a continuous measure of software integrity, while the Supply Chain Attack Threat Center shows whether emerging threats affect their environment.
Together with prevention across the development lifecycle, these capabilities help organizations stop compromised software before production and move faster when the software supply chain comes under attack.
Learn More
Learn more about Software Supply Chain Security in Cortex Cloud, explore the latest capabilities, and request a demo to see how Cortex Cloud helps you build trust into your software supply chain.