{"id":965467,"date":"2026-05-20T16:55:33","date_gmt":"2026-05-20T20:55:33","guid":{"rendered":"https:\/\/www.marketnewsdesk.com\/index.php\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\/"},"modified":"2026-05-20T16:55:33","modified_gmt":"2026-05-20T20:55:33","slug":"new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs","status":"publish","type":"post","link":"https:\/\/www.marketnewsdesk.com\/index.php\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\/","title":{"rendered":"New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs"},"content":{"rendered":"<p>        <!--.bwalignc { text-align: center; list-style-position: inside }\n.bwblockalignl { margin-left: 0px; margin-right: auto }\n.bwcellpmargin { margin-bottom: 0px; margin-top: 0px }\n.bwlistdisc { list-style-type: disc }\n.bwpadl0 { padding-left: 0px }\n.bwtablemarginb { margin-bottom: 10px }\n.bwvertalignt { vertical-align: top }body {font:normal small Arial,Helvetica,sans-serif;color:#000;background-color:#fff;padding:24px;margin:0;} a img {border:0;} h3 {font-size:medium;color:#000;margin:0 0 1em 0; text-align:center;}-->  <\/p>\n<p class=\"bwalignc\"><b><i>New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs<\/i><\/b><\/p>\n<p class=\"bwalignc\"><i>The Hidden Costs of AI at Scale: JFrog\u2019s 2026 Software Supply Chain Security report shows threat actors weaponizing developer workflows, driving 177K new malicious packages, 495 malicious AI models, and a 451% increase in infected npm packages<\/i><\/p>\n<p>SUNNYVALE, Calif.&#8211;(<a href=\"http:\/\/www.businesswire.com\">BUSINESS WIRE<\/a>)&#8211;<a rel=\"nofollow\" href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fjfrog.com%2F%3Futm_source%3Dpr%26utm_medium%3Dannouncement%26utm_campaign%3Dsscstateofu%26utm_content%3Dreport&amp;esheet=54539401&amp;newsitemid=20260520126325&amp;lan=en-US&amp;anchor=JFrog+Ltd&amp;index=1&amp;md5=a69458b382d50698b248227ef504ea32\">JFrog Ltd<\/a>. (Nasdaq: FROG), the Liquid Software company and creators of the<a rel=\"nofollow\" href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fjfrog.com%2Fsoftware-supply-chain-platform%2F%3Futm_source%3Dpr%26utm_medium%3Dannouncement%26utm_campaign%3Dsscstateofu%26utm_content%3Dreport&amp;esheet=54539401&amp;newsitemid=20260520126325&amp;lan=en-US&amp;anchor=JFrog+Software+Supply+Chain+Platform&amp;index=2&amp;md5=e30b8a580ab3f90f3ea510e5eb1fa2f2\"> JFrog Software Supply Chain Platform<\/a>, the system of record for trusted software artifacts, binaries, and AI assets today announced the findings of its <a rel=\"nofollow\" href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fjfrog.com%2Fsoftware-supply-chain-state-of-union%2F%3Futm_source%3Dpr%26utm_medium%3Dannouncement%26utm_campaign%3Dsscstateofu%26utm_content%3Dreport&amp;esheet=54539401&amp;newsitemid=20260520126325&amp;lan=en-US&amp;anchor=2026+Software+Supply+Chain+Security+State+of+the+Union&amp;index=3&amp;md5=8d08e950172cac4eeba4b7fea4922852\"><b>2026 Software Supply Chain Security State of the Union <\/b><\/a>report. This year\u2019s report reveals an unprecedented acceleration in enterprise software risk as threat actors expand strikes beyond traditional package registries into AI model registries and developer tooling, creating a blind spot in current software governance frameworks.<\/p>\n<p id=\"news-body-cta\">This press release features multimedia. View the full release here: <a href=\"https:\/\/www.businesswire.com\/news\/home\/20260520126325\/en\/\" rel=\"nofollow\">https:\/\/www.businesswire.com\/news\/home\/20260520126325\/en\/<\/a><\/p>\n<div id=\"bwbodyimg\" style=\"width: 480px;float:left;padding-left:0px;padding-right:20px;padding-top:0px;padding-bottom:0px\"><img decoding=\"async\" src=\"https:\/\/mms.businesswire.com\/media\/20260520126325\/en\/2811224\/4\/1200x960.jpg\" alt=\"The AI governance gap is real - and it's coming at a high cost to enterprise organizations. The JFrog 2026 Software Supply Chain Security report shows a 451% surge in malicious npm packages, AI agent skills are a new attack surface; and 97% of orgs claim AI governance while 53% still pull models from public registries where malicious payloads have been found. Read the report to learn earn how to move from reactive patching to a governance-first framework that actually keeps pace with Al speed.\" \/><\/p>\n<p style=\"font-size:85%\">The AI governance gap is real &#8211; and it&#8217;s coming at a high cost to enterprise organizations. The JFrog 2026 Software Supply Chain Security report shows a 451% surge in malicious npm packages, AI agent skills are a new attack surface; and 97% of orgs claim AI governance while 53% still pull models from public registries where malicious payloads have been found. Read the report to learn earn how to move from reactive patching to a governance-first framework that actually keeps pace with Al speed.<\/p>\n<\/div>\n<p>\n&#8220;Every enterprise is adding AI to their software supply chain, which is increasing the attack surface for bad actors. Our report shows attackers are no longer just breaching traditional defenses \u2013 they are actively weaponizing the trusted models, registries, and agentic tools driving today&#8217;s AI-powered development. The era of &#8216;scan and hope&#8217; is over,\u201d said Shlomi Ben Haim, CEO &amp; Co-Founder, JFrog. \u201cOrganizations need a single source of truth that governs every binary, every model, and every AI agent skill from the moment it enters the pipeline to the moment it is deployed in production. This is what JFrog was built to deliver.\u201d<\/p>\n<p>\nAs AI moves from experimentation to a structural force reshaping the software supply chain, organizations are seeing a widening gap between reported security confidence and the risks accumulating in their infrastructure. Drawing on data from 18.2 billion artifacts managed across the JFrog Platform (up 136% year\u2011over\u2011year), original vulnerability research by the <a rel=\"nofollow\" href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fresearch.jfrog.com%2F%3Futm_source%3Dpr%26utm_medium%3Dannouncement%26utm_campaign%3Dsscstateofu%26utm_content%3Dreport&amp;esheet=54539401&amp;newsitemid=20260520126325&amp;lan=en-US&amp;anchor=JFrog+Security+Research&amp;index=4&amp;md5=1d85475ffa4b7fb274d330a0608472a6\">JFrog Security Research<\/a> team, and a global survey of 1,508 security and DevOps professionals <sup>1<\/sup>, this report exposes what it calls the \u201cillusion of mastery\u201d, i.e. the growing disparity between perceived security and the reality of mounting supply chain risk.<\/p>\n<p><b>Key Findings Include:<\/b><\/p>\n<ul class=\"bwlistdisc\">\n<li><b>Malicious Packages Hit an All-Time High: <\/b>Malicious npm packages surged 451% year-over-year, with 177K new malicious packages detected across registries in the last year. Attackers are exploiting trust at scale \u2013 the \u201cQix\u201d campaign used just 25 packages to compromise over 2.5 million downloads.\n<\/li>\n<li><b>AI Agent Skills Emerge as a New Attack Surface: <\/b>For the first time, JFrog tracked malicious AI agent skills \u2013 identifying 969 carrying high-impact payloads alongside 495 malicious AI models on Hugging Face and 56 malicious extensions on OpenVSX. Attackers are no longer just targeting code; they are targeting the autonomous tools that write, review, and deploy it.\n<\/li>\n<li><b>Cutting through the Noise: Vulnerabilities Are Surging and Severity Scores Are Misleading:<\/b> Over 48,000 new CVEs were disclosed in 2025, a 20% year-over-year increase partially driven by AI-generated code reintroducing decades-old weaknesses, like Injection (CWE-74), which grew 3,110%. Yet the JFrog Security Research team found that 66% of CVEs analyzed had minimal real-world applicability: volume-based triage is noise, while context and applicability become the mission-critical signals.\n<\/li>\n<li><b>The Fastest-Growing Threats Are the Least Defended: <\/b>Only 40% of organizations have adopted malicious package detection and secrets detection is active at just 28%. The categories growing fastest in threat volume remain the least covered by existing tooling.\n<\/li>\n<li><b>Security Teams Bear the Human Cost of AI: <\/b>45% of respondents say reviewing and hardening AI-generated code is now a major time drain \u2013 proving that AI hasn&#8217;t eliminated work \u2013 it\u2019s merely shifted the burden as threat actors weaponize upstream developer environments and agentic tools.\n<\/li>\n<li><b>The AI Governance Gap: <\/b>97% of organizations claim they have certified model governance \u2013 yet 53% self-host models from sources where malicious payloads have been detected, and 18% have zero governance over their integrated development environments (IDE) or Model Context Protocol (MCP) servers sitting inside their developers\u2019 workflows. Thus, the gap between reported executive confidence and actual control is widening as AI development accelerates.\n<\/li>\n<\/ul>\n<p>\n\u201cThe industry is operating with a false sense of security. Vulnerabilities are growing in number, but the real threat lies in threat actors hijacking our CI\/CD pipelines and developer tools before code even exists,\u201d said Shachar Menashe, VP of JFrog Security Research. \u201cMoving to automated, platform-native governance is no longer optional \u2013 it is the only way to secure the intelligent systems creating, approving, and distributing today\u2019s software.\u201d<\/p>\n<p>\n\u201cAI has not only changed how software is written; it has also increased the speed and scale at which zero-day vulnerabilities are exploited, and malicious software supply chain attacks are developed and distributed,\u201d said Yoav Landman, CTO and Co-Founder of JFrog. \u201cTo stay ahead, organizations need automated governance that curates every software asset entering the organization, whether introduced by agents or developers, and continuously monitors every release that contains those assets. The race is no longer about who discovers a zero-day first, because that information is advertised within minutes. It is about who can fortify their software supply chain at scale to keep their organization secure.\u201d<\/p>\n<p>\nTo explore the full findings of this year\u2019s report and learn how your organization can close the AI governance gap, <a rel=\"nofollow\" href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fjfrog.com%2Fsoftware-supply-chain-state-of-union%2F%3Futm_source%3Dpr%26utm_medium%3Dannouncement%26utm_campaign%3Dsscstateofu%26utm_content%3Dreport&amp;esheet=54539401&amp;newsitemid=20260520126325&amp;lan=en-US&amp;anchor=download+the+JFrog+2026+Software+Supply+Chain+Security+State+of+the+Union&amp;index=5&amp;md5=b4a88e7318e14ef0c1789c700d118063\">download the JFrog 2026 Software Supply Chain Security State of the Union<\/a>. You can also check out <a rel=\"nofollow\" href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fjfrog.com%2Fblog%2Fthe-ai-governance-gap-2026-software-supply-chain-report%2F%3Futm_source%3Dpr%26utm_medium%3Dannouncement%26utm_campaign%3Dsscstateofu%26utm_content%3Dreport&amp;esheet=54539401&amp;newsitemid=20260520126325&amp;lan=en-US&amp;anchor=our&amp;index=6&amp;md5=f9f3420b46d032025d89b7a05fd79a78\">our <\/a><a rel=\"nofollow\" href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fjfrog.com%2Fblog%2Fthe-ai-governance-gap-2026-software-supply-chain-report%2F&amp;esheet=54539401&amp;newsitemid=20260520126325&amp;lan=en-US&amp;anchor=blog&amp;index=7&amp;md5=e434c7ff87923e6f2357bdbf9d6f8309\">blog<\/a> or register to join JFrog Security and developer experts for an upcoming webinar \u2013 <a rel=\"nofollow\" href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fleap.jfrog.com%2FWN-MoFu-Sec-26-06-Illusion-Of-Mastery-MIX-AM-LP.html%3Futm_source%3Dpr%26utm_medium%3Dannouncement%26utm_campaign%3Dsscstateofu%26utm_content%3Dreport&amp;esheet=54539401&amp;newsitemid=20260520126325&amp;lan=en-US&amp;anchor=%26%238220%3BThe+Illusion+of+Mastery%3A+Bridging+the+Al+Governance+Gap+in+2026&amp;index=8&amp;md5=2078032c67cf38f8497334d355f525a8\"><i>\u201cThe Illusion of Mastery: Bridging the Al Governance Gap in 2026<\/i><\/a><i>\u201d <\/i><b>\u2013<\/b> detailing the challenges, threats, and necessary actions for securing your software supply chain in the AI era.<\/p>\n<p><b>Like this Story? Share this on X (a.k.a. Twitter):<\/b><i>Malicious #npm packages surged 451%; AI agent skills are now an attack surface; and 97% of orgs claim AI governance while 53% still pull models from public registries where malicious payloads have been found. The AI governance gap is real. Read the @JFrog 2026 Software Supply Chain Security report: <\/i><a rel=\"nofollow\" href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fbit.ly%2F3PRNzJB&amp;esheet=54539401&amp;newsitemid=20260520126325&amp;lan=en-US&amp;anchor=https%3A%2F%2Fbit.ly%2F3PRNzJB&amp;index=9&amp;md5=872c8a9e6196a041812ec19efa135f0f\"><i>https:\/\/bit.ly\/3PRNzJB<\/i><\/a><i>.<br \/>\n<br \/><\/i><i>#DevSecOps #SoftwareSupplyChain #Cybersecurity #AI #governance #DevGovOps<\/i><\/p>\n<p><b>About JFrog<\/b><\/p>\n<p>\nJFrog Ltd. (Nasdaq: FROG), the creators of the unified DevOps, DevSecOps, DevGovOps, and MLOps platform, is on a mission to create a world of trusted software delivery without friction from development to production. Driven by a \u201cLiquid Software\u201d vision, the JFrog Platform is a software supply chain system of record that is designed to power organizations as they build, manage, govern, and distribute secure software with speed and scale. Holistic security features help identify, protect, and remediate against threats and vulnerabilities. The universal, hybrid, multi-cloud JFrog Platform is available as both SaaS services across major cloud service providers and self-hosted. Millions of users and approximately 6,600 organizations worldwide, including a majority of the Fortune 100, depend on JFrog solutions to securely embrace digital transformation in the AI era. Learn more at <a rel=\"nofollow\" href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fjfrog.com&amp;esheet=54539401&amp;newsitemid=20260520126325&amp;lan=en-US&amp;anchor=https%3A%2F%2Fjfrog.com&amp;index=10&amp;md5=e7c70cdcc569196da9cc439484f3b8d7\">https:\/\/jfrog.com<\/a> or follow us on X @JFrog.<\/p>\n<table cellspacing=\"0\" class=\"bwtablemarginb bwblockalignl\">\n<tr>\n<td class=\"bwvertalignt bwpadl0\" rowspan=\"1\" colspan=\"1\">\n<p class=\"bwcellpmargin\">\n_______________________________________________________________________________________<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td class=\"bwvertalignt bwpadl0\" rowspan=\"1\" colspan=\"1\">\n<p class=\"bwcellpmargin\"><sup>1 <\/sup><i>JFrog commissioned <\/i><a rel=\"nofollow\" href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fwww.4media-group.com%2Fservices%2Fintelligence%2F&amp;esheet=54539401&amp;newsitemid=20260520126325&amp;lan=en-US&amp;anchor=4Media+Group%26%238217%3Bs+Atomik+Research&amp;index=11&amp;md5=ff5712b56cace5f518dd1ad68482334b\"><i>4Media Group\u2019s Atomik Research<\/i><\/a><i> to conduct an international online survey of 1,508 IT professionals across selected industries in the United States (n=508), United Kingdom (n=125), India (n=167), Germany (n=120), France (n=125), Australia (n=165), Singapore (n=174), and Spain (n=124) between Jan-Feb. 2026. Respondents were full-time employees in IT, information systems, or technology departments holding specified job functions. All worked for organizations with 1,000+ employees and confirmed a software development team of at least 50 members. The margin of error for the overall sample is \u00b13 percentage points at a 95% confidence level.<\/i><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<p>\n\u00a0<\/p>\n<p><img decoding=\"async\" alt=\"\" src=\"https:\/\/cts.businesswire.com\/ct\/CT?id=bwnews&amp;sty=20260520126325r1&amp;sid=flmnd&amp;distro=nx&amp;lang=en\" style=\"width:0;height:0\" \/><span class=\"bwct31415\" \/><\/p>\n<p id=\"mmgallerylink\"><span id=\"mmgallerylink-phrase\">View source version on businesswire.com: <\/span><span id=\"mmgallerylink-link\"><a href=\"https:\/\/www.businesswire.com\/news\/home\/20260520126325\/en\/\" rel=\"nofollow\">https:\/\/www.businesswire.com\/news\/home\/20260520126325\/en\/<\/a><\/span><\/p>\n<p><b>Media Contact:<br \/>\n<\/b><br \/>Siobhan Lyons, Director, Global Communications, <a rel=\"nofollow\" href=\"mailto:siobhanL@jfrog.com\">siobhanL@jfrog.com<\/a><\/p>\n<p><b>Investor Contact:<br \/>\n<\/b><br \/>Jeff Schreiner, VP of Investor Relations, <a rel=\"nofollow\" href=\"mailto:jeffS@jfrog.com\">jeffS@jfrog.com<\/a><\/p>\n<p><b>KEYWORDS:<\/b> United States North America California<\/p>\n<p><b>INDUSTRY KEYWORDS:<\/b> Technology Security Transport Software Internet Data Management Logistics\/Supply Chain Management Supply Chain Management Retail Artificial Intelligence<\/p>\n<p><b>MEDIA:<\/b><\/p>\n<table cellpadding=\"3\" cellspacing=\"3\">\n<tr>\n<td><font face=\"Arial\" size=\"2\"><b>Photo<\/b><\/font><\/td>\n<\/tr>\n<tr>\n<td><img decoding=\"async\" src=\"https:\/\/mms.businesswire.com\/media\/20260520126325\/en\/2811224\/3\/1200x960.jpg\" alt=\"Photo\" \/><\/td>\n<\/tr>\n<tr>\n<td><font face=\"Arial\" size=\"2\">The AI governance gap is real &#8211; and it&#8217;s coming at a high cost to enterprise organizations. The JFrog 2026 Software Supply Chain Security report shows a 451% surge in malicious npm packages, AI agent skills are a new attack surface; and 97% of orgs claim AI governance while 53% still pull models from public registries where malicious payloads have been found. Read the report to learn earn how to move from reactive patching to a governance-first framework that actually keeps pace with Al speed.<\/font><\/td>\n<\/tr>\n<tr>\n<td><font face=\"Arial\" size=\"2\"><b>Logo<\/b><\/font><\/td>\n<\/tr>\n<tr>\n<td><img decoding=\"async\" src=\"https:\/\/mms.businesswire.com\/media\/20260520126325\/en\/2343408\/3\/JFrog.jpg\" alt=\"Logo\" \/><\/td>\n<\/tr>\n<tr>\n<td><font face=\"Arial\" size=\"2\"><\/font><\/td>\n<\/tr>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs The Hidden Costs of AI at Scale: JFrog\u2019s 2026 Software Supply Chain Security report shows threat actors weaponizing developer workflows, driving 177K new malicious packages, 495 malicious AI models, and a 451% increase in infected npm packages SUNNYVALE, Calif.&#8211;(BUSINESS WIRE)&#8211;JFrog Ltd. (Nasdaq: FROG), the Liquid Software company and creators of the JFrog Software Supply Chain Platform, the system of record for trusted software artifacts, binaries, and AI assets today announced the findings of its 2026 Software Supply Chain Security State of the Union report. This year\u2019s report reveals an unprecedented acceleration in enterprise software risk as threat actors expand strikes beyond traditional package registries into &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.marketnewsdesk.com\/index.php\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-965467","post","type-post","status-publish","format-standard","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs - Market Newsdesk<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.marketnewsdesk.com\/index.php\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs - Market Newsdesk\" \/>\n<meta property=\"og:description\" content=\"New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs The Hidden Costs of AI at Scale: JFrog\u2019s 2026 Software Supply Chain Security report shows threat actors weaponizing developer workflows, driving 177K new malicious packages, 495 malicious AI models, and a 451% increase in infected npm packages SUNNYVALE, Calif.&#8211;(BUSINESS WIRE)&#8211;JFrog Ltd. (Nasdaq: FROG), the Liquid Software company and creators of the JFrog Software Supply Chain Platform, the system of record for trusted software artifacts, binaries, and AI assets today announced the findings of its 2026 Software Supply Chain Security State of the Union report. This year\u2019s report reveals an unprecedented acceleration in enterprise software risk as threat actors expand strikes beyond traditional package registries into &hellip; Continue reading &quot;New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs&quot;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.marketnewsdesk.com\/index.php\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\/\" \/>\n<meta property=\"og:site_name\" content=\"Market Newsdesk\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-20T20:55:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mms.businesswire.com\/media\/20260520126325\/en\/2811224\/4\/1200x960.jpg\" \/>\n<meta name=\"author\" content=\"Newsdesk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Newsdesk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\\\/\"},\"author\":{\"name\":\"Newsdesk\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/#\\\/schema\\\/person\\\/482f27a394d4fda80ecb5499e519d979\"},\"headline\":\"New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs\",\"datePublished\":\"2026-05-20T20:55:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\\\/\"},\"wordCount\":1430,\"image\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/mms.businesswire.com\\\/media\\\/20260520126325\\\/en\\\/2811224\\\/4\\\/1200x960.jpg\",\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\\\/\",\"url\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\\\/\",\"name\":\"New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs - Market Newsdesk\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/mms.businesswire.com\\\/media\\\/20260520126325\\\/en\\\/2811224\\\/4\\\/1200x960.jpg\",\"datePublished\":\"2026-05-20T20:55:33+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/#\\\/schema\\\/person\\\/482f27a394d4fda80ecb5499e519d979\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\\\/#primaryimage\",\"url\":\"https:\\\/\\\/mms.businesswire.com\\\/media\\\/20260520126325\\\/en\\\/2811224\\\/4\\\/1200x960.jpg\",\"contentUrl\":\"https:\\\/\\\/mms.businesswire.com\\\/media\\\/20260520126325\\\/en\\\/2811224\\\/4\\\/1200x960.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/#website\",\"url\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/\",\"name\":\"Market Newsdesk\",\"description\":\"Latest Business News in Real Time\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/#\\\/schema\\\/person\\\/482f27a394d4fda80ecb5499e519d979\",\"name\":\"Newsdesk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a0d0bd5b0f0ca12a265a459b13169dac35f33776d8501eda5e68844a366f2f46?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a0d0bd5b0f0ca12a265a459b13169dac35f33776d8501eda5e68844a366f2f46?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a0d0bd5b0f0ca12a265a459b13169dac35f33776d8501eda5e68844a366f2f46?s=96&d=mm&r=g\",\"caption\":\"Newsdesk\"},\"url\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/author\\\/newsdesk\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs - Market Newsdesk","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.marketnewsdesk.com\/index.php\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\/","og_locale":"en_US","og_type":"article","og_title":"New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs - Market Newsdesk","og_description":"New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs The Hidden Costs of AI at Scale: JFrog\u2019s 2026 Software Supply Chain Security report shows threat actors weaponizing developer workflows, driving 177K new malicious packages, 495 malicious AI models, and a 451% increase in infected npm packages SUNNYVALE, Calif.&#8211;(BUSINESS WIRE)&#8211;JFrog Ltd. (Nasdaq: FROG), the Liquid Software company and creators of the JFrog Software Supply Chain Platform, the system of record for trusted software artifacts, binaries, and AI assets today announced the findings of its 2026 Software Supply Chain Security State of the Union report. This year\u2019s report reveals an unprecedented acceleration in enterprise software risk as threat actors expand strikes beyond traditional package registries into &hellip; Continue reading \"New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs\"","og_url":"https:\/\/www.marketnewsdesk.com\/index.php\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\/","og_site_name":"Market Newsdesk","article_published_time":"2026-05-20T20:55:33+00:00","og_image":[{"url":"https:\/\/mms.businesswire.com\/media\/20260520126325\/en\/2811224\/4\/1200x960.jpg","type":"","width":"","height":""}],"author":"Newsdesk","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Newsdesk","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.marketnewsdesk.com\/index.php\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\/#article","isPartOf":{"@id":"https:\/\/www.marketnewsdesk.com\/index.php\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\/"},"author":{"name":"Newsdesk","@id":"https:\/\/www.marketnewsdesk.com\/#\/schema\/person\/482f27a394d4fda80ecb5499e519d979"},"headline":"New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs","datePublished":"2026-05-20T20:55:33+00:00","mainEntityOfPage":{"@id":"https:\/\/www.marketnewsdesk.com\/index.php\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\/"},"wordCount":1430,"image":{"@id":"https:\/\/www.marketnewsdesk.com\/index.php\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\/#primaryimage"},"thumbnailUrl":"https:\/\/mms.businesswire.com\/media\/20260520126325\/en\/2811224\/4\/1200x960.jpg","inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.marketnewsdesk.com\/index.php\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\/","url":"https:\/\/www.marketnewsdesk.com\/index.php\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\/","name":"New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs - Market Newsdesk","isPartOf":{"@id":"https:\/\/www.marketnewsdesk.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.marketnewsdesk.com\/index.php\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\/#primaryimage"},"image":{"@id":"https:\/\/www.marketnewsdesk.com\/index.php\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\/#primaryimage"},"thumbnailUrl":"https:\/\/mms.businesswire.com\/media\/20260520126325\/en\/2811224\/4\/1200x960.jpg","datePublished":"2026-05-20T20:55:33+00:00","author":{"@id":"https:\/\/www.marketnewsdesk.com\/#\/schema\/person\/482f27a394d4fda80ecb5499e519d979"},"breadcrumb":{"@id":"https:\/\/www.marketnewsdesk.com\/index.php\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.marketnewsdesk.com\/index.php\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.marketnewsdesk.com\/index.php\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\/#primaryimage","url":"https:\/\/mms.businesswire.com\/media\/20260520126325\/en\/2811224\/4\/1200x960.jpg","contentUrl":"https:\/\/mms.businesswire.com\/media\/20260520126325\/en\/2811224\/4\/1200x960.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.marketnewsdesk.com\/index.php\/new-jfrog-report-warns-ai-governance-fails-as-software-supply-chain-attacks-hit-record-highs\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.marketnewsdesk.com\/"},{"@type":"ListItem","position":2,"name":"New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs"}]},{"@type":"WebSite","@id":"https:\/\/www.marketnewsdesk.com\/#website","url":"https:\/\/www.marketnewsdesk.com\/","name":"Market Newsdesk","description":"Latest Business News in Real Time","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.marketnewsdesk.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.marketnewsdesk.com\/#\/schema\/person\/482f27a394d4fda80ecb5499e519d979","name":"Newsdesk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a0d0bd5b0f0ca12a265a459b13169dac35f33776d8501eda5e68844a366f2f46?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a0d0bd5b0f0ca12a265a459b13169dac35f33776d8501eda5e68844a366f2f46?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a0d0bd5b0f0ca12a265a459b13169dac35f33776d8501eda5e68844a366f2f46?s=96&d=mm&r=g","caption":"Newsdesk"},"url":"https:\/\/www.marketnewsdesk.com\/index.php\/author\/newsdesk\/"}]}},"_links":{"self":[{"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/posts\/965467","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/comments?post=965467"}],"version-history":[{"count":0,"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/posts\/965467\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/media?parent=965467"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/categories?post=965467"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/tags?post=965467"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}