AI Coding Tools Are Now a Prime Target for Threat Actors

168 Views

AI-assisted coding tools have become a major attack target, with Google’s Threat Intelligence Group reporting that rapid AI adoption and reduced scrutiny of dependencies contributed to several large-scale software supply chain compromises in 2025 and early 2026.

Commenting on this, Ronald Lewis, head of cybersecurity governance at Black Duck, had the following to say :

“While the headline focuses on attackers targeting AI coding tools, the bigger story is that AI has fundamentally changed the attack surface. It’s wider because organisations are rapidly adopting AI models, agents, plugins, and new AI-enabled workflows. It’s deeper because attackers are now targeting AI intellectual property, models, prompts, and the supporting supply chain itself. At the same time, adversaries are using AI to automate reconnaissance, identify weaknesses, prioritise targets, and execute campaigns at unprecedented speed. Security teams are still working to quantify and manage these emerging risks while the attack landscape continues to evolve, but the rate of change is unsustainable for the security industry. Here’s why:

AI is fundamentally changing both the size of the attack surface and the speed and scale at which attackers can exploit it. While AI coding tools are contributing to the change in the attack surface, what we’re seeing is simply a manifestation of a much larger shift.  On one side of this shift, we have threat actors who are increasingly using AI to automate reconnaissance, evaluating a target’s attack surface, identifying and prioritising an attack map, as well as rapidly building and executing attack campaigns. We see demonstrations, such as those reported by Google, of how AI is collapsing attack timelines from weeks/months into hours. We also see entirely new classes of targets emerging: proprietary models, prompts, training data, AI agents, workflows, and AI-related intellectual property. All of these are becoming valuable assets for espionage, extortion, and theft.

A third emerging concern is the AI supply chain. The rapid adoption of AI tooling, MCP servers, open-source models, agents, plugins, and AI-focused dependencies-creates new attack paths. Adoption is increasing at a rate that exceeds most security teams’ ability to evaluate, understand, quantify, and manage the associated risks.

The challenge for defenders is that these risks are evolving faster than many organisations can quantify, measure, and govern. Security teams are no longer protecting only applications, users, and infrastructure. They must now secure AI models, agents, prompts, data pipelines, and an increasingly complex AI supply chain while also defending against adversaries using AI to accelerate attacks.”