The post How AI And Nation-States Could Put Open-Source Software At Risk appeared on BitcoinEthereumNews.com. NEW YORK, NEW YORK – JULY 19: An information screen informs travellers that train information is not running due to the global technical outage at Canal Street subway station on July 19, 2024 in New York City. Businesses and transport worldwide were affected by a global technology outage that was attributed to a software update issued by CrowdStrike, a cybersecurity firm whose software is used by many industries around the world. (Photo by Adam Gray/Getty Images) Getty Images Open-source software powers much of the modern internet – from cloud infrastructure to government services. As a digital public good, its reliability is essential to the internet and yet increasingly fragile. Despite its ubiquity, most projects are maintained by a small number of volunteers or underfunded developers. Tech giants are spending billions on artificial intelligence, but far less on securing the open-source tools that underpin their products. As The Economist put it, “the software at the heart of the internet is maintained not by giant corporations or sprawling bureaucracies but by a handful of earnest volunteers toiling in obscurity.” The rise of autonomous AI agents could destabilize this ecosystem. Nation-states and cybercriminals may soon weaponize these tools to exploit the openness of open source software. How AI Supercharges Old Threats AI can scan repositories, inject subtle backdoors, generate benign-looking contributions, or impersonate trusted developers. Stormy Peters, vice president for communities at GitHub, noted in ComputerWeekly that “China has the second-largest number of developers on GitHub by country.” That global scale matters because it amplifies the risk. Ryan Ware, an open-source security expert, sees the threat already taking shape. “AI can help with some of the social engineering aspects,” he told me. “It’s already a proven benefit to help people in creating content for social engineering efforts.” In other words, AI doesn’t need… The post How AI And Nation-States Could Put Open-Source Software At Risk appeared on BitcoinEthereumNews.com. NEW YORK, NEW YORK – JULY 19: An information screen informs travellers that train information is not running due to the global technical outage at Canal Street subway station on July 19, 2024 in New York City. Businesses and transport worldwide were affected by a global technology outage that was attributed to a software update issued by CrowdStrike, a cybersecurity firm whose software is used by many industries around the world. (Photo by Adam Gray/Getty Images) Getty Images Open-source software powers much of the modern internet – from cloud infrastructure to government services. As a digital public good, its reliability is essential to the internet and yet increasingly fragile. Despite its ubiquity, most projects are maintained by a small number of volunteers or underfunded developers. Tech giants are spending billions on artificial intelligence, but far less on securing the open-source tools that underpin their products. As The Economist put it, “the software at the heart of the internet is maintained not by giant corporations or sprawling bureaucracies but by a handful of earnest volunteers toiling in obscurity.” The rise of autonomous AI agents could destabilize this ecosystem. Nation-states and cybercriminals may soon weaponize these tools to exploit the openness of open source software. How AI Supercharges Old Threats AI can scan repositories, inject subtle backdoors, generate benign-looking contributions, or impersonate trusted developers. Stormy Peters, vice president for communities at GitHub, noted in ComputerWeekly that “China has the second-largest number of developers on GitHub by country.” That global scale matters because it amplifies the risk. Ryan Ware, an open-source security expert, sees the threat already taking shape. “AI can help with some of the social engineering aspects,” he told me. “It’s already a proven benefit to help people in creating content for social engineering efforts.” In other words, AI doesn’t need…

How AI And Nation-States Could Put Open-Source Software At Risk

2025/09/19 06:17

NEW YORK, NEW YORK – JULY 19: An information screen informs travellers that train information is not running due to the global technical outage at Canal Street subway station on July 19, 2024 in New York City. Businesses and transport worldwide were affected by a global technology outage that was attributed to a software update issued by CrowdStrike, a cybersecurity firm whose software is used by many industries around the world. (Photo by Adam Gray/Getty Images)

Getty Images

Open-source software powers much of the modern internet – from cloud infrastructure to government services. As a digital public good, its reliability is essential to the internet and yet increasingly fragile.

Despite its ubiquity, most projects are maintained by a small number of volunteers or underfunded developers. Tech giants are spending billions on artificial intelligence, but far less on securing the open-source tools that underpin their products.

As The Economist put it, “the software at the heart of the internet is maintained not by giant corporations or sprawling bureaucracies but by a handful of earnest volunteers toiling in obscurity.” The rise of autonomous AI agents could destabilize this ecosystem. Nation-states and cybercriminals may soon weaponize these tools to exploit the openness of open source software.

How AI Supercharges Old Threats

AI can scan repositories, inject subtle backdoors, generate benign-looking contributions, or impersonate trusted developers. Stormy Peters, vice president for communities at GitHub, noted in ComputerWeekly that “China has the second-largest number of developers on GitHub by country.” That global scale matters because it amplifies the risk.

Ryan Ware, an open-source security expert, sees the threat already taking shape. “AI can help with some of the social engineering aspects,” he told me. “It’s already a proven benefit to help people in creating content for social engineering efforts.”

In other words, AI doesn’t need to write malicious code to be dangerous – it just needs to talk like a developer. The same dynamic is unfolding in developer communities. As the Wall Street Journal reported, activity on Stack Overflow has collapsed by more than 90% since the launch of ChatGPT.

That decline matters because, as tech writer Nick Hodges explained in InfoWorld, “Stack Overflow provides much of the knowledge that is embedded in AI coding tools, but the more developers rely on AI coding tools the less likely they will participate in Stack Overflow, the site that produces that knowledge.”

Dan Middleton, chair of the Confidential Computing Consortium’s technical advisory committee, says, “AI agents are already a routine part of both open-source and closed source software maintenance. Many developers rely on automated tools – linters, test runners, dependency updaters – to catch common errors. The transition to AI-assisted development is accelerating.” That acceleration makes it useful to examine how past breaches unfolded.

What Past Breaches Reveal About Today’s Risks

These incidents show how a single weak link can ripple through entire systems – an effect AI could magnify. The XZ Utils backdoor offered a glimpse of how devastating a single compromise can be. Before that came the SolarWinds breach, a Russian operation that infiltrated trusted update channels across the U.S. government and industry.

Even widely used packages can rest on fragile foundations. The Node.js utility fast-glob, downloaded nearly 80 million times a week and embedded in more than 30 Department of Defense projects, is maintained by a single developer in Russia.

HONG KONG – 2019/04/05: In this photo illustration a Russian Federation flag is seen on an Android mobile device with a figure of hacker in the background. (Photo Illustration by Budrul Chukrut/SOPA Images/LightRocket via Getty Images)

LightRocket via Getty Images

While there’s no evidence of wrongdoing, the situation highlights the enormous trust placed in lone maintainers. In an article for The Register, Haden Smith of Hunted Labs noted, “Every piece of code written by Russians isn’t automatically suspect, but popular packages with no external oversight are ripe for the taking by state or state-backed actors.” The growing reliance on single maintainers shows why AI-driven threats could be so destabilizing.

AI Can Turn Small Threats Into Big Ones

With generative AI, such attacks could scale faster and operate with greater stealth. “A proliferation of independent agents can reduce the risk posed by any single compromised tool, but that also makes deep inspection of each tool more difficult,” Middleton said. “On the other hand, consolidating trust into a small set of well-vetted agents improves auditability, yet increases systemic risk.”

That systemic tension extends to volunteer capacity. Ware believes the deeper problem is capacity. “There aren’t enough resources to cover every open-source project with overworked maintainers that find their projects suddenly in use by industry,” he said.

Derek Zimmer, executive director of the Open Source Technology Improvement Fund, told me, “A majority of organizations don’t know nor fully understand how much open source they run, or their level of exposure to these kinds of threats.”

Over time, software continues to become complex, including the amount of direct and indirect dependencies on the software. “This interdependence gives rise to rich software that delivers fantastic features, but the hidden cost is the increased exposure to threats in the supply chain,” Zimmer said.

Exhausted volunteers need more support to reduce risk. “An attack where a maintainer who no longer can or wants to contribute to a critical project can simply hand off the project to a malicious actor is a very real threat, and advocacy for mechanisms to reduce the risks are few and far between,” he warned.

For now, it’s often easy to spot where AI is making contributions, because it tends to add too many extra libraries. “AI conversations are still pretty easy to spot but may not be as easy to catch in a few years. I think we are still far away from the capability being there for AI, but I have no doubt that someone will attempt to do this at scale,” Zimmer cautioned.

When AI Becomes A Spy Tool

With organizations generating more data than ever, the risk of AI-driven surveillance is only increasing. “If China develops the best AI models and DeepSeek on Alibaba Cloud becomes the dominant thing that everyone uses, it would have unfettered access to personal and business secrets,” Zimmer said.

As AI tools integrate into coding assistants and business platforms, unsuspecting users may expose sensitive data. Ware has considered detection tools to flag AI-generated contributions, but admitted that “It would be the beginning of a new cat-and-mouse game that would be ongoing for decades.”

That kind of endless cycle leaves project maintainers under immense pressure. “The open source culture needs to have a wake-up call,” Zimmer said. “Maintainers need to be notified that they are critical parts of the global supply chain.”

Nation-states are constantly searching for new ways to infiltrate their adversaries’ systems. Too many organizations take for granted the unpaid work of open source maintainers. Without greater support, these projects could one day be handed off, whether willingly or through burnout, to hostile actors or even AI agents weaponized by nation-states.

Source: https://www.forbes.com/sites/davidkirichenko/2025/09/18/how-ai-and-nation-states-could-put-open-source-software-at-risk/

Piyasa Fırsatı
Threshold Logosu
Threshold Fiyatı(T)
$0.00941
$0.00941$0.00941
-3.08%
USD
Threshold (T) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

XRP Price Prediction: Can Ripple Rally Past $2 Before the End of 2025?

XRP Price Prediction: Can Ripple Rally Past $2 Before the End of 2025?

The post XRP Price Prediction: Can Ripple Rally Past $2 Before the End of 2025? appeared first on Coinpedia Fintech News The XRP price has come under enormous pressure
Paylaş
CoinPedia2025/12/16 19:22
BlackRock boosts AI and US equity exposure in $185 billion models

BlackRock boosts AI and US equity exposure in $185 billion models

The post BlackRock boosts AI and US equity exposure in $185 billion models appeared on BitcoinEthereumNews.com. BlackRock is steering $185 billion worth of model portfolios deeper into US stocks and artificial intelligence. The decision came this week as the asset manager adjusted its entire model suite, increasing its equity allocation and dumping exposure to international developed markets. The firm now sits 2% overweight on stocks, after money moved between several of its biggest exchange-traded funds. This wasn’t a slow shuffle. Billions flowed across multiple ETFs on Tuesday as BlackRock executed the realignment. The iShares S&P 100 ETF (OEF) alone brought in $3.4 billion, the largest single-day haul in its history. The iShares Core S&P 500 ETF (IVV) collected $2.3 billion, while the iShares US Equity Factor Rotation Active ETF (DYNF) added nearly $2 billion. The rebalancing triggered swift inflows and outflows that realigned investor exposure on the back of performance data and macroeconomic outlooks. BlackRock raises equities on strong US earnings The model updates come as BlackRock backs the rally in American stocks, fueled by strong earnings and optimism around rate cuts. In an investment letter obtained by Bloomberg, the firm said US companies have delivered 11% earnings growth since the third quarter of 2024. Meanwhile, earnings across other developed markets barely touched 2%. That gap helped push the decision to drop international holdings in favor of American ones. Michael Gates, lead portfolio manager for BlackRock’s Target Allocation ETF model portfolio suite, said the US market is the only one showing consistency in sales growth, profit delivery, and revisions in analyst forecasts. “The US equity market continues to stand alone in terms of earnings delivery, sales growth and sustainable trends in analyst estimates and revisions,” Michael wrote. He added that non-US developed markets lagged far behind, especially when it came to sales. This week’s changes reflect that position. The move was made ahead of the Federal…
Paylaş
BitcoinEthereumNews2025/09/18 01:44
DMCC and Crypto.com Partner to Explore Blockchain Infrastructure for Physical Commodities

DMCC and Crypto.com Partner to Explore Blockchain Infrastructure for Physical Commodities

The Dubai Multi Commodities Centre and Crypto.com have announced a partnership to explore on-chain infrastructure for physical commodities including gold, energy, and agricultural products. The collaboration brings together one of the world's leading free trade zones with a global cryptocurrency exchange, signaling serious institutional interest in commodity tokenization.
Paylaş
MEXC NEWS2025/12/16 20:46