JFrog Report Highlights Urgent Need for DevSecOps Evolution in the AI Era
The latest JFrog report, published on May 27, 2026, paints a stark picture of the escalating threat landscape, emphasizing the urgent need for DevSecOps to evolve rapidly in response to the proliferation of artificial intelligence in software development. The study, based on an extensive analysis of 18.2 billion artifacts managed through the JFrog Platform, uncovered a disturbing trend: cybercriminals are actively and increasingly targeting the very AI tools and platforms that development teams rely upon.
Specifically, security researchers identified 969 AI agent skills embedded with high-impact payloads and detected 495 malicious AI models on the Hugging Face platform, a popular repository for open-source AI models. Furthermore, 56 malicious extensions were found within the OpenVSX registry. This indicates a direct assault on the AI components integral to modern software creation, posing a significant risk to the integrity and security of applications built with these tools.
The report also highlights a concerning lack of preparedness among organizations. A survey conducted by JFrog, involving 1,508 security and DevOps professionals globally, revealed that a substantial portion of organizations are struggling to secure code generated by AI coding assistants. Nearly half of the respondents (45%) admitted that reviewing and hardening AI-generated code consumes a major amount of time, with an equal percentage still performing these crucial security checks manually. This reliance on manual processes in an increasingly automated and AI-driven development environment creates significant bottlenecks and introduces human error, making it difficult to keep pace with the speed of AI-powered attacks.
Alarmingly, despite decades of awareness regarding common vulnerabilities, the report notes a resurgence in the discovery of CWE-79 (Cross-Site Scripting), CWE-89 (SQL Injection), and CWE-74 (Injection) vulnerabilities since the rise of AI coding. This suggests that while AI accelerates development, it may also inadvertently contribute to the reintroduction or amplification of long-standing security flaws if not properly managed.
Paul Davis, Field CISO for JFrog, stressed that the findings unequivocally demonstrate the necessity for fundamental changes to current DevSecOps workflows, which are often inconsistent and inadequate. The survey data supports this, showing that while 59% of respondents attempt to enforce security at the developer workstation level and 58% at the CI/CD pipeline level, a significant 48% still depend on manual processes, and the same percentage requires a full week to establish proof of compliance.
The report concludes that the current uneven application of security practices and the struggle to automate security for AI-generated code leave organizations vulnerable. As adversaries increasingly leverage AI to discover and exploit vulnerabilities faster, a proactive and automated DevSecOps approach is no longer optional but a critical imperative for safeguarding the software supply chain in the AI era.
Read original source