AI coding tools are accelerating software contribution and vulnerability remediation, but they are also expanding the volume of code that maintainers and enterprise engineering teams must validate. Open-source projects—many operating with limited funding and staff—face added exposure from AI-assisted flaw discovery and exploitation, malicious packages, incomplete software bill of materials adoption, and poor visibility into the dependencies organizations rely on.
Security leaders are being urged to treat AI-generated code as disposable implementation governed by explicit requirements, specifications, and tests rather than trusting it as inherently reviewable. AI-assisted review can help identify defects, including a generated regular expression vulnerable to catastrophic backtracking and application denial of service, but it does not remove the need for governance. Recommended controls include investing in project maintenance, documentation, secure packaging, dependency inventories, fundraising, and requirements-focused review while using automated tools to remediate issues and remove obsolete code.

Track how attackers are adapting to this technology.
6 events from the most recent confirmed update back to the earliest known activity.
Between April and October 2025, Google reported that its CodeMender agent contributed 72 security fixes to open-source projects, including projects containing up to 4.5 million lines of code.
The Linux Foundation reported $292,217,236 in revenue for 2024, while the Apache Software Foundation reported $2,379,402, illustrating uneven funding among open-source institutions.
Arthur Whitney’s 1989 J Incunabulum provided a compact C implementation of an interpreter for the J programming language, later cited by Phillip Mortimer as an example of dense and difficult-to-read software.
Carta’s Feature Flag Reaper Claude skill autonomously removed more than 400 feature flags and tens of thousands of lines of dead code. Carta also implemented a Claude skill using observability data to help remediate software problems, though it was not fully autonomous.
Phillip Mortimer described an AI code review that found catastrophic backtracking in an AI-generated regular expression. The overlapping repeated pattern could cause exponential processing when rejecting inputs and potentially lock an application in a denial-of-service condition.
Six authors writing for the ACM Technology Policy Council said AI coding tools increase the volume of code that human open-source maintainers must review and can aid both vulnerability remediation and attackers. They called for improved funding, governance, documentation, packaging, and dependency management.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.