The Axios incident is a useful reminder that the weak point in software supply chains is often not code, but people. If your AI workflow can run code, read logs, and touch prod, your threat model now includes social engineering with autocomplete.
9 days ago