ScrollInsights

Vulnerabilities & exploits

Omdia survey: AI risks and stolen credentials dominate software supply chain concerns

An Omdia report from February 2026 found that 77% of organizations experienced supply chain incidents in the prior 12 months, with AI technology ranked as the top risk and 35% reporting stolen developer credentials.

Disclaimer

This article was produced by Scroll Insights News Desk using automated systems and published under our standing editorial policy. It is compiled from the primary sources linked above and is provided for general information only — it is not legal, financial, investment, tax or professional advice, and no decision should be taken on it without independent verification against those sources. Errors can be reported to corrections@scrollinsights.com and are corrected on the record.

An Omdia report released in April 2026 surveyed security practices across organizations and found widespread exposure to supply chain incidents. In the 12 months before the February survey, 77% of organizations reported experiencing a software supply chain incident, and 46% faced unauthorized access to applications and data as a result.

AI and stolen credentials pose the greatest immediate risks

AI technology ranked as the top supply chain risk at 40% of concerns, with 35% of organizations specifically worried about AI increasing or generating vulnerable code. Stolen developer credentials, secrets, or keys affected 35% of organizations in supply chain incidents, while the Shai-Hulud campaign pioneered by TeamPCP automates and scales such attacks using stolen credentials.

Third-party and open-source code was ranked second at 39% of concerns, and software dependencies third at 38%. Among reported supply chain attacks, 38% exploited known vulnerabilities in third-party software. Organizations struggle with visibility here: 36% worry about identifying vulnerabilities in third-party and open-source code, while 39% worry about vulnerability remediation in those components.

Third-party code share rises from 38% to an expected 58%

Currently, 38% of organizations report that more than half of their total software code comes from third-party sources, and 31% report the same for open-source software. Within 12 months, 58% of organizations expect more than half of their code to come from third-party sources, and 51% expect the same for open-source.

SBOMs help mitigation but deployment remains incomplete

Software bill of materials documents proved effective in mitigation: 73% of organizations found that SBOMs help with more efficient vulnerability mitigation, and 72% found them effective for implementing security controls and processes. Compliance benefits also emerged, with 68% citing help in meeting regulations. However, adoption is inconsistent—only 42% of organizations that generate an SBOM do so as a mandatory part of the process for all applications, while 55% generate them on a case-by-case basis.

Supply chain incidents created concrete costs: 37% of organizations had service-level agreements impacted by remediation steps.

Investment plans and confidence gaps

The survey found split sentiment on investment: 62% of organizations expect to make significant investments in software supply chain security, while 37% anticipate more modest investments. Yet 45% of security teams reported only moderate or less influence over security products and processes for developers, and 45% of organizations do not feel they have robust software supply chain security.

Developer readiness presents another gap. While 98% of organizations prioritize shifting security left so developers can secure their code, and 32% rank that as their top application security priority, only 45% of respondents believe their developers are completely comfortable taking on security responsibilities, with another 38% saying developers are mostly comfortable.

Secure container services and hardened container image libraries rated as very effective by 51% of organizations, ranking highest among 11 security tool categories evaluated.

Sources