Manifest Joins Athena to Secure AI Software Supply Chains

Manifest Joins Athena for AI Supply Chain Security Manifest Joins Athena for AI Supply Chain Security

Manifest Cyber has joined Athena, the Chainguard-led coalition focused on coordinated defense of open-source software, adding software supply chain visibility to a group that includes JPMorganChase, Morgan Stanley, Cisco, Cloudflare, Akamai and PwC. The move gives Athena another way to identify where vulnerable open-source components reside inside commercial and third-party software—an increasingly important problem as AI accelerates both software development and vulnerability discovery.

Software supply chain security is becoming less about finding vulnerabilities and more about determining which systems actually contain them. Manifest Cyber is entering that problem through Athena, a coalition created by Chainguard to coordinate vulnerability discovery, remediation and defensive controls across the open-source ecosystem.

Manifest says its role will center on software supply chain illumination: identifying open-source components and third-party dependencies inside software products, determining whether vulnerable code is reachable, and continuously monitoring first- and third-party software as new vulnerabilities emerge.

That distinction matters because organizations cannot always rebuild the software they depend on.

A vulnerability in an open-source package embedded in an application can potentially be addressed by rebuilding the application with a hardened version. But the same component could also be buried inside a medical device, industrial controller, network appliance, vehicle system or other commercial product that an enterprise does not control at the source-code level.

In those cases, security teams need another answer. They may have to isolate the affected system, deploy a compensating control or work with the supplier. All of those responses depend on first knowing where the vulnerable component exists.

Manifest’s binary analysis capability is designed for that scenario. The company says it can inspect shipped commercial software without source-code access and identify open-source components and third-party dependencies. Its results persist, allowing subsequent vulnerability records to be checked against existing software intelligence rather than starting a new analysis each time.

The company also says its application reachability analysis can help determine whether software actually calls vulnerable code. That can provide additional context for vulnerability prioritization, although reachability is only one part of determining operational risk.

Athena’s broader model is built around sharing vulnerability intelligence before public disclosure, developing hardened fixes and adding layers of platform and network protection where immediate rebuilding is not possible. Chainguard said in July that Athena had processed more than 40,000 vulnerability findings in its first three weeks, with 42% classified as critical or high severity. Those figures are coalition-reported rather than an independent measurement of the broader vulnerability landscape.

The coalition’s premise is becoming particularly relevant to AI infrastructure. AI development platforms increasingly depend on open-source libraries, container images, model tooling, orchestration frameworks and third-party services. That creates a software chain in which vulnerabilities can move across applications, infrastructure and AI workloads.

Gartner formally identified software supply chain security as an emerging standalone capability in 2026, covering risks from open-source software as well as third-party AI. Gartner also forecasts that spending on securing AI will reach nearly $4.8 billion in 2027, up 68.7% from 2026, as organizations address vulnerabilities and other risks surrounding AI systems.

The connection between AI and supply chain security runs in both directions. AI can increase the volume and speed of software development, while frontier AI systems are also being used to discover vulnerabilities. Chainguard argues that this compresses the window between discovery and exploitation, creating pressure for security teams to coordinate rather than independently investigate every vulnerability.

NIST’s software supply chain guidance reinforces the need for visibility beyond source-code scanning. Its recommendations include software bills of materials, continuous vulnerability monitoring and, where vendor SBOMs are unavailable, binary decomposition of software installation packages. NIST specifically identifies binary software composition analysis as a way to examine supplied binaries and images for vulnerable components.

That makes Manifest’s contribution relevant beyond traditional application security. For enterprises building generative AI applications, maintaining machine learning infrastructure or deploying AI agents, the software stack can include dependencies they did not write and cannot directly rebuild.

The challenge for Athena will be turning shared intelligence into measurable protection across those heterogeneous environments. A vulnerability database alone does not establish exposure, and an automated patch does not solve vulnerabilities embedded in products controlled by another vendor.

Manifest’s addition addresses one of those gaps by connecting vulnerability intelligence with the inventory of software actually deployed across first- and third-party environments. Its foreign contributor risk capability also aims to identify ownership, control and influence considerations associated with open-source contributors and suppliers.

The result is a broader interpretation of AI infrastructure security: protecting not only models and AI applications, but the software components underneath them. As enterprise AI platforms become increasingly dependent on complex open-source and commercial ecosystems, understanding what software is actually running may become as important as detecting the vulnerability itself.

Market Landscape

Software supply chain security is moving toward continuous, asset-level visibility rather than periodic supplier questionnaires and conventional vulnerability scanning. Gartner’s 2026 research describes the market as an emerging capability covering third-party software, open-source dependencies and third-party AI.

The trend also intersects with AI security. Gartner expects the market for securing AI to approach $4.8 billion in 2027, while predicting that more than half of successful attacks against AI agents could exploit access-control weaknesses and prompt injection by 2029.

For AI development teams, that means software composition analysis, SBOMs, binary analysis, dependency reachability and supplier monitoring are increasingly connected to the broader security architecture around generative AI technologies, AI development frameworks and machine learning infrastructure.

Top Insights

  • Manifest brings binary software analysis and dependency visibility to Athena, addressing vulnerabilities embedded in commercial and third-party products.
  • Athena reported more than 40,000 processed findings within three weeks, with 42% classified as critical or high severity.
  • Binary analysis can help organizations identify vulnerable components when source code or vendor-provided SBOMs are unavailable.
  • AI-driven software development increases the importance of continuous monitoring across open-source libraries, AI frameworks and third-party infrastructure.
  • Gartner expects spending on securing AI to reach nearly $4.8 billion in 2027, reflecting rising enterprise security requirements.

Power Tomorrow’s Intelligence — Build It with TechEdgeAI

Grow Your
Brand Visibility

Looking to publish a press release, guest article, interview or podcast? Connect with us.

GET FEATURED
Subscribe

Sign up today for exclusive insights and updates.

Newsletter Signup