RSSI, or Risk and Security Strategy Institutes, are tasked with safeguarding their organizations, employees, and assets from potential threats. To achieve this, they must manage a continuous stream of alerts that signal possible security issues. However, the sheer number of alerts is not the biggest challenge. A more significant concern is the uncontrolled risk — the kind that is hidden, unpredictable, or even unknown. For RSSI professionals, ignorance is not an option. The real enemy is a lack of visibility. Once a threat is understood, its mechanism identified, and its origin known, it becomes possible to respond effectively. But in a world of rapid technological advancement, the ability to identify, understand, and assess risks must keep pace with these changes.
A common viewpoint among RSSI professionals is that large language models (LLMs), such as Mythos, may amplify existing threats without fundamentally changing the landscape. This is not about spreading unnecessary fear, but about recognizing the ongoing evolution of threats. Assuming that these models only amplify known risks could lead to a dangerous oversight — the failure to make necessary changes. Although the threats may seem familiar, the capabilities available, the speed of execution, and the scale at which they can be exploited have changed dramatically.
For a long time, security teams focused on analyzing the composition of software, identifying the contents of packages, and moving on. They rarely examined the potential threats those components might carry. Today, attackers are targeting more than just open-source components. They are now aiming at the owners of code repositories, LLMs, and other tools, with the list of potential targets growing. The attack surface is no longer limited to a simple perimeter; it now spans the entire development cycle, from the creation of code to its packaging, distribution, and eventual exploitation.
According to the latest JFrog Security State of the Union report, only 12% of the most publicized security vulnerabilities (CVEs) in 2025 were actually highly exploitable in enterprise environments. Meanwhile, 66% scored between 0 and 20% on an applicability scale. These results highlight that a vulnerability is not always a real risk, especially when analyzed in context. With new-generation AI models, this analysis becomes even more complex. It is no longer just about determining whether a function is used, but also about considering data manipulation, data flow, and hidden weaknesses. Alerts should provide more context, not just the affected package, but also the data manipulation technique involved. This would allow threat intelligence teams to more effectively assess whether the risk is real. This nuance is crucial, as it helps distinguish between truly critical alerts and those that do not require immediate action, reducing the noise that complicates the daily work of security teams.
The evolution of threats highlights the need to consolidate security tools around a common data source shared by security teams, DevSecOps, and product security. In a context where threat intelligence flows are multiplying, simply increasing the number of tools that report the same information does not improve protection — it only increases complexity. This awareness is growing. The proportion of organizations using seven or more application security (AppSec) solutions has decreased from 73% to 35% in just one year. However, many companies still struggle with a growing number of tools that fragment visibility and complicate risk management. AI, however, risks reviving the same pitfalls. Many organizations are investing in tools like MCP registers, believing they have solved the problem, when they only address part of the attack surface. They then continue to add new tools to respond to each new need, without ever stepping back to question their true objective. At the core, the trap remains the same: only the tools change. The real challenge has never been to secure an isolated component, but to protect the entire AI application.
AI and Security Challenges in the Development Chain
AI-rewritten from original reportingHow it works
rssiai-securitythreat-intelligenceappsecllm-riskssecurity-tools



