AI's Logic Gap Creates Provenance Debt
Identity Spoofing Fuels Supply Chain Attacks
In May 2026, the GitHub "Megalodon" campaign infected over 5,500 GitHub repositories through malicious commits disguised as legitimate automated contributions, harvesting cloud credentials and CI/CD secrets, Foresiet reported. This failure to cryptographically bind AI commits to verifiable identities drives software