#892 The AI Coding Arms Race is Transforming Software with Henrik Plate & Amod Gupta of Endor Labs

Everyone is rushing to master AI, but what does that mean for software security?

Today, we're talking to Henrik Plate and Amod Gupta from Endor Labs about their State of Dependency Management report. We discuss how AI coding assistants are introducing new security vulnerabilities, why 90% of security issues exist in code you're not even using, and how malware is now hijacking local AI agents to steal credentials.

All of this right here, right now, on the Modern CTO Podcast! 

To read Endor Labs' State of Dependency Management Report, check it out here!

About Henrik Plate

Henrik Plate is the Research Lead at Endor Labs, where he investigates software supply chain security and AI-assisted development. His work focuses on critical security challenges including vulnerable dependencies, malicious packages in open source ecosystems, and the emerging risks of AI code generation tools. Henrik's deep technical analysis has uncovered novel attack vectors, including malware that colludes with local AI agents and vulnerabilities in MCP servers. With expertise in program analysis and software security, his research directly influences how enterprises secure their development pipelines in the age of autonomous coding agents.

About Amod Gupta

Amod Gupta is the Vice President of Product and Design at Endor Labs, where he transforms cutting-edge security research into enterprise-ready solutions. Working at the intersection of customer needs and technical innovation, Amod synthesizes complex security challenges from enterprise clients and collaborates with research teams to develop practical, scalable solutions. His product philosophy centers on reachability-based vulnerability prioritization, helping organizations focus on security issues that actually matter. Amod's work emphasizes treating AI-generated code as untrusted input and building comprehensive governance frameworks for modern development tools, helping enterprises stay secure while embracing AI-assisted coding.

About Endor Labs

Endor Labs is the AppSec platform built for the AI era. It helps teams find, prioritize, and fix the most critical risks in code, whether written by humans or AI—faster.

Endor Labs understands the entire structure of your codebase, from 40 year-old C++ to modern Bazel monorepos. Powered by AI agents and the industry’s richest security dataset about open source code, Endor Labs doesn’t just flag issues, it reduces noise, prioritizes what matters most, and proposes intelligent remediations based on the context of your code.

Whether you’re an upstart or in the Fortune 500, Endor Labs helps AppSec and development teams eliminate noisy alerts, fix code 6.2x faster, and stay compliant with standards like FedRAMP, PCI, SLSA, and NIST SSDF.