"Most application security programs were built around vulnerability management, not to detect malware in the software supply ...