Sonatype says 91 Spring vulnerabilities affecting more than 209,000 software components highlight how AI is accelerating vulnerability discovery and creating a new patching challenge for DevSecOps teams.
‘Flooding Dropper’ Is Hitting npm With a Tidal Wave of Malicious Packages
Threat researchers at Sonatype are warning developers of an expanding campaign that is generating a wide range of npm accounts and dropping small numbers of malicious packages from each one, […]
Bad Actor Drops 36 Malicious Packages in npm, Targets Guardarian Users
The npm code repository is again being used by a bad actor to launch a supply chain attack that includes three dozen malicious packages that appear as Strapi CMS plugins […]
North Korean Hackers Suspected in Supply Chain Attack on Popular Axios Project
The threat actor targeted a highly popular open source project with more than 100 million weekly downloads, creating a large “blast radius.”
Two Malicious npm Packages Aim to Steal Credentials and Other Secrets
Bad actors took over a npm maintainer account and have published two malicious packages designed to steal credentials, API keys, and other secrets from the computers of victims who download […]
Navigating Compliance: Ensuring Your Software Meets Regulatory Standards
As the regulatory landscape continues to evolve, organizations face increasing pressure to comply with standards such as the Executive Order on Improving the Nation’s Cybersecurity. This panel will guide you […]
Securing Your Code: Combating Malware in the Software Supply Chain
Malware has emerged as one of the most significant threats to modern software development, especially within open-source ecosystems. This panel will explore the rise of malware attacks on the software […]
Why You Need SCA and SBOM
As software development evolves and global regulatory pressures increase, ensuring the security of your software supply chain has never been more critical. In this exclusive panel series hosted by Sonatype […]
Securing Open Source Components in a World of Mixed Committer Motivations
Our world runs on software that contains open source components. This places an increased burden on developers, as the primary consumers and deployers of those components, to use code that […]
Sonatype Report Surfaces Scope of Known Vulnerability Challenge
Sonatype this week published a State of the Software Supply Chain Report that found a 633% year-over-year increase in malicious attacks aimed at open source software residing in public repositories. […]
- 1
- 2
- 3
- …
- 6
- Next Page »











