Composition Analysis stories
Sonatype warns of surge in trusted open-source malware
3 days ago
#
application security
#
devsecops
#
supply chain
Sonatype flags 21,764 malicious open-source packages in Q1 2026, with npm hit hardest as attackers used trusted workflows to steal secrets.
Malware surge in open source software alarms firms
This month
#
malware
#
devops
#
application security
Open source malware advisories jumped in 2025 as Endor Labs warned that firms are under-prepared and budgets lag the threat.
AppOmni adds Heisenberg mode after LiteLLM supply attack
Last month
#
virtualisation
#
cloud security
#
application security
AppOmni upgrades Heisenberg to help teams trace GitHub Actions and spot tainted dependencies after the LiteLLM supply chain breach.
NetRise launches Provenance to trace open source risk
Last month
#
devops
#
iot security
#
iot
NetRise unveils Provenance, a tool to trace open source maintainers and stop risky dependencies before they spread through software.
Sonatype finds live data beats larger AI models on upgrades
Last month
#
devops
#
application security
#
supply chain
Sonatype says smaller AI tied to live software data can outsecure larger models on dependency upgrades, slashing risk and cost.
Cloudsmith adds controls to block risky dependencies
Last month
#
devops
#
cloud security
#
application security
Cloudsmith adds automated controls to quarantine and block risky dependencies, tightening enforcement on software supply chain security.
Veracode launches Fix for open-source vulnerability repair
Last month
#
devops
#
application security
#
devsecops
Veracode unveils an AI-driven tool that automatically fixes open-source vulnerabilities, tackling mounting security debt in software supply chains.
Keysight unveils SBOM Manager to meet new cyber rules
Last month
#
application security
#
physical security
#
devsecops
Keysight debuts SBOM Manager to automate software bills of materials as EU and US cyber rules tighten transparency and compliance demands.
Harness unveils AI Security & coding tools for DevSecOps
Last month
#
devops
#
application security
#
advanced persistent threat protection
Harness has launched AI Security and Secure AI Coding tools to spot and block vulnerabilities in AI-powered apps and AI-generated code.
ActiveState unveils Curated Catalog for safer code
Last month
#
application security
#
devsecops
#
supply chain
ActiveState launches Curated Catalog, a private, pre-vetted open source repository to tighten software supply chain security for enterprises.
Manifest tool boosts SBOMs for critical C & C++ code
Last month
#
application security
#
cartech
#
devsecops
Manifest unveils SBOM generator for unmanaged C and C++ code, tackling critical supply chain blind spots in embedded and safety systems.
ActiveState names Abby Kearns as new Chief Executive
Last month
#
digital transformation
#
application security
#
it automation
ActiveState appoints seasoned open source leader Abby Kearns as Chief Executive, sharpening its focus on managed open source security.
Open source dependencies leave apps dangerously exposed
Last month
#
uc
#
digital transformation
#
application security
Secure.com warns most apps hide critical flaws in open source components, as unpatched dependencies and licence risks leave firms exposed.
Endor Labs launches AURI to secure AI-driven coding
Last month
#
digital transformation
#
application security
#
devsecops
Endor Labs unveils AURI, a security intelligence platform embedding reachability-led checks into AI coding assistants and CI/CD pipelines.
Manifest flags AI readiness gap between execs & AppSec
Last month
#
digital transformation
#
cloud security
#
application security
Manifest research reveals executives overestimate AI security readiness, as AppSec teams warn of unmanaged tools, blind spots and rising risk.
Security debt surges as legacy vulnerabilities pile up
Thu, 26th Feb 2026
#
data protection
#
devops
#
application security
Security debt hits 82% of organisations as legacy flaws linger over a year, with third-party code driving most critical vulnerabilities.
AI, cloud adoption driving new surge in cyber exposure
Wed, 25th Feb 2026
#
data protection
#
digital transformation
#
pam
Rapid AI and cloud adoption is fuelling a new wave of cyber risk, as Tenable warns of exposed software supply chains and “ghost” identities.
ActiveState unveils 79m-strong secure open source catalogue
Fri, 20th Feb 2026
#
devops
#
digital transformation
#
application security
ActiveState launches a 79m-component secure open source catalogue to centralise software supply chains and cut enterprise vulnerability risk.
Endor Labs buys Autonomous Plane for container security
Fri, 13th Feb 2026
#
virtualisation
#
cloud security
#
application security
Endor Labs acquires Autonomous Plane to add reachability-led container image analysis, promising fewer false positives for security teams.
Armis unveils AI-native Centrix platform for app security
Wed, 11th Feb 2026
#
devops
#
application security
#
socs
Armis launches AI-native Centrix platform to secure application code, aiming to cut false alarms and safeguard AI-assisted development.