ChannelLife US - Industry insider news for technology resellers

Composition Analysis stories

Flux result 20e12820 27f4 4e8a 9da9 1c2ee2ea902d

Sonatype warns of surge in trusted open-source malware

3 days ago
#
application security
#
devsecops
#
supply chain
Sonatype flags 21,764 malicious open-source packages in Q1 2026, with npm hit hardest as attackers used trusted workflows to steal secrets.
Flux result 2134aca4 e1cc 446a 8945 80553175f1f3

Malware surge in open source software alarms firms

This month
#
malware
#
devops
#
application security
Open source malware advisories jumped in 2025 as Endor Labs warned that firms are under-prepared and budgets lag the threat.
Flux result 86c5d3ff 8544 4b88 ac41 93781b8158bc

AppOmni adds Heisenberg mode after LiteLLM supply attack

Last month
#
virtualisation
#
cloud security
#
application security
AppOmni upgrades Heisenberg to help teams trace GitHub Actions and spot tainted dependencies after the LiteLLM supply chain breach.
Flux result 0b725e6f 488f 44c4 b57e 5c23a2bc516f

NetRise launches Provenance to trace open source risk

Last month
#
devops
#
iot security
#
iot
NetRise unveils Provenance, a tool to trace open source maintainers and stop risky dependencies before they spread through software.
Software engineer reviewing branching dependency tree upgrade success green

Sonatype finds live data beats larger AI models on upgrades

Last month
#
devops
#
application security
#
supply chain
Sonatype says smaller AI tied to live software data can outsecure larger models on dependency upgrades, slashing risk and cost.
Alison

Cloudsmith adds controls to block risky dependencies

Last month
#
devops
#
cloud security
#
application security
Cloudsmith adds automated controls to quarantine and block risky dependencies, tightening enforcement on software supply chain security.
Editorial software dev code review open source supply chain shield repair vulnerable deps

Veracode launches Fix for open-source vulnerability repair

Last month
#
devops
#
application security
#
devsecops
Veracode unveils an AI-driven tool that automatically fixes open-source vulnerabilities, tackling mounting security debt in software supply chains.
Software supply chain security dashboard global infrastructure

Keysight unveils SBOM Manager to meet new cyber rules

Last month
#
application security
#
physical security
#
devsecops
Keysight debuts SBOM Manager to automate software bills of materials as EU and US cyber rules tighten transparency and compliance demands.
Secure ai software engineer workstation multi screens cinematic night

Harness unveils AI Security & coding tools for DevSecOps

Last month
#
devops
#
application security
#
advanced persistent threat protection
Harness has launched AI Security and Secure AI Coding tools to spot and block vulnerabilities in AI-powered apps and AI-generated code.
Secure datacenter with shielded servers and vetted oss packages flow

ActiveState unveils Curated Catalog for safer code

Last month
#
application security
#
devsecops
#
supply chain
ActiveState launches Curated Catalog, a private, pre-vetted open source repository to tighten software supply chain security for enterprises.
Embedded circuit board to document stack symbolizing software bom

Manifest tool boosts SBOMs for critical C & C++ code

Last month
#
application security
#
cartech
#
devsecops
Manifest unveils SBOM generator for unmanaged C and C++ code, tackling critical supply chain blind spots in embedded and safety systems.
Abby kearns

ActiveState names Abby Kearns as new Chief Executive

Last month
#
digital transformation
#
application security
#
it automation
ActiveState appoints seasoned open source leader Abby Kearns as Chief Executive, sharpening its focus on managed open source security.
Moody night coding workstation puzzle piece supply chain risks

Open source dependencies leave apps dangerously exposed

Last month
#
uc
#
digital transformation
#
application security
Secure.com warns most apps hide critical flaws in open source components, as unpatched dependencies and licence risks leave firms exposed.
Software engineer ai coding security shields padlock network diagram

Endor Labs launches AURI to secure AI-driven coding

Last month
#
digital transformation
#
application security
#
devsecops
Endor Labs unveils AURI, a security intelligence platform embedding reachability-led checks into AI coding assistants and CI/CD pipelines.
Split boardroom execs vs stressed engineers ai data leak scene

Manifest flags AI readiness gap between execs & AppSec

Last month
#
digital transformation
#
cloud security
#
application security
Manifest research reveals executives overestimate AI security readiness, as AppSec teams warn of unmanaged tools, blind spots and rising risk.
Moody legacy code wall crumbling with bugs and stressed engineers

Security debt surges as legacy vulnerabilities pile up

Thu, 26th Feb 2026
#
data protection
#
devops
#
application security
Security debt hits 82% of organisations as legacy flaws linger over a year, with third-party code driving most critical vulnerabilities.
Cloudy asia pacific skyline ai data streams cyber risk art

AI, cloud adoption driving new surge in cyber exposure

Wed, 25th Feb 2026
#
data protection
#
digital transformation
#
pam
Rapid AI and cloud adoption is fuelling a new wave of cyber risk, as Tenable warns of exposed software supply chains and “ghost” identities.
Glowing secure data hub with network of open source package cubes

ActiveState unveils 79m-strong secure open source catalogue

Fri, 20th Feb 2026
#
devops
#
digital transformation
#
application security
ActiveState launches a 79m-component secure open source catalogue to centralise software supply chains and cut enterprise vulnerability risk.
Transparent container with cubes and magnifying glass security scan

Endor Labs buys Autonomous Plane for container security

Fri, 13th Feb 2026
#
virtualisation
#
cloud security
#
application security
Endor Labs acquires Autonomous Plane to add reachability-led container image analysis, promising fewer false positives for security teams.
Enterprise devops secops room dashboard threat graphs containers

Armis unveils AI-native Centrix platform for app security

Wed, 11th Feb 2026
#
devops
#
application security
#
socs
Armis launches AI-native Centrix platform to secure application code, aiming to cut false alarms and safeguard AI-assisted development.