Composition Analysis stories
Government agencies will gain wider access to application security tools as the partnership places Checkmarx products on Carahsoft's procurement channels.
Government buyers will gain wider access to Checkmarx tools as Carahsoft opens procurement routes through reseller networks and federal contracts.
Agentic AI, zero-day surge, sovereign cloud, and humanoid robots will define IT strategy in 2027, Info-Tech Research Group warns.
Rising demand for secure AI software development has prompted Sonatype to expand its leadership team and scale operations globally.
The award underscores rising demand for software tools that spot structural risk as AI coding assistants flood enterprise systems with new code.
The round values the software supply chain security company at USD $1 billion as AI coding boosts the flow of third-party code into production.
The pact advances a UK-led instrument towards the Moon as researchers hunt for minerals, volatiles and water ice on future commercial landings.
Attackers hid malware in familiar package workflows, prompting Sonatype to log 21,764 malicious open-source packages in the quarter.
Most engineering teams could struggle to meet EU Cyber Resilience Act reporting deadlines, with many still handling SBOMs manually or only after incidents.
Organisations remain exposed as malware in open-source packages surged in 2025, with most advisories and account takeovers reported last year.
The malicious packages could leave build systems and Kubernetes clusters exposed, prompting checks across CI/CD pipelines and AI frameworks.
Enterprises could spot compromised maintainers sooner, as the new tool maps open-source contributors, dependencies and policy breaches across builds.
Sonatype says smaller AI tied to live software data can outsecure larger models on dependency upgrades, slashing risk and cost.
Cloudsmith adds automated controls to quarantine and block risky dependencies, tightening enforcement on software supply chain security.
Veracode unveils an AI-driven tool that automatically fixes open-source vulnerabilities, tackling mounting security debt in software supply chains.
Keysight debuts SBOM Manager to automate software bills of materials as EU and US cyber rules tighten transparency and compliance demands.
The survey also found most firms still lack secrets scanning and rapid audit proof, leaving hidden credentials and compliance delays as weak spots.
Malicious open source packages are increasingly slipping past spelling checks, exposing developer data and build systems to supply-chain attacks.
Australian developers can now access free vulnerability tools as Vulnetix takes a formal role in global software flaw tracking.
Australian organisations face fresh risk of cloud and identity compromise as the cyber watchdog reissues its alert on repository attacks.