SCA stories
Sonatype warns of surge in trusted open-source malware
3 days ago
#
application security
#
devsecops
#
supply chain
Sonatype flags 21,764 malicious open-source packages in Q1 2026, with npm hit hardest as attackers used trusted workflows to steal secrets.
Malware surge in open source software alarms firms
This month
#
malware
#
devops
#
application security
Open source malware advisories jumped in 2025 as Endor Labs warned that firms are under-prepared and budgets lag the threat.
AppOmni adds Heisenberg mode after LiteLLM supply attack
Last month
#
virtualisation
#
cloud security
#
application security
AppOmni upgrades Heisenberg to help teams trace GitHub Actions and spot tainted dependencies after the LiteLLM supply chain breach.
NetRise launches Provenance to trace open source risk
Last month
#
devops
#
iot security
#
iot
NetRise unveils Provenance, a tool to trace open source maintainers and stop risky dependencies before they spread through software.
Fime gains EMVCo recognition for biometric card tests
Last month
#
biometrics
#
fintech
#
iam
Fime's EMEA lab wins EMVCo nod to test fingerprint sensors for biometric cards, supporting global roll-out of trusted contactless payments.
Sonatype finds live data beats larger AI models on upgrades
Last month
#
devops
#
application security
#
supply chain
Sonatype says smaller AI tied to live software data can outsecure larger models on dependency upgrades, slashing risk and cost.
Veracode launches Fix for open-source vulnerability repair
Last month
#
devops
#
application security
#
devsecops
Veracode unveils an AI-driven tool that automatically fixes open-source vulnerabilities, tackling mounting security debt in software supply chains.
Harness unveils AI Security & coding tools for DevSecOps
Last month
#
devops
#
application security
#
advanced persistent threat protection
Harness has launched AI Security and Secure AI Coding tools to spot and block vulnerabilities in AI-powered apps and AI-generated code.
ActiveState unveils Curated Catalog for safer code
Last month
#
application security
#
devsecops
#
supply chain
ActiveState launches Curated Catalog, a private, pre-vetted open source repository to tighten software supply chain security for enterprises.
Manifest tool boosts SBOMs for critical C & C++ code
Last month
#
application security
#
cartech
#
devsecops
Manifest unveils SBOM generator for unmanaged C and C++ code, tackling critical supply chain blind spots in embedded and safety systems.
RateGain & Juspay launch RG Pay for travel payments
Last month
#
saas
#
digital transformation
#
fintech
RateGain and Juspay unveil RG Pay, an embedded payments layer to boost cross-border checkout performance for global travel brands.
ActiveState names Abby Kearns as new Chief Executive
Last month
#
digital transformation
#
application security
#
it automation
ActiveState appoints seasoned open source leader Abby Kearns as Chief Executive, sharpening its focus on managed open source security.
Appdome unveils Threat-Memory to track repeated attacks
Last month
#
malware
#
endpoint protection
#
application security
Appdome's new Threat-Memory tool stores on-device threat histories and AI scores to counter repeat mobile fraud and account takeovers.
Endor Labs launches AURI to secure AI-driven coding
Last month
#
digital transformation
#
application security
#
devsecops
Endor Labs unveils AURI, a security intelligence platform embedding reachability-led checks into AI coding assistants and CI/CD pipelines.
Manifest flags AI readiness gap between execs & AppSec
Last month
#
digital transformation
#
cloud security
#
application security
Manifest research reveals executives overestimate AI security readiness, as AppSec teams warn of unmanaged tools, blind spots and rising risk.
Security debt surges as legacy vulnerabilities pile up
Thu, 26th Feb 2026
#
data protection
#
devops
#
application security
Security debt hits 82% of organisations as legacy flaws linger over a year, with third-party code driving most critical vulnerabilities.
Ecommpay issues free guide to combat rising eCommerce fraud
Thu, 26th Feb 2026
#
mfa
#
fintech
#
cx
Ecommpay launches a free fraud guide for online retailers as UK payment fraud hits GBP £1.17 billion and AI-driven scams rapidly escalate.
AI, cloud adoption driving new surge in cyber exposure
Wed, 25th Feb 2026
#
data protection
#
digital transformation
#
pam
Rapid AI and cloud adoption is fuelling a new wave of cyber risk, as Tenable warns of exposed software supply chains and “ghost” identities.
ActiveState unveils 79m-strong secure open source catalogue
Fri, 20th Feb 2026
#
devops
#
digital transformation
#
application security
ActiveState launches a 79m-component secure open source catalogue to centralise software supply chains and cut enterprise vulnerability risk.
FDATA appoints Kat Cloud to strengthen open finance security
Thu, 12th Feb 2026
#
fintech
#
physical security
#
iam
FDATA names Sumsub policy lead Kat Cloud to its board, signalling a sharper focus on identity, fraud and security in North American open finance.