The Sonatype Newsroom
Explore Sonatype's latest announcements, media coverage, threat research, brand assets, and more.
Featured News and Stories
January 28, 2026
Sonatype Research Reveals OSS Malware Grows 75% as Yearly Open Source Downloads Surpass 9.8 Trillion
2026 State of the Software Supply Chain® report finds AI-driven development accelerates risk and expands attack surface, making enforceable AI ...
Read More
Press Releases
Sonatype Research Reveals OSS Malware Grows 75% as Yearly Open Source Downloads Surpass 9.8 Trillion
Sonatype Introduces Guide, the Intelligent Solution for Secure Agentic Development
Sonatype Intelligence Reveals CVE Program Leaves Majority of Vulnerabilities Unscored
Sonatype Unveils Nexus One: An AI-Native DevSecOps Platform to Secure and Accelerate Software Innovation
Sonatype Celebrates Grand Opening of India Innovation Hub in Hyderabad
Sonatype Announces 2025 Elevate Award Winners & Finalists
Sonatype Threat Research
Powering unmatched visibility and insights
Sonatype’s world-class Security Research team leads the market in identifying and analyzing threats within the open source ecosystem. With a combination of automated intelligence, expert analysis, and secondary expansion, the team uncovers new forms of open source malware, software supply chain attacks, and emerging vulnerabilities. From in-depth reports to real-time threat detection, Sonatype Security Research powers the insights that keep our customers ahead of adversaries and sets the standard for trust in software development.
In the News
Open source devs consider making hogs pay for every download
The Open Source Economy is Cracking and Europe’s SMEs are on the Fault Line
Software developers: Prime cyber targets and a rising risk vector for CISOs
Every Developer Is Now A Risk: AI, Accountability And The Future Of Software
Cyber Security Expo 2026: Machine trust in modern software delivery
"The CVE system isn’t working – what's next? "
.png?width=500&height=396&name=SSCR%20-%20Computer%20Display%20(1).png)
10th Annual State of the Software Supply Chain Report
Sonatype was the first to share year-over-year analyses of open source consumption and threat data. For over a decade, the State of the Software Supply Chain® Report has provided developers and security teams with insights into trends, risks, and threats related to open source software — ultimately helping them better understand and manage their software supply chains.