The Sonatype Newsroom
Explore Sonatype's latest announcements, media coverage, threat research, brand assets, and more.
Featured News and Stories
November 20, 2025
Sonatype Intelligence Reveals CVE Program Leaves Majority of Vulnerabilities Unscored
Inconsistent and delayed open source vulnerability data results in 150,000 false negatives, leaving AI-driven development pipelines exposed Fulton, ...
Read More
Press Releases
Sonatype Intelligence Reveals CVE Program Leaves Majority of Vulnerabilities Unscored
Sonatype Unveils Nexus One: An AI-Native DevSecOps Platform to Secure and Accelerate Software Innovation
Sonatype Celebrates Grand Opening of India Innovation Hub in Hyderabad
Sonatype Announces 2025 Elevate Award Winners & Finalists
Open Source Malware Surges 140% in Q3 as Attackers Target Data and Trusted Dependencies
Sonatype Named a Visionary on the 2025 Gartner® Magic Quadrant™ for Application Security Testing
Sonatype Threat Research
Powering unmatched visibility and insights
Sonatype’s world-class Security Research team leads the market in identifying and analyzing threats within the open source ecosystem. With a combination of automated intelligence, expert analysis, and secondary expansion, the team uncovers new forms of open source malware, software supply chain attacks, and emerging vulnerabilities. From in-depth reports to real-time threat detection, Sonatype Security Research powers the insights that keep our customers ahead of adversaries and sets the standard for trust in software development.
2024 in Open Source Malware Report
In the News
Sonatype Unveils Nexus One
Building Trust in the Age of AI: Sonatype CEO Bhagwat Swaroop on Why India is the Future of Software Security
“IndonesianFoods” npm Worm Publishes 44,000 Malicious Packages
Why Sonatype Bets Big on Hyderabad as Its Open-Source Security Hub
What the Dev? A developer's Hippocratic Oath in the age of AI (with Sonatype's Mitchell Johnson)
U.S. firm Sonatype opens AI innovation hub in Hyderabad
.png?width=500&height=396&name=SSCR%20-%20Computer%20Display%20(1).png)
10th Annual State of the Software Supply Chain Report
Sonatype was the first to share year-over-year analyses of open source consumption and threat data. For over a decade, the State of the Software Supply Chain® Report has provided developers and security teams with insights into trends, risks, and threats related to open source software — ultimately helping them better understand and manage their software supply chains.