The Sonatype Newsroom
Explore Sonatype's latest announcements, media coverage, threat research, brand assets, and more.
Featured News and Stories
December 9, 2025
Sonatype Introduces Guide, the Intelligent Solution for Secure Agentic Development
New solution connects generative and agentic AI coding assistants to real-time open source intelligence to optimize development speed, reduce ...
Read More
Press Releases
Sonatype Introduces Guide, the Intelligent Solution for Secure Agentic Development
Sonatype Intelligence Reveals CVE Program Leaves Majority of Vulnerabilities Unscored
Sonatype Unveils Nexus One: An AI-Native DevSecOps Platform to Secure and Accelerate Software Innovation
Sonatype Celebrates Grand Opening of India Innovation Hub in Hyderabad
Sonatype Announces 2025 Elevate Award Winners & Finalists
Open Source Malware Surges 140% in Q3 as Attackers Target Data and Trusted Dependencies
Sonatype Threat Research
Powering unmatched visibility and insights
Sonatype’s world-class Security Research team leads the market in identifying and analyzing threats within the open source ecosystem. With a combination of automated intelligence, expert analysis, and secondary expansion, the team uncovers new forms of open source malware, software supply chain attacks, and emerging vulnerabilities. From in-depth reports to real-time threat detection, Sonatype Security Research powers the insights that keep our customers ahead of adversaries and sets the standard for trust in software development.
2024 in Open Source Malware Report
In the News
Shai-Hulud malware is back with a vengeance and hit more than 19,000 GitHub repositories so far — here's what developers need to know
640 NPM Packages Infected in New ‘Shai-Hulud’ Supply Chain Attack
Did your npm pipeline break today? Check your ‘classic’ tokens
A concerning number of Log4j downloads are still vulnerable four years on
Sonatype Guide aims to steer secure open source agentic development
Are Trade Concerns Trumping US Cybersecurity?
.png?width=500&height=396&name=SSCR%20-%20Computer%20Display%20(1).png)
10th Annual State of the Software Supply Chain Report
Sonatype was the first to share year-over-year analyses of open source consumption and threat data. For over a decade, the State of the Software Supply Chain® Report has provided developers and security teams with insights into trends, risks, and threats related to open source software — ultimately helping them better understand and manage their software supply chains.