惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Azure Blog
Microsoft Azure Blog
J
Java Code Geeks
量子位
腾讯CDC
C
Check Point Blog
小众软件
小众软件
IT之家
IT之家
I
InfoQ
Hugging Face - Blog
Hugging Face - Blog
Stack Overflow Blog
Stack Overflow Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
GbyAI
GbyAI
Apple Machine Learning Research
Apple Machine Learning Research
大猫的无限游戏
大猫的无限游戏
博客园_首页
S
SegmentFault 最新的问题
The Cloudflare Blog
阮一峰的网络日志
阮一峰的网络日志
aimingoo的专栏
aimingoo的专栏
P
Proofpoint News Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Google DeepMind News
Google DeepMind News
T
Tailwind CSS Blog
Martin Fowler
Martin Fowler

The Stack

How Lloyds has transformed its trusted critical data for AI Micron's revenue surges with no end to the memory shortage in sight Ubiquiti UniFi OS vulnerabilities exploited in the wild Mistral's new OCR 4 model shows size matters EU approves €76m in state aid for chip testing firm Even FedEx is a winner of the data centre boom Why AWS thinks AI coding assistants need a new place to run Why China is forging closer ties with open-source foundations China's CPU-only supercomputer tops power list Runtime: Why 'Bring-your-own-Cloud' is taking off; the TRAIT&R framework for agents, and... AWS adds yet another security tool to speed up patching Scattered Spider: UK teen pleads guilty to TfL attack Places for People forking out £60m for new ERP system Google offers ATT&CK for bad AI, with surging cost forecast STACKUP: The Stack's weekly tech startups and funding wrap Bring Your Own Cloud: why more enterprises are buying in AWS takes NVIDIA "G7" Blackwell instances GA Runtime: Vercel sets up a new framework for agents, Databricks finds a new Genie, and… Borussia Dortmund's IT head has to sometimes think "outside of the box" Accenture stumbles after Middle East, AI, merger questions Cabinet Office offering £100k+ for AI "ambassador" Critical Splunk Enterprise vulnerability being exploited Accenture buys majority stake in OT security company Dragos npm's security rethink, Satya’s warning, a COBOL win, and... US spending billions to counter China's tech influence NatGeo Society CTO on migrating 15 years of video data to the cloud Alibaba opens French data centres in Europe cloud push SpaceX to take over Cursor in $60bn play for AI coding market Hosting firm Hetzner hikes prices sharply amid supply chain pain HSBC's CIO: AI is easy. True impact is hard.
OSS security finally gets a Magic Quadrant
Edward Targett · 2026-06-23 · via The Stack

Open source malware is a “nation-state business model”, Sonatype said pithily in its “State of the Software Supply Chain” report for 2026.

Per that report: “Attackers are exploiting high-trust open source ecosystems. 

“Malware campaigns are increasingly optimized for developer workflows, targeting credentials, CI secrets, and build environments. State-linked activity shows that these tactics are not just opportunistic, they are strategic…”

There’s no shortage of victims – just ask GitHub, or less significantly, OpenAI.

APTs, script kiddies and OSS worms

The evidence bears Sonatype’s view out; APTs are rubbing shoulders with financially motivated script kiddies on the outer reaches of npm and other OSS code repositories – even as they scramble to improve safeguards.

One example from just the past few days: Microsoft Threat Intelligence attributing the latest npm package compromise to a North Korean APT.

The threat group, dubbed Sapphire Sleet, successfully, if briefly, compromised 140 ‘Mastra’ packages (Mastra is an open-source TypeScript framework for building AI agents and RAG pipelines) and injected malware that ensured “login persistence on all three major operating systems.”

(Sonatype said it spotted 454,600 new malicious packages in 2025 across npm, PyPI, Maven Central, NuGet, and Hugging Face amid “sustained, industrialized campaigns against the people and tooling that build software.”)

A Magic Quadrant, here to help lazy CISOs!

To CISOs grappling with this increasingly visible and active threat landscape, and not finding the guidance in the likes of the S2C2 Framework quite enough, there’s now a Magic Quadrant for Software Supply Chain Security. 

There’s eight “leaders” and 18 companies represented in Gartner’s perennially controversial, yet still closely watched MQ research report.

SSCS ftw

Gartner defines software supply chain security (SSCS) tools as toolkits that use a mix of threat intelligence, software composition analysis, software bills of materials and third-party governance to “identify risk and ensure software integrity from acquisition through delivery… improving DevSecOps maturity.”

In alphabetical order, Apiiro, Black Duck, Chainguard, Checkmarx, Cycode, JFrog, Sonatype, OX Security take the coveted top right hand corner. 

Arnica, ActiveState, Endor Labs, FOSSA, GitHub, Mend.io, Lineaje, RapidFort, Reversing Labs, and Veracode also get a name-check in the report.  

The leaders get some pointed criticism too. A few samples below.

Chainguard, Gartner says, “offers limited support for in-IDE inspection or in-line remediation workflows” and “provides little flexibility to consume arbitrary upstream packages” and customers will get “tightly coupled to its build-from-source Chainguard Factory, curated artifact catalog, and continuous rebuild workflows, creating a risk of vendor lock-in.”

Meanwhile “Checkmarx’s subscription-based and forthcoming consumption-based pricing is higher than average compared to vendors in this Magic Quadrant. Customers should validate long-term cost predictability as AI-driven remediation and agent-based features increase utilization…”

And “Sonatype is lacking… features, including software pipeline security posture, developer workspace security and secrets detection…”

Purists will argue that some of these companies differ so vastly in proposition that they almost don’t belong in the same Magic Quadrant, but as a useful research point for the CISO belatedly looking to improve their security posture when it comes to open source software consumption, it may be worth a read. Most of the vendors above have provided a free version. Here’s a non-gated one.

Your views on this new MQ? Is it comparing Apples and Apples? We’re always interested in hearing from readers. 

Pop me a line on ed@thestack.technology