惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
C
Check Point Blog
GbyAI
GbyAI
Jina AI
Jina AI
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 司徒正美
Hacker News - Newest:
Hacker News - Newest: "LLM"
V2EX - 技术
V2EX - 技术
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
F
Full Disclosure
S
Secure Thoughts
WordPress大学
WordPress大学
博客园 - Franky
N
News and Events Feed by Topic
雷峰网
雷峰网
www.infosecurity-magazine.com
www.infosecurity-magazine.com
H
Hacker News: Front Page
N
Netflix TechBlog - Medium
Forbes - Security
Forbes - Security
TaoSecurity Blog
TaoSecurity Blog
C
CERT Recently Published Vulnerability Notes
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Vercel News
Vercel News
T
The Blog of Author Tim Ferriss
MyScale Blog
MyScale Blog
Security Latest
Security Latest
Attack and Defense Labs
Attack and Defense Labs
The Register - Security
The Register - Security
Spread Privacy
Spread Privacy
H
Help Net Security
宝玉的分享
宝玉的分享
L
LangChain Blog
MongoDB | Blog
MongoDB | Blog
I
Intezer
Schneier on Security
Schneier on Security
Latest news
Latest news
Y
Y Combinator Blog
Recent Commits to openclaw:main
Recent Commits to openclaw:main
I
InfoQ
A
About on SuperTechFans
T
Tor Project blog
Microsoft Security Blog
Microsoft Security Blog
M
MIT News - Artificial intelligence
Google DeepMind News
Google DeepMind News
Microsoft Azure Blog
Microsoft Azure Blog
T
Threat Research - Cisco Blogs
S
Schneier on Security
Cisco Talos Blog
Cisco Talos Blog
H
Heimdal Security Blog

Press Releases

Sonatype Named a Leader in the 2026 Gartner® Magic Quadrant™ Sonatype Strengthens Leadership Team for AI-Driven Growth Sonatype Firewall Extends Malicious Package Protection Sonatype and Package Registry Leaders Unite on OS Sustainability Sonatype Releases Q1 2026 Open Source Malware Index AI Grounded in Intelligence Delivers Safer Outcomes | Sonatype Sonatype Research Reveals Open Source Malware Grows 75% Sonatype Introduces Guide for Secure Agentic Development CVE Program Leaves Vulnerabilities Unscored | Sonatype Sonatype Unveils Nexus One: An AI-Native DevSecOps Platform Sonatype Grand Opening of India Innovation Hub in Hyderabad Announcing 2025 Elevate Award Winners & Finalists | Sonatype Open Source Malware Surges in Q3 as Attackers Target Dependencies Sonatype Named Visionary in 2025 Gartner® Magic Quadrant™ for AST Sonatype Launches Nexus Repository Cloud in the AI Era | Sonatype
Sonatype Research Labs Marks 15 Years of Open Source Intelligence
research@son · 2026-07-14 · via Press Releases

New research finds attackers are shifting from broad malware campaigns to precision attacks targeting developers, trusted software, and AI-driven development.

Fulton, Md. – July 14, 2026 Sonatype®, the company helping enterprises build with confidence in the AI era, today marked the 15-year anniversary of Sonatype Research Labs, the team behind more than a decade of software supply chain intelligence that helps developers and security teams separate meaningful risk from advisory noise. The anniversary arrives as software supply chain attacks are undergoing their biggest transformation in decades.

Founded in 2011, Sonatype Research Labs has uncovered major malware campaigns, tracked the evolution of software supply chain attacks, and delivered the research security teams rely on to make policy and remediation decisions with confidence. That historical context and experience forms the foundation of Attacking the Assembly Line, the team's latest research report, which examines how software supply chain attacks look in the AI era.

"The AI era forced us to rethink where software supply chain research was headed. Vulnerabilities remain important, but we realized the next frontier is understanding intentionally malicious software and the attackers behind it," said Adam Cazzolla, Head of Research Labs at Sonatype. "That's exactly what Attacking the Assembly Line explores: not just how attacks are changing, but why they're changing."

The biggest AI-era shift is a change in attacker strategy. Sonatype Research Labs found attackers are increasingly investing in precision campaigns designed to influence software decisions before code is ever written. According Attacking the Assembly Line:

  • Targeted malicious package campaigns increased 75× in just two years, showing attackers are investing more effort in reaching specific developers and organizations.
  • 62% of AI-era malicious packages analyzed executed during installation, allowing attackers to steal credentials and compromise developer environments before code ever reaches production.
  • More than one in four malicious packages now use advanced stealth techniques, making malicious software harder to understand, investigate, and block.

"Fifteen years ago, people questioned whether open source vulnerabilities even mattered. Many organizations didn't realize how much open source they were actually shipping. Software supply chain attacks and software composition analysis were not a part of the conversation,” said Brian Fox, Co-founder and CTO of Sonatype and Steward of Maven Central. “Today, every organization depends on software they didn't write, and attackers know it. The challenge is no longer discovering that software supply chains matter. It's giving developers intelligence they can trust as AI changes how software gets built."

To read the full analysis from Sonatype Research Labs, visit https://www.sonatype.com/resources/research/attacking-the-assembly-line.

About Sonatype

Sonatype is the company that accelerates agentic software development with confidence. Trusted by thousands of enterprises and millions of developers, Sonatype helps organizations build with confidence by governing the open source, AI-generated, and third-party components that power modern software. As the steward of Maven Central and the company behind Nexus Repository, Sonatype provides unmatched visibility into how software is built, consumed, and secured — helping teams move faster, reduce risk, and ship software with confidence at AI scale. To learn more about Sonatype, please visit www.sonatype.com.