惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
S
SegmentFault 最新的问题
Jina AI
Jina AI
D
DataBreaches.Net
人人都是产品经理
人人都是产品经理
罗磊的独立博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
爱范儿
爱范儿
大猫的无限游戏
大猫的无限游戏
C
Check Point Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
WordPress大学
WordPress大学
博客园 - 三生石上(FineUI控件)
B
Blog
博客园 - 【当耐特】
博客园 - Franky
M
MIT News - Artificial intelligence
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
L
LangChain Blog
MyScale Blog
MyScale Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 叶小钗
Last Week in AI
Last Week in AI
Engineering at Meta
Engineering at Meta

Press Releases

Sonatype Automates Fixes in AI-Driven Software Development Sonatype Named a Leader in the 2026 Gartner® Magic Quadrant™ Sonatype Strengthens Leadership Team for AI-Driven Growth Sonatype Firewall Extends Malicious Package Protection Sonatype and Package Registry Leaders Unite on OS Sustainability Sonatype Releases Q1 2026 Open Source Malware Index AI Grounded in Intelligence Delivers Safer Outcomes | Sonatype Sonatype Research Reveals Open Source Malware Grows 75% Sonatype Introduces Guide for Secure Agentic Development CVE Program Leaves Vulnerabilities Unscored | Sonatype Sonatype Unveils Nexus One: An AI-Native DevSecOps Platform Sonatype Grand Opening of India Innovation Hub in Hyderabad Announcing 2025 Elevate Award Winners & Finalists | Sonatype Open Source Malware Surges in Q3 as Attackers Target Dependencies Sonatype Named Visionary in 2025 Gartner® Magic Quadrant™ for AST Sonatype Launches Nexus Repository Cloud in the AI Era | Sonatype
Sonatype Research Labs Marks 15 Years of Open Source Inte...
research@son · 2026-07-14 · via Press Releases

New research finds attackers are shifting from broad malware campaigns to precision attacks targeting developers, trusted software, and AI-driven development.

Fulton, Md. – July 14, 2026 Sonatype®, the company helping enterprises build with confidence in the AI era, today marked the 15-year anniversary of Sonatype Research Labs, the team behind more than a decade of software supply chain intelligence that helps developers and security teams separate meaningful risk from advisory noise. The anniversary arrives as software supply chain attacks are undergoing their biggest transformation in decades.

Founded in 2011, Sonatype Research Labs has uncovered major malware campaigns, tracked the evolution of software supply chain attacks, and delivered the research security teams rely on to make policy and remediation decisions with confidence. That historical context and experience forms the foundation of Attacking the Assembly Line, the team's latest research report, which examines how software supply chain attacks look in the AI era.

"The AI era forced us to rethink where software supply chain research was headed. Vulnerabilities remain important, but we realized the next frontier is understanding intentionally malicious software and the attackers behind it," said Adam Cazzolla, Head of Research Labs at Sonatype. "That's exactly what Attacking the Assembly Line explores: not just how attacks are changing, but why they're changing."

The biggest AI-era shift is a change in attacker strategy. Sonatype Research Labs found attackers are increasingly investing in precision campaigns designed to influence software decisions before code is ever written. According Attacking the Assembly Line:

  • Targeted malicious package campaigns increased 75× in just two years, showing attackers are investing more effort in reaching specific developers and organizations.
  • 62% of AI-era malicious packages analyzed executed during installation, allowing attackers to steal credentials and compromise developer environments before code ever reaches production.
  • More than one in four malicious packages now use advanced stealth techniques, making malicious software harder to understand, investigate, and block.

"Fifteen years ago, people questioned whether open source vulnerabilities even mattered. Many organizations didn't realize how much open source they were actually shipping. Software supply chain attacks and software composition analysis were not a part of the conversation,” said Brian Fox, Co-founder and CTO of Sonatype and Steward of Maven Central. “Today, every organization depends on software they didn't write, and attackers know it. The challenge is no longer discovering that software supply chains matter. It's giving developers intelligence they can trust as AI changes how software gets built."

To read the full analysis from Sonatype Research Labs, visit https://www.sonatype.com/resources/research/attacking-the-assembly-line.

About Sonatype

Sonatype is the company that accelerates agentic software development with confidence. Trusted by thousands of enterprises and millions of developers, Sonatype helps organizations build with confidence by governing the open source, AI-generated, and third-party components that power modern software. As the steward of Maven Central and the company behind Nexus Repository, Sonatype provides unmatched visibility into how software is built, consumed, and secured — helping teams move faster, reduce risk, and ship software with confidence at AI scale. To learn more about Sonatype, please visit www.sonatype.com.