
New North Korean campaign uses fake coding interviews to steal developer credentials
DPRK-aligned hackers hid malware inside SVG flag images to backdoor developer job interview coding tests. Not one antivirus vendor caught it.

DPRK-aligned hackers hid malware inside SVG flag images to backdoor developer job interview coding tests. Not one antivirus vendor caught it.

Cloudflare has deployed two WAF rules in response to high-severity vulnerabilities disclosed to us by the WordPress security team. The new rules protect all Cloudflare customers using affected WordPress versions, but customers should still update immediately to a patched release

Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data.

A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes.

When you deploy Eclipse Dataspace Components (EDC) connectors on AWS, one of the first challenges you face is predicting and controlling the cost of the required infrastructure. Without clear benchmarks, it is difficult to make informed decisions about workload sizing, environment configuration, and long-term investment. Part 1 of this 3-part blog series covered the fundamentals

Running Eclipse Dataspace Components (EDC) connectors in production on AWS requires deliberate architecture decisions around isolation, managed services, and security layering. In Part 1 of this series, we covered the fundamentals of data space architectures and EDC per the International Data Space Association’s (IDSA) standards. If you are new to EDC, we recommend starting there.

This three-part blog series offers a comprehensive guide to implementing Eclipse Dataspace Components (EDC) on AWS. The first installment lays the theoretical groundwork, covering IDSA standards, the Dataspace Protocol (DSP), and the essential architecture of EDC. The second part focuses on practical deployment patterns suitable for production, utilizing AWS services such as Amazon Elastic Container Service (ECS) and Amazon Aurora. The series ultimately aims to facilitate successful EDC implementation on AWS.

The Gemini Enterprise Agent Platform now offers 13 demos designed to showcase its capabilities for building, scaling, governing, and optimizing AI agents. Users can use the Agents CLI with various coding agents to create intelligent agents efficiently. Demos include building basic agents, event-driven workflows, and securing agent lifecycles, among others. Detailed tutorials guide users through concepts from initial setup to deployment and optimization, emphasizing practical applications and the ease of integration in enterprise environments. Start building agents using this versatile platform today.

BigQuery introduces data governance tags, providing an enhanced method for securing sensitive information in response to evolving data complexities. These tags enable users to create a hierarchical tag tree for column-level security, allowing for global application and automatic disaster recovery across regions. The implementation involves three steps: creating the tag key and values, attaching tags to columns via JSON schema, and defining access policies. This system offers flexibility and enhances data protection, positioning it as a significant upgrade from previous policy tags. Future updates will further improve these capabilities.

Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel.

Residential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek “clean” residential proxies and combine them with browser fingerprints, device profiles, and other identity signals to evade modern fraud detection.

For the tech chief at the electric vehicle racing organisation, innovation extends from everything digital to all the technology elements that make the growing motorsport operation a success

A new ransomware strain named Spirals was identified in an attack against an IT services company in South Asia. Attackers were able to transition from gaining initial access to stealing data and encrypting the network in under 24 hours. Developed in Rust, Spirals quickly encrypts files using a unique AES-128 key for each file, with each key protected by an attacker-controlled ECDH. This rapid execution highlights the growing sophistication of ransomware attacks.

A security researcher using the “Nightmare Eclipse” handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems.

KubeCon + CloudNativeCon India 2026 brought the cloud native community to Mumbai on June 18-19. For LitmusChaos, this was not just another conference. It was one of our most significant events to date. We walked away…

Apple has issued a warning to iPhone and iPad users about a new scam involving FaceTime calls. Fraudsters are impersonating trusted organizations to deceive users into sharing sensitive information such as account passwords, security codes, and financial details. They can even spoof phone numbers, making it appear as though the call is coming from legitimate sources like Apple or banks, enhancing their scam’s plausibility. Users are urged to remain vigilant against such tactics.

Optimizing token consumption is essential for enhancing AI coding assistants’ speed and accuracy. Users should adopt structured habits to ensure an efficient feedback loop. Key strategies include starting with basic models, utilizing reusable skills, automating tasks with scripts, delegating output-heavy jobs to sub-agents, and being specific with context. Additionally, users should shift testing early, update rules as needed, avoid uncontrolled loops, and initiate new sessions for different topics. Effective token management balances user direction and automation, ultimately improving productivity while managing costs.

Microsoft announced that Windows Server 2022 will reach the mainstream end date in October 2026, but will switch to extended support and continue receiving security updates for five more years.

U.S. prosecutors on Thursday charged a New York man and woman for their roles in a large-scale crime ring that laundered money stolen in cyber investment fraud scams.

If signed off, cloud-based EPOS system will replace controversial Horizon software from Fujitsu

The retail bank is one of 11 organisations testing quantum technologies as part of Digital Catapult’s quantum technology access programme

CISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detection platform.

David Minahan, director of digital at Young Lives vs Cancer, discusses data silos and how new tech is offering a more natural user experience

Responsible for everything from keeping the IT lights on, to digital transformation, AI strategy, fostering cross-organisation relations and managing complexity, the modern CIO has their plate full. Top CIOs share their tips for success

Everywoman founders Maxine Benson and Karen Gill highlight the importance of diversity and why women’s voices need to be heard more widely in tech

A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password.

The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States.

A flaw in Anthropic’s Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude’s access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce.

A new malicious framework called OkoBot is delivering more than 20 payloads in attacks focused on stealing cryptocurrency wallet seed phrases, credentials, and other sensitive data.

Amazon Web Services has launched AWS Continuum, an integrated security platform designed to automate the discovery, enforcement, and remediation of security issues in codebases, dependencies, and applications. The platform introduces four key functionalities that cover the entire vulnerability lifecycle: penetration testing, code review, threat modeling, and identification of code vulnerabilities. This initiative aims to enhance the security processes for developers and organizations.

Google has been recognized as a leader in the 2026 Gartner Magic Quadrant for Conversational AI Platforms, achieving the highest scores in both Vision and Execution. Their Gemini Enterprise for Customer Experience platform enables organizations to move beyond basic chatbots and create AI agents that understand customer intent, reason across enterprise knowledge, and take action. The platform, powered by Gemini models and built on Google Cloud’s AI stack, provides tools like CX Agent Studio to build and deploy AI agents across voice and chat, assist human agents, and accelerate deployment with pre-built solutions for industries like retail and automotive. The Home Depot is already leveraging these capabilities to improve customer support and speed up issue resolution.

Long foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story.

Data scientists often juggle between SQL and Python for data processing, facing challenges with data transfer between the two. To ease this, Google Cloud introduced SQL cells in Colab Enterprise, enhancing workflow integration with the new %%bqsql IPython cell magic for seamless SQL and Python operation. This allows users to efficiently utilize both languages in a single processing pipeline, leveraging tools like Jupyter and pandas. Users can set up local environments or use Colab to access BigQuery resources. The integration facilitates direct SQL querying of local pandas DataFrames and enables chaining operations between SQL and Python, enhancing scalability and readability. Users can visualize data in Python post-SQL transformations, maintaining efficient workflows. The BigFrames team encourages feedback on this hybrid experience.

In the July 2026 edition of Cloud CISO Perspectives, Francis deSouza, COO of Google Cloud, discusses how deep context enhances the effectiveness of AI in cybersecurity for defenders against evolving threats from AI-driven attackers. With AI accelerating cyberattacks, Google has developed the AI Threat Defense framework, integrating various security technologies to provide a proactive defense strategy. Key principles include thorough preparation, smart scanning, efficient remediation using automation, and continuous monitoring, as illustrated by Morgan Stanley’s success in significantly reducing threat detection time. Additionally, the issue highlights ongoing efforts to improve security practices, adapt to emerging threats, and leverage collaboration within the cybersecurity community.

Collaboration with CNCF reflects Broadcom’s continued investment in open source innovation, cloud native resilience and the technologies powering the next generation of AI workloads Key Highlights SAN FRANCISCO, California — July 16, 2026 — The Cloud…

Migrating to new AI models can be complex and time-consuming for engineering teams, often requiring extensive testing and manual evaluation. Google Cloud’s Applied ML team has developed a new workflow that allows model upgrades to be completed in hours instead of months, using the Gemini Enterprise Agent Platform. They share three lessons: engaging in hands-on discovery to understand requirements, moving away from rigid automation, and adopting a flexible agent architecture. By applying these principles, teams can create efficient migration workflows and utilize tools like Autoraters and Antigravity for automation, ultimately improving both speed and quality in adopting new AI models.

A Google internal hackathon tested whether AI agents could collaboratively create short films. Teams of agents, each with specific roles, collaborated through messaging and shared files within an open-source framework called Scion. Over the competition, ten crews produced 25+ films totaling about 44 minutes, using various AI tools for scriptwriting, visuals, and audio. The experiment’s findings highlighted the importance of clear communication, effective team structures, and the benefits of specific prompts over general directions in AI-generated media.

If you run critical workloads on AWS, such as a contact center on Amazon Connect Customer, database workloads on Amazon Relational Database Service (Amazon RDS), or hybrid connectivity through AWS Direct Connect, service health events demand your attention. But not all events are equal. An operational issue, a scheduled maintenance window, and a deprecation notice

Traditional security workflows were built for environments that changed at human speed. Token Security explains why AI agents require a new approach: building on a live identity foundation while giving security teams the flexibility to create workflows tailored to their own environments.

The Mandiant M-Trends 2026 report notes that the mean time-to-exploit vulnerabilities has decreased to -7 days. To address this, security teams are exploring the integration of large language models (LLMs) within their development processes for automated vulnerability management. The blog outlines best practices for safely incorporating AI, emphasizing the importance of operational guardrails, adherence to industry standards like the NIST AI Risk Management Framework, and securing data by isolating AI agents in controlled environments. It stresses combining AI with human oversight to enhance vulnerability detection while minimizing risks. The discussion includes securing pre-agent data, workload isolation, effective red teaming, and fostering a culture of continuous improvement in vulnerability management. Additionally, it highlights integrating AI into software development lifecycle for both enterprise and product security. Ultimately, organizations should prioritize foundational security and approach LLM deployment strategically to balance innovation with risk management.

Genetic testing company 23andMe has agreed to pay $18 million to settle claims from a coalition of 43 attorneys general that it failed to protect customers’ genetic data.

Two leading members of the Scattered Spider cybercrime collective were sentenced to five years and six months in prison each for hacking Transport for London (TfL) in 2024.

AutomationDirect’s Productivity Suite versions up to 4.6.2.2 are vulnerable to several critical issues that could allow local attackers to cause memory corruption, system instability, or denial-of-service conditions. Key vulnerabilities include out-of-bounds reads/writes, and a divide-by-zero error. Users are advised to update to version 4.7.0.47 or later. If immediate updates aren’t possible, AutomationDirect recommends various compensating measures, such as network isolation, access restrictions, and stringent monitoring practices to mitigate risks. CISA encourages organizations to maintain robust cybersecurity practices and to report any anomalies.

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, reflecting active exploitation: two CVEs related to Fortinet FortiSandbox OS Command Injection and one from Microsoft SharePoint concerning Deserialization of Untrusted Data. These vulnerabilities are significant risks for federal agencies, driving the need for prompt remediation as outlined in Binding Operational Directive 26-04. While this directive specifically affects Federal Civilian Executive Branch agencies, CISA advises all organizations to adopt similar risk-based vulnerability management practices. CISA welcomes submissions for new vulnerabilities to the KEV Catalog through its nomination process.

A vulnerability in NASA’s Core Flight System (cFS) Health & Safety (HS) Application could lead to denial-of-service conditions. The issue stems from a null pointer dereference, causing a segmentation fault when handling a Housekeeping Telemetry request. This flaw affects the cFS Health & Safety application, with critical implications for transportation systems globally. The vendor, NASA, provides a CVSS score of 7.5 for this vulnerability, indicating its severity.

A denial-of-service vulnerability (CVE-2026-9653) has been identified in Rockwell Automation’s 1756-EN2, 1756-EN3, and 1756-ENBT communication modules due to improper validation of connection packets. The affected versions can allow attackers on the network to disrupt device connections, although these connections will resume immediately after. Users are advised to upgrade the affected devices to version 12.002, as the 1756-ENBT is discontinued and has no available fix. CISA recommends enhancing network security, including using firewalls and VPNs, to mitigate risks.

Rockwell Automation’s Arena software versions up to V17.00.00 are vulnerable to multiple memory corruption issues, identified as CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, and CVE-2026-8314. Attackers could exploit these vulnerabilities to execute arbitrary code by convincing users to open malicious files. Users are urged to update to V17.00.01 to mitigate these risks. CISA recommends enhancing network security and implementing cybersecurity best practices to protect against such threats.

A vulnerability in Rockwell Automation’s FactoryTalk DataMosaix Private Cloud (versions 8.02 and earlier) allows authenticated attackers to inject malicious scripts due to improper input neutralization. This issue, classified as a stored cross-site scripting vulnerability (CVE-2026-9292), could lead to account takeovers and credential theft. Users are urged to upgrade to version 8.03 or later. CISA advises enhancing network security and following best practices to mitigate risks, with no known active exploitation reported.

A critical vulnerability in SALTO ProAccess Space versions earlier than 6.13 allows authenticated attackers to escalate privileges and access restricted spaces within a system, assuming valid operator credentials are available and partition features are enabled. To mitigate this risk, users are advised to upgrade to version 6.13 and implement several security practices, including using internal networks, applying least-privilege principles, and considering separate instances for strong tenant separation. CISA emphasizes the need for cybersecurity strategies to defend industrial control systems and encourages organizations to report any suspicious activities related to this vulnerability.

Multiple vulnerabilities have been identified in Siemens’ SICAM 8 products, potentially leading to denial of service and unauthorized access. Affected devices include various firmware versions, with specific vulnerabilities (CVE-2026-54798, CVE-2026-54799, CVE-2026-54800, CVE-2026-54801) impacting the CPCI85 and SICORE systems among others. Siemens recommends that users update to firmware versions V26.20 or later to mitigate these risks. The company emphasizes the need for protective measures in critical infrastructure networks to enhance overall system security and resilience. Users are encouraged to follow security guidelines and conduct proper risk assessments when implementing updates.

Mobile network operators in the UK are battling with energy costs, planning red tape and regulations, all of which are impacting their investment plans

Palantir is a US defence-intelligence company, born from the CIA’s venture arm that now operates inside the UK public sector. We examine the claim that its technology does what no other supplier can

Artificial intelligence is rapidly evolving, requiring robust security strategies that traditional methods can’t keep up with. Chief Information Security Officers (CISOs) must protect AI model weights, defend against threats like prompt injection, and comply with regulations without impeding development. Google Cloud offers a comprehensive blueprint for securing AI workloads on Google Kubernetes Engine (GKE), emphasizing effective security layers from infrastructure to application security. This approach includes hardware-level encryption, zero-trust networking, model integrity controls, and defenses against AI-specific threats. It advocates a phased security strategy: deploying foundational configurations, hardening production systems, and automating compliance. By leveraging GKE, teams can ensure enhanced security without compromising AI deployment speed.

Running large language model (LLM) workloads in-house is one of several patterns teams adopt alongside managed API services. Managed API services are convenient and well suited to many workloads. Self-hosting is a complementary option that some…

A three-person agency received a $14,000 AWS bill in one day after attackers extracted static access keys and burned Claude invocations on Bedrock. Combined with May’s DN42 incident, where an autonomous agent provisioned $6,531 of oversized infrastructure in 24 hours, practitioners warn that cloud billing lags roughly a day behind agent-speed spend. By Steef-Jan Wiggers

Humans can no longer keep up with the volume and velocity of security data on their own, but AI can’t be fully trusted. David discusses the merits of both and muses on what the future might look like.

Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.

Owen Flowers and Thalha Jubair, the hackers behind the 2024 TfL cyber attack, have been sentenced to five-year prison terms at Woolwich Crown Court

While support ended in October 2025, community-driven insights from Lansweeper has found that smaller businesses are still using Windows 10

Microsoft promised “infinite” cloud scalability, but signs of capacity strain and regional rollbacks suggest it may be overstretched, forcing customers to rethink vendor lock-in

To fix grid crisis caused by mismanagement under her previous administrations, Danish prime minister opens third term in office with laws against datacentres

TELEPUZ is a modular malware that emerged through CLICKFIX-VIDAR attacks in April. We reverse-engineered it to show you the infrastructure and evasion techniques that matter.

How to implement proper consent management to allow users to consciously authorize your applications.

The CNCF Technical Oversight Committee (TOC) has voted to accept HAMi as a CNCF incubating project. About HAMi Modern AI infrastructure teams run into the same problem over and over: expensive GPUs often sit fragmented and…

The deployment of the Gemini Enterprise app greatly enhances organizational productivity by offering advanced AI tools and specialized solutions. However, as its usage scales, managing telemetry data presents challenges in audit, governance, and insight extraction. Google Cloud addresses this with pre-computed dashboards and the integration of BigQuery, enabling enhanced analysis of usage patterns, compliance verification, and safety audits. Utilizing BigQuery’s capabilities, administrators can visualize data, streamline queries, and generate insights effectively, ensuring successful integration and governance of the Gemini Enterprise app within their organizations.

AlloyDB enhances enterprise search by integrating advanced hybrid capabilities that merge text, vector, and keyword searches into one SQL query. The recent addition of RUM index support further improves full-text search, especially for logographical languages like Chinese, Japanese, and Korean, where traditional indexing struggles due to the absence of whitespace. Through AlloyDB AI Functions, users can utilize Gemini’s multilingual models for efficient text parsing and segmentation without the complexity of external processing pipelines. This approach facilitates high-accuracy searches, optimized for handling continuous text. The native integration in AlloyDB streamlines operations by keeping data processing within the database, improving performance, and simplifying data management.

IDC’s 2026 AI in Networking Special Report Survey reveals that while enterprises are rapidly piloting AI initiatives, transitioning from pilot to production is hindered primarily by infrastructure issues, particularly in networking. Key concerns include security challenges (32.6%), automation difficulties (26.8%), and talent restrictions (24.7%). The rise of agentic AI intensifies these issues due to its complex, distributed nature, emphasizing the need for robust, consistent networking to support operational control and governance. Organizations must balance platform-based solutions with best-of-breed capabilities to ensure security, reduce complexity, and enable fast deployment. An adaptable, extensible infrastructure is vital for managing the demands of agentic AI systems effectively.

When 121 million mobile devices establish persistent gRPC connections to your origin infrastructure within seconds of a live broadcast, the routing policy behind your DNS records matters far more than it does at normal traffic levels. The wrong policy can concentrate all your connections onto a single origin endpoint, turning a scaling success into an

Microsoft Azure Databricks integrates the Databricks platform with Microsoft’s ecosystem to provide significant business advantages. This collaboration results in a solution that aligns seamlessly with existing Microsoft tools, identities, and governance structures used by organizations. Customers can expect measurable value from this first-party offering, enhancing their data analytics capabilities within the Azure environment.

Stripe introduces a benchmark suite to evaluate whether AI agents can build real-world Stripe integrations across backend, frontend, and browser-based checkout workflows. The study examines end-to-end software engineering capability, focusing on execution, testing, and validation gaps in agentic systems under production-like constraints. By Leela Kumili

Mandiant’s security assessments frequently uncover serverless applications with inadequate authentication, exposing them to vulnerabilities like Local and Remote File Inclusion and Command Injection. These can lead to significant risks, including complete cloud environment takeovers. The blog discusses attack scenarios and offers security recommendations, including adopting a Secure Software Development Lifecycle, implementing effective Identity and Access Management, and using Web Application Firewalls like Cloud Armor to protect against common attacks. Furthermore, the article emphasizes the importance of proactive security measures during development to maintain secure serverless environments.

Another mammoth Patch Tuesday update, likely topping 600 flaws in total, sends defenders into the weeds

CISA has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, reflecting active exploitation risks: CVE-2023-4346 related to a KNX protocol issue and CVE-2026-46817 concerning Oracle E-Business Suite’s privilege management. The Binding Operational Directive 26-04 directs federal agencies to prioritize high-risk vulnerabilities for quick remediation. CISA encourages all organizations to adopt similar risk-based management practices and will continue to expand the KEV Catalog. Submissions for new vulnerabilities can be made through CISA’s KEV Nomination Form.

The National Security Agency, CISA, and international partners have developed guidance for software manufacturers and online service providers to establish a coordinated vulnerability disclosure (CVD) program. This includes creating a clear vulnerability disclosure policy and a process for managing reported vulnerabilities, including assigning Common Vulnerabilities and Exposures (CVE) identifiers. The guidelines recommend using third-party intermediaries to enhance CVD programs, fostering collaboration with security researchers for effective vulnerability remediation and improved product security.

AWS and Anthropic have released the Claude apps gateway for AWS, a self-hosted control plane that centralizes identity, policy, telemetry, routing, and spend caps for Claude Code and Claude Desktop. The gateway runs as a single stateless container and routes inference to Amazon Bedrock or Claude Platform on AWS. By Steef-Jan Wiggers

For application teams, databases should feel like a solved problem. A team needs PostgreSQL, MariaDB, Redis, or another data service, submits a request, receives credentials, and starts building. In practice, the experience is rarely that simple….

Soon-to-be-appointed prime minister adds weight to government’s existing plan to ‘end era of outsourcing’

PoliceAI will be used to pilot artificial intelligence tools that are capable of automatically generating summaries of digital material, saving ‘countless’ admin hours

The UK government has ambitions to build out its own AI capabilities, but its plans are stumped by high datacentre power costs

When good infrastructure works, most people do not think about it. They might even forget. But when it stops working, everyone notices.

Billions of pounds are being lost - and hundreds of thousands of people excluded from the economy - because so much of our technology and working lives are not inclusive by design

The latest monthly digest from AWS highlights new security features, compliance updates, and hands-on resources. It includes expert blog posts focusing on identity and access management, threat intelligence, network security, AI-driven security tools, and multi-account strategies. Additionally, readers will find information on new service capabilities, code samples, and workshops designed to enhance security practices within AWS environments.

Why give away the most valuable data in security? Learn how Athena’s business model aligns trust, incentives, and open source defense.

The Five Eyes AI guidance urges organizations to strengthen software supply chain security. Learn how Chainguard helps teams stay ahead.

Stop writing manual API calls and hand-rolling token refresh logic. Learn how to accelerate your production setups using the Auth0 SDK, Auth0 CLI, and Infrastructure as Code.

Insurance fraud poses ongoing challenges, raising costs, eroding trust, and diverting resources from customer service. Current detection methods often use rule-based systems, manual reviews, and historical data analysis, which are effective for known fraud patterns but struggle with new or evolving schemes.

The countdown is officially on. In just a few weeks, the cloud-native ecosystem meets in Yokohama for KubeCon + CloudNativeCon Japan 2026. Taking place on Tuesday, July 28 from 09:00 – 12:30, KeycloakCon Japan brings together…

Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as “critical.”

Security Hub is our foundation for full-stack enterprise security across clouds. It centralizes your security operations and turns raw signals into prioritized insights, so your team spends its time managing real risk instead of stitching tools together. Today that foundation grows in two directions our customers asked for most. We are adding purpose-built protection for

Global datacentre electricity consumption reaches 1.9% of all generation, with ‘zombie workloads’ wasting 3GW of US capacity alone and a 100MW project delay costing up to $1bn

Report demands answers on Capita’s suitability to run HR and payroll services to 250,000 civil servants

AI agents are part of the modern development workflow. They write code, review pull requests, generate tests, call tools, interact with MCP servers, and help developers move faster. But behind every useful agent, there is something just as important as the model itself: the context that tells the agent how to behave. That context can

Google has long prioritized practical enterprise needs, focusing on infrastructure, security, and data platforms essential for large organizations. Emphasizing reliability and predictability, Google aims to deliver models that create business impact. Their leadership status in the IDC MarketScape for foundation model software underscores their ability to translate research into secure systems. With the Gemini Enterprise platform, Google provides tools that enable organizations to use AI more effectively, allowing dynamic agents to handle complex workflows securely. The Gemini 3.5 series, designed for intricate tasks, exemplifies this approach, enabling developers and business users to integrate AI seamlessly into their operations.

The Cloud Security Alliance (CSA) has unveiled the AI Controls Matrix (AICM) v1.1, enhancing its framework for secure AI systems. This latest version broadens control coverage, introduces a dedicated Model Security domain, and incorporates AI-specific security controls. Additionally, it provides comprehensive mappings to major AI governance frameworks globally, further solidifying its commitment to promoting trustworthy AI practices in the industry.

Running frontier AI in production can be challenging, but Claude on Google Cloud addresses these complexities. It combines Claude’s reasoning capabilities with Google Cloud’s managed infrastructure for ease of use across various enterprise needs. This setup allows for low latency, compliance, and optimized performance, freeing teams from infrastructure management. The platform supports different endpoint types for global reach and regional data needs, ensuring security and cost efficiency, particularly in regulated industries. With features like prompt caching and batch prediction, organizations can enhance performance while managing costs effectively. The integration facilitates a unified approach to both inference and agent functionalities, promoting streamlined development and deployment.

As AI agents and automated tools increasingly access web applications, distinguishing legitimate bot traffic from malicious attempts has become a critical security challenge. Traditional approaches such as IP-based filtering and reverse DNS lookups fail in multi-tenant systems (such as Amazon Bedrock AgentCore) where thousands of distinct workloads share the same IP space. Attackers can easily

AI is affecting the day-to-day careers of cyber security pros in regard to stress levels, but respondents to an ISC2 data-gathering exercise are split over whether or not their stress levels are going up or down

Google, along with industry partners, has introduced the Agentic Resource Discovery (ARD) Specification, an open standard designed for the publishing, discovery, and verification of AI tools, APIs, and agents. This standard incorporates a discovery layer that utilizes catalogs and registries to facilitate dynamic capability discovery. It also makes use of established protocols such as MCP and OpenAPI, focusing on enhancing trust and interoperability within the AI ecosystem.

When a failed DNSSEC key rollover took down the .al TLD, we deployed a Negative Trust Anchor to restore resolution. This time, though, clients didn’t have to take our word for it: 1.1.1.1 returned EDE 33, a new DNS error code that signals directly in the response that DNSSEC validation was bypassed.

ABB has acknowledged a vulnerability, CVE-2026-31431, in certain versions of its Ability Edgenius products that could allow a locally authenticated user to gain elevated root privileges on systems using a compromised Linux kernel. This flaw could enable attackers to control the affected system entirely. ABB has released an update (version 3.2.4.1) to address the issue and recommends immediate application of this fix. It is advised to limit access to the affected systems and implement additional security measures, as successful exploitation requires local access.

ABB has identified a vulnerability in certain versions of its Advant Master Online Builder products, where an incorrect version of the Online Builder was included, potentially allowing unauthorized execution of code. The affected versions have been documented, and an update has been released to remediate the issue. ABB recommends users upgrade to the fixed versions, enforce strong password policies, and restrict access to unauthorized users to mitigate risks associated with this vulnerability.

ABB has identified vulnerabilities in its T-MAC Plus version 4.0-24 products, which could allow attackers to compromise systems through various methods, including file disclosure, unauthorized access, cross-site scripting, and denial-of-service attacks. Affected users are urged to update to version 4.0-25 to resolve these critical and high-severity issues. Specific mitigations and workarounds are suggested, but the vulnerabilities require proper updates for full resolution. The vulnerabilities were responsibly disclosed and do not appear to have been exploited publicly prior to the advisory.

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, highlighting active exploitation risks. The vulnerabilities include server-side request forgery and code injection for SonicWall SMA1000 Appliances, as well as access control and authentication issues in Microsoft Active Directory and SharePoint Server. The Binding Operational Directive 26-04 mandates federal agencies to prioritize rapid remediation of these high-risk vulnerabilities. CISA urges all organizations to adopt similar risk-based management practices and encourages submissions for additional vulnerabilities meeting specific criteria.

CISA has updated its Alert regarding vulnerabilities impacting on-premises SharePoint Server versions, including CVE-2026-58644, which was added to the Known Exploited Vulnerabilities Catalog on July 16, 2026. Active exploitation is noted for multiple vulnerabilities, enabling unauthorized access and malware deployment. Organizations are advised to apply the latest patches, utilize security measures, and monitor for unusual activity. CISA recommends strengthening security around SharePoint Servers and encourages reporting any anomalies.

A critical vulnerability has been identified in the Rockwell Automation 1715-AENTR EtherNet/IP Adapter, affecting versions 3.003 and below. This flaw exposes a debug port that allows unauthenticated remote access, enabling attackers to read or delete files, stop tasks, and modify device states, potentially compromising confidentiality and availability. Users are urged to upgrade to version 3.011 or later or adopt security best practices to mitigate risks. The Cybersecurity and Infrastructure Security Agency (CISA) recommends defensive measures to reduce exploitation risks and emphasizes the importance of network isolation and secure remote access methods.

When we first started building kagent, we didn’t run every agent in its own Kubernetes Pod, Service, and ServiceAccount. Instead, agents were simply executed inside the kagent runtime. It was the simplest architecture possible: one runtime…

Can our new Prime Minister bring a new approach to AI that treats the voracious Big Tech companies with less deference?
![[Video] Where protection starts: Cisco Talos Intelligence Integrations](/article-images/45ee2cdb-5520-41dd-952e-ae9f390226c1.webp)
Every day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations help reduce uncertainty by turning the latest threat intelligence into proactive protections across Cisco technologies.

Google released the Genkit Agents API in preview for TypeScript and Go. The open-source framework packages message history, tool loops, streaming, and state persistence behind a single chat() interface. Detached turns let agents work after clients disconnect. Interruptible tools provide human-in-the-loop control with anti-forgery validation on resume. By Steef-Jan Wiggers

This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Python environments.

Drawing from the enduring adaptability of HTML and HTTP, Seph Gentle proposes embedding self-contained schemas directly into file headers, ensuring data remains readable without external definitions. His experimental format prioritises forward, backwards, and sideways compatibility, enabling data format evolution without central coordination or data loss By Olimpiu Pop

The Annual AI Security Report 2026 from Check Point Research reveals a significant shift in the role of AI within cyber security. Previously viewed as a tool that enhanced existing attack methods, AI has now evolved into an active operator in cyber attacks. This change marks a transition where AI not only assists attackers in preparation but takes on a more central role in executing malicious activities. This development emphasizes the growing sophistication and impact of AI in cyber threats.

A supply chain attack compromised AsyncAPI npm packages via GitHub Actions. See how Chainguard blocked the malicious releases by design.

Securely extend your multi-tenant APIs and MCP servers to AI agents, partner marketplaces and developer ecosystems using native, organization-scoped access control with Auth0 Third-Party Applications for Organizations

For most of Maven Central’s history, publishing has followed a simple model: maintainers publish releases, users consume them, and when something goes wrong, the fix comes through the same channel.

In this post, we walk you through three main steps: First, you create an AWS CodeConnections host in your VPC with connectivity to your private Git server. Second, you establish a connection that Argo CD can use. Finally, you deploy a sample application to verify the integration. By the end, you have a secure way to deploy applications from private repositories.

The automotive industry is shifting towards Software-Defined Vehicle (SDV) architectures, transforming vehicles into AI-native, intelligent hubs within a connected ecosystem. Google, through its Android Automotive OS (AAOS) and Google Cloud, is leading this transition, providing a modular platform that separates core vehicle functions from hardware. The Nexus SDV platform utilizes Google technologies to integrate automotive telemetry and enhance vehicle functionality. This approach enables predictive maintenance by analyzing real-time data, improving customer experiences, and ensuring vehicle uptime. With built-in security measures, OEMs can rapidly implement these advanced solutions to create unique brand experiences and transition from traditional models to an AI-driven ecosystem.

In the evolving landscape of 2026, the public sector is adapting to defend interconnected trust relationships against fast-operating adversaries. Mandiant’s recent report highlights alarming trends, such as a 22-second median attack hand-off to ransomware operators, necessitating a shift towards machine-speed defenses. Additionally, persistent state-sponsored threats challenge standard security measures, while vulnerabilities in virtualization and SaaS integrations create new attack vectors. Continuous verification is now essential for resilience, with Google advocating for identity-centric security, real-time telemetry analysis, and hardening infrastructure. Agencies like the Pasco Sheriff’s Office and the State of Connecticut showcase the effectiveness of these strategies in enhancing security and operational efficiency. The report provides vital insights for public sector leaders aiming to strengthen their defenses against evolving threats.

Managing shadow AI in organizations can be challenging due to workloads deployed without formal registration, which often evade security scanners. To address this, the k8s-aibom tool is being open-sourced. This lightweight Kubernetes controller continuously monitors AI runtimes and generates CycloneDX Machine Learning Bill of Materials (ML-BOMs), offering real-time visibility into cluster environments without requiring changes to existing workflows. It distinguishes between declared and inferred AI configurations, enhancing audit confidence while ensuring data immutability and compliance readiness for regulations like the EU AI Act and NIST AI Risk Management Framework. This solution is designed to support governance, security operations, and developers in managing AI deployment seamlessly.

A panel on data ownership challenged the definition of “ownership,” arguing it must extend beyond simple account control to include structural independence, interoperability, and community governance. Speakers like Zenna Fiscella, Paul Frazee, Boris Mann, and Robin Berjon emphasised the need for shared standards, unbundled platforms, and better tools to support user sovereignty. By Olimpiu Pop

DoorDash details the architecture behind Ask DoorDash, its AI-powered conversational shopping assistant, combining LLMs, specialized AI agents, MCP-based tooling, and an intelligence layer with persistent consumer memory and live backend data. Early results show up to 24% higher checkout conversion, 17% larger baskets, and improved intent accuracy using memory-backed sessions. By Leela Kumili

Amazon Web Services (AWS) has released new compliance guidance for healthcare organizations pursuing HITRUST i1 certification. The document, titled “HITRUST i1 Compliance on AWS: Customer Implementation Guidance with an Illustrative Healthcare Platform,” provides a framework that encompasses 182 curated controls necessary for compliance. The guidance aims to assist these organizations in effectively utilizing AWS as their cloud infrastructure while meeting HITRUST standards.

In the Threat Intelligence Bulletin for the week of July 13th, significant cyber research findings are shared, including a major data breach by U.S. auto insurer AssuranceAmerica. Approximately 7 million individuals were affected when attackers accessed company systems using compromised employee credentials, leading to the theft of personal information, such as names, contact details, and driver’s licenses. This incident highlights ongoing vulnerabilities in the sector.

Precursor, our new continuous behavioral validation engine for bot management, offers visibility into how humans and bots actually interact across the full user journey. By turning session-level behavior into bot detection signals, it identifies advanced automation with higher precision — while reducing friction for legitimate users.

This week’s Java roundup for July 6th, 2026, features news highlighting: the GA release of TornadoVM 5.0; point releases of JHipster, Keycloak and Google ADK; maintenance releases of GraalVM Native Build Tools and Micronaut; the OmniFish Build of Payara and introducing Vidocq, a new implementation of the Jakarta EE 11 Core Profile and MicroProfile 7.1. By Michael Redlich

CISA has added a new vulnerability, CVE-2008-4128, related to Cisco IOS, to its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation concerns. This vulnerability is a common target for cyber attackers and poses significant risks to federal entities. Under Binding Operational Directive 26-04, federal agencies are required to prioritize the rapid remediation of high-risk vulnerabilities from the KEV Catalog while allowing for deferral of lower-risk ones. CISA urges all organizations to adopt similar risk-based vulnerability management practices. Organizations can submit information on exploited vulnerabilities for potential KEV catalog inclusion through CISA’s nomination process.

The Russian Federal Security Service (FSB) continues to exploit poorly configured networking devices globally, impacting various critical infrastructure sectors, including communications, energy, and healthcare. A recent Cybersecurity Advisory (CSA) from multiple agencies, including the NSA, CISA, and FBI, details tactics, techniques, and recommended mitigations to combat threats posed by FSB cyber actors. Key actions include disabling insecure protocols like SNMPv1/v2, using SNMPv3, and implementing strong password policies. Network defenders are urged to enhance configurations and monitor for unusual activities to better protect their systems.

As more organizations move to use OpenTelemetry in production at scale, with multiple Collectors across heterogeneous environments, a new challenge arises: how to remotely manage, configure, and update this agent fleet in a consistent and secure…

Organizations are facing challenges with traditional video surveillance storage due to rapidly expanding video data volumes from retail, banking, restaurants, and transportation. Growing retention needs and a desire for operational insights make on-premise storage unsustainable, prompting a search for alternative solutions.

Jake Lazaroff presented the AT Protocol as a versatile framework for distributed applications, extending beyond just social networking. He highlighted the importance of a local-first architecture, enabling users to store data in personal data stores (PDSs) while utilizing a shared infrastructure for synchronization and updates. The presentation featured experiments on collaborative tools, demonstrating advantages such as decreased dependency on app-specific backends.

Learn how to close the audit gap in agentic workflows by leveraging Auth0 logs monitoring, Token Vault secure token exchanges, and CIBA approval flows.

Opinions on AI range from transformative optimism to deep skepticism, but one thing is clear: AI is becoming an increasingly important part of enterprise technology strategies. Feel free to pick whichever you like. But whatever you…

Google Cloud has been designated as a critical third party (CTP) to the U.K. financial sector by the U.K. Treasury, reflecting its significant role for U.K. firms. This designation will enable oversight by the Bank of England and other financial regulators to enhance operational resilience in the sector. Google Cloud is committed to supporting customers in meeting regulatory requirements and fostering closer collaboration with regulators. The company aims to maintain its focus on being a secure and resilient platform for digital transformation in finance.

Amazon Web Services EMEA Sarl (AWS) has been designated as a critical third party (CTP) to the UK financial sector by HM Treasury. The CTP regime came into force on January 1, 2025, and establishes a framework through which the Bank of England, PRA, and FCA (collectively the UK regulators) can set requirements on and

The article explores the complexities of evaluating AI agents, particularly in data retrieval and question-answering contexts. It criticizes traditional pass/fail benchmarks that provide limited insights into an agent’s capabilities, advocating for a more nuanced approach through the use of a meta-benchmark called Discovery Bench. This framework uses information theory to modulate query difficulty by adjusting terms based on their informative power. The aim is to generate detailed performance maps, highlighting not only successes but also specific failure modes, thereby enabling targeted improvements in AI systems. The piece emphasizes the need to rigorously evaluate both the performance of AI agents and the quality of evaluation benchmarks themselves.

Google Cloud provides regular updates, announcements, and resources on its services. Upcoming webinars include one on July 16 introducing Google Cloud NGFW with advanced malware protection powered by Palo Alto Networks, and another on optimizing infrastructure for agentic AI. Public previews for Cloud Run sandboxes and new capabilities in Apigee are also highlighted. Reports indicate many organizations need infrastructure upgrades for agentic AI. Various tech talks will cover AI governance, security, and optimizing API deployments.

Agentic testing is an AI-driven approach to end-to-end test automation introduced by Slack engineering. It uses AI agents that execute workflows based on intent rather than fixed scripts, adapting to UI and system changes at runtime. The approach aims to reduce brittle tests in distributed systems while complementing deterministic unit, integration, and E2E testing strategies. By Leela Kumili

CISA has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-48939 (iCagenda) and CVE-2026-56291 (Balbooa Forms), both related to unrestricted file uploads. These vulnerabilities represent significant risks to federal systems. The Binding Operational Directive (BOD) 26-04 outlines requirements for federal agencies to manage high-risk vulnerabilities effectively. While it primarily applies to Federal Civilian Executive Branch agencies, CISA urges all organizations to adopt similar strategies for vulnerability management. Organizations can suggest additional vulnerabilities for inclusion in the KEV Catalog through CISA’s nomination process.

Smart Tiered Cache allows for precise upper tier selection for origins hosted on AWS, GCP, Azure, and Oracle Cloud with customer-provided cloud region hints.

In a recent article, Datadog engineer Arnold Wakim shared what worked, what didn’t, and the lessons they learned while evolving a critical production system using AI to overcome hard limits in its storage backend and significantly improve performance. By Sergio De Simone

You can now connect your agents to the AWS MCP Server using the same credentials and sign-in methods that you already use for connecting to the AWS Management Console or AWS Command Line Interface (AWS CLI) through a familiar browser-based experience powered by industry-standard OAuth. This new sign-in path supports AWS Identity and Access Management

Specification-driven composition offers a solution to data pipeline scalability issues. As pipelines evolve from simple scripts, duplicated transformation logic and cascading changes create management challenges. This approach aims to avoid code duplication and improve maintainability by centralizing transformation definitions.


Cisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in GeoVision, and one vulnerability in VTK-DICOM. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy. For

With Wimbledon’s help, Hazel argues against the popular myth that “Attackers only need to be right once, but defenders need to be right 100% of the time.”

The Cloud Controls Matrix (CCM) is a key security framework developed by the Cloud Security Alliance (CSA) for cloud computing. It aligns with CSA best practices, helping assess and enhance the security posture of cloud services. The CCM offers guidance on which controls should be implemented by different participants within the cloud supply chain, benefiting both cloud service customers (CSCs) and cloud service providers (CSPs). It contains 197 controls organized into 17 domains.

Introducing OpenAI’s latest frontier model series, the Asia Pacific Data Zone, and product agent capabilities, all generally available in Microsoft Foundry. The post Frontier models and production agents: Advancing Microsoft Foundry for the agentic era appeared first on Microsoft Azure Blog.

The article reflects on a discussion with a CISO from a major retail company about a significant security incident that occurred six months prior. Despite no stolen credentials, malware, or firewall breaches, the critical reconciliation process failed, attracting regulatory attention. The root cause was an AI-powered automation agent that had been properly granted access, highlighting the complexities and potential risks of relying on AI in security processes.

Google Cloud has introduced Cloud Run sandboxes in public preview, allowing developers to run AI-generated code and untrusted binaries without risking host applications or sensitive data. This feature provides lightweight, isolated execution environments that start in milliseconds, ideal for tasks like executing dynamic Python scripts or running headless browsers. Security measures include credential and environment isolation, denied outbound network access by default, and a read-only filesystem. Cloud Run sandboxes leverage existing resources without incurring extra costs, making them a cost-effective solution for executing untrusted code securely.

This post provides a detailed guide on migrating a Node.js web application from EC2 instances to a scalable, containerized service using EKS Auto Mode. It covers the configuration and utilization of AWS and Amazon EKS MCP Servers with the Kiro CLI. The tutorial includes steps for automating essential migration tasks, such as creating Dockerfiles, optimizing images, generating Kubernetes manifests, and deploying the application in a production environment on EKS Auto Mode.

NIST is advancing nine new post-quantum signature algorithms as potential candidates for future standardization. We take a closer look at all of them, and argue that while they are in the works and show great potential, we should use ML-DSA for now — the best one currently available.

Today, we’re excited to announce that Boost is moving out of beta and into public preview. After months of building, breaking, and rebuilding inside JFrog’s own R&D organization, Boost is ready for the world. If you are currently running into token limits, unpredictable costs, or runaway usage from AI agents, Boost was built for you.

In Q2 2026, Sonatype Research recorded 1.8 million malicious packages, with npm accounting for 96.6% of this figure. The quarter illustrated a troubling theme where trusted software distribution channels were exploited through repository abuse, trojan-class malware, and compromised maintainers. Attackers not only targeted malicious packages but also high-trust developer workflows, evidencing a shift toward industrialized open-source malware. While npm dominated the count of threats, the ecosystem also saw significant malicious activity in PyPI and NuGet. The report emphasizes the importance of addressing trust and dependency relationships, revealing that once trusted accounts or packages are compromised, attackers gain legitimacy. To combat these threats, organizations should enhance security measures across the software supply chain and recognize the evolving nature of open-source malware.

A critical vulnerability has been identified in OpenPLC v3, where authenticated users can write arbitrary files to the filesystem due to improper handling of filenames in the web UI. This flaw can lead to arbitrary native code execution when a malicious file is compiled. OpenPLC v3 is affected and no longer receives security updates, prompting the recommendation to upgrade to OpenPLC v4. Users are advised to minimize network exposure and follow cybersecurity practices to mitigate risks associated with this vulnerability.

Schneider Electric has identified a vulnerability in its Easergy MiCOM Px40 Series products, specifically related to the use of hard-coded credentials, which may allow unauthorized access to device information via the SNMP protocol. Affected models include various versions of the Easergy MiCOM P14x, P24x, P341, and other series. Users are advised to upgrade firmware or implement several mitigations, such as using protected networks and firewalls, to reduce security risks. CISA provides additional cybersecurity recommendations for industrial control systems.

Google shipped AlloyDB AI functions GA with a proxy model architecture that trains a lightweight local model from LLM outputs, then runs queries at database speed without external calls. Smart batching delivers 2,400x throughput improvement. The proxy model reaches 100,000 rows per second in preview, but benchmark numbers apply only to ai.if in internal testing. By Steef-Jan Wiggers

AWS has outlined how ProGlove, an industrial-wearables manufacturer, was able to scale its SaaS platform to run more than one million AWS Lambda functions spread across thousands of dedicated customer accounts. By Matt Foster

Explore why delegated administration in SaaS isn’t just a UI feature — it is a fundamental security and trust architecture for your enterprise customers.

A harmless-looking symlink in a Git repo can redirect a tool into reading or writing anywhere on your machine. That old trick is now showing up in AI coding assistants, with nasty results.

System prompts form the foundation of generative AI applications. A system prompt is a collection of instructions and operational context provided to a large language model (LLM) that shapes how the model behaves and interacts with users and tools. System prompts often contain proprietary information, including role definitions, behavioral guidelines, tool descriptions and usage instructions,

Microsoft’s Secure Future Initiative (SFI) aims to define and meet security requirements for a well-defended cloud service. This involves not only setting the standards but also continuously assessing live services to ensure they comply, particularly in the context of rapidly evolving artificial intelligence. The initiative emphasizes proactive measures to strengthen cloud security against emerging threats.

Cloud resiliency is about ensuring systems can adapt, recover, and keep functioning within real-world constraints. The post Built to bounce back: How Azure resiliency evolved appeared first on Microsoft Azure Blog.

Over a dozen major economies have now published post-quantum cryptography (PQC) adoption guidance. As a CISO, you’re probably well into your migration plan and know the most difficult part has little to do with changing algorithms. The real leadership challenge is driving coordinated change across a large, complex organization where asymmetric cryptography is embedded in

AI agents and large language models (LLMs) are transforming software development by building, analyzing, and deploying code throughout the lifecycle. As AI increasingly shapes software supply chains, it is crucial to implement proactive security measures and access controls. To govern authentication and permissions effectively without hindering development speed, organizations must revise their access management strategies, ensuring the security of AI-driven processes.

Cloudflare Research is building a global consensus service called Meerkat that uses a new consensus algorithm called QuePaxa. We plan to use Meerkat to build a strongly consistent, fault-tolerant key-value store, and other applications.

Elastic Security Labs tracks REF6045, an active operator-assisted banking fraud operation targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges.

Learn how to balance control and security using the four stages of Auth0 customization, from standard Universal Login to embedded authentication.

With the introduction of models that require data sharing with third-party providers—such as Claude Fable 5—organizations need a way to centrally enforce data retention policies. Amazon Bedrock gives you control over whether your prompts and model outputs are retained after an inference request completes. You might need a way to enforce your retention settings across

In this post, we demonstrate how to use Envoy’s External Processing filter (ext_proc) to solve this challenge on Amazon EKS. This solution captures complete request and response data without modifying application code, providing the compliance-grade audit trails that regulators require.

S&P Global Market Intelligence utilized Amazon FSx for NetApp ONTAP to create a disaster recovery solution for their Capital IQ platform. This allows for a rapid failover to read-only mode in a secondary region within 15 minutes, with full read-write recovery available later. The implementation improves failover time and ensures data consistency for financial operations.

AI agents are changing how software gets built, but the infrastructure around them hasn’t caught up. Agents burn through tokens on noise. They take actions they shouldn’t. Context evaporates between releases. And most delivery pipelines were never designed for the pace and volume of agentic development. On June 11th we brought together developers in San

Azure Key Vault Managed Hardware Security Module (HSM) offers robust control over encryption keys, ensuring that they are generated and stored within a single-tenant, FIPS 140-3 Level 3 HSM that you alone manage. Microsoft does not have access to the key material, allowing you to determine access permissions for each key. The feature of external key management for Azure Managed HSM has now entered public preview, enhancing security and governance for users.

CISA has added a new vulnerability, CVE-2026-48282, related to Adobe ColdFusion, to its Known Exploited Vulnerabilities (KEV) Catalog due to signs of active exploitation. This type of vulnerability is often targeted by cybercriminals and poses significant risks for federal agencies. Binding Operational Directive (BOD) 26-04 mandates federal agencies to prioritize high-risk vulnerabilities in their remediation efforts. Although this directive is for federal agencies, CISA urges all organizations to adopt similar risk-based vulnerability management strategies. Organizations can also submit exploited vulnerabilities for potential inclusion in the KEV Catalog.

The pledge is a voluntary framework inviting organizations to commit to foundational cyber security governance, board-level accountability, and supply chain rigor. For over a decade, Cloudflare has pioneered the core pillars of this framework: democratizing security, leadership accountability, and radical transparency.

Hitachi Energy has identified a buffer overflow vulnerability in their e-mesh EMS products, specifically in versions 4.1.6, 4.4.2, and 4.7.0. Exploiting this vulnerability could lead to denial of service or arbitrary code execution. The issue arises from an NGINX vulnerability linked to the ngx_http_rewrite_module, affecting systems with ASLR disabled. Users are advised to update NGINX to version 1.30.2 or newer and follow specific mitigation steps. This advisory is part of an ongoing effort to improve cybersecurity in critical infrastructure sectors, particularly in the energy domain.

Hitachi Energy has identified a vulnerability in the PROMOD V product line that relies on insecure HTTP communication instead of HTTPS. This flaw allows potential attackers to intercept sensitive data, risking credential theft and unauthorized access. Versions affected include PROMOD V 1.0.10 and older. Users are urged to upgrade to version 1.0.11 and implement HTTPS on the Digipede server for remediation. CISA recommends minimizing network exposure and implementing strong cybersecurity practices to safeguard these systems.

Recent vulnerabilities have been identified in the Hydro-Québec Le Circuit Electrique charging station backend, with a CVSS score of 9.8 indicating critical severity. These flaws, including improper access control and insufficient session expiration, could allow for privilege escalation and potential denial-of-service attacks. The affected products are deployed in Canada, highlighting concerns for critical transportation systems. The main vulnerability, CVE-2026-20744, allows unauthenticated connections to the websocket endpoint.

Labcenter Electronics has identified multiple vulnerabilities in Labcenter Proteus 9.1_SP4_Build_42914, which can lead to information disclosure and arbitrary code execution. The issues include an out-of-bounds write, a stack-based buffer overflow, and a use-after-free vulnerability. The current version is recommended to be updated to 9.2 SPO to mitigate risks. Users should ensure proper cybersecurity practices are followed, as no public exploitation has been reported yet for these vulnerabilities.

Siemens Mendix Studio Pro versions prior to 11.12 are vulnerable to a file parsing issue that can allow code execution in the user’s context if they open a crafted malicious project. Affected versions include 10.11 through 10.24 (below 10.24.21), and 11.0 to 11.11 (below 11.6.7). Siemens has released updates to address this vulnerability and advises users to upgrade immediately. Additional countermeasures are recommended for products without available fixes.

Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware.

Add Auth0 login, logout, sessions, and token refresh to a Hono app on Cloudflare Workers with one middleware call. A practical guide to the new @auth0/auth0-hono SDK (beta).

See how Athena is helping secure open source by coordinating AI-discovered vulnerabilities, partner protections, and upstream fixes at scale.

Organizations must prioritize CMMC compliance as the U.S. Department of War will integrate CMMC assessment requirements into relevant defense contracts starting November 2025. Although the initial phase emphasizes self-assessments for Levels 1 and 2, this should not be viewed as a grace period. Contractors managing Controlled Unclassified Information (CUI) need to ensure their CMMC readiness promptly, as it is becoming essential for their business operations.

Recent research by Okta highlights the rapid adoption of AI agents within enterprises, showcasing that these autonomous systems are increasingly replacing traditional software models that relied on human permission to function. Unlike earlier technology, AI agents can independently execute complex workflows, access sensitive systems, and even create more agents to enhance task completion without human intervention. This shift marks a significant transformation in IT environments as organizations increasingly rely on AI-driven solutions.

If you’re building multi-agent AI systems, you need to prevent authorization scope from silently expanding as agents delegate tasks through multi-hop chains. Without proper controls, an agent can potentially act beyond what the originating user authorized, even when role-based access control (RBAC) policies are in place. The OWASP Top 10 for Agentic Applications classifies this

Read five key learnings from the Frost & Sullivan 2025 Frost Radar™ for CSPM to learn how CSPM is evolving from point-in-time compliance to continuous risk management. The post 5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture Management appeared first on Microsoft Security Blog.

Running your entire engineering ecosystem out of a single environment introduces a critical single point of failure. Here is how moving into Auth0 Teams protects your production uptime and engineering velocity.

Open source security has spent years getting better at finding problems. Scanning improved, as did intelligence, disclosure and prioritization. All of these still matter, but they are not enough.

We are launching Workers Cache, a regionally tiered cache that sits directly in front of your Worker entrypoints. Infinitely composable, configured via standard HTTP headers

Since early 2026, Check Point Research has been monitoring a new modular command-and-control framework associated with the Iranian APT group Cavern Manticore. This group primarily targets Israeli organizations, particularly in the IT and government sectors. Cavern Manticore is linked to Iran’s Ministry of Intelligence and Security and has connections to the OilRig group, highlighting its strategic focus on cyber operations against specific entities in Israel.

The latest Threat Intelligence Bulletin for the week of July 6th highlights significant developments in cyber research. One notable incident involves River Bank & Trust, a US financial institution that fell victim to a ransomware attack after an unauthorized individual breached the network of its parent company, River Financial Corporation, on June 16. The bank continues to assess the impact of this cybersecurity breach.

Chainguard launches a Bugcrowd bounty with up to $200K in rewards, inviting researchers to test its infrastructure against real-world attacks.

Clearinghouses alone won’t secure open source. Learn why actuation, trusted builds, and secure-by-design software matter more than vulnerability data.

What do board games and cybersecurity have in common? Pattern recognition. Strategy. Adaptation. In this week’s Threat Source Bill explores why curiosity may be a defender’s most valuable skill.

This post demonstrates how AWS DevOps Agent diagnoses Amazon Elastic Kubernetes Service (Amazon EKS) API server performance degradation, specifically 429 throttling and API Priority and Fairness (APF) seat exhaustion.

Learn how Microsoft is building a digital twin of Azure Service Health and why it changes how hyperscale operates. The post Meet Brain: The AI system behind Azure reliability appeared first on Microsoft Azure Blog.

The article by Philip Griffiths highlights the need for evolution in Zero Trust security measures, specifically steps 3, 4, and 5, beyond traditional methods like patching and ticket-driven connectivity. It emphasizes that the rapid pace of AI-driven threats necessitates a shift from merely identifying and fixing vulnerabilities to adopting a more comprehensive architectural approach to risk management. The focus should be on proactive strategies to mitigate exposure rather than just reactive measures.

Elastic’s InfoSec team built AI agents on Elastic Workflows that investigate every alert and assemble the case before an analyst ever opens it.

See how Chainguard uses Lens to monitor AI agents in real time with traces, evals, costs, and safeguards that make autonomous coding trustworthy.

Today, you can use AWS Network Firewall to protect traffic flowing to and from containerized applications on Amazon Elastic Kubernetes Service (Amazon EKS) and Amazon Elastic Container Service (Amazon ECS) clusters. If you run AI and machine learning (ML) workloads on Amazon EKS—such as model inference, RAG pipelines, or JupyterHub—your containerized workloads require the same

Today, we’re announcing Amazon EKS Version Rollback, a new capability that allows cluster administrators to safely roll back Kubernetes version upgrades on Amazon Elastic Kubernetes Service (Amazon EKS) clusters. With this feature, you can now confidently roll out new version upgrades across your EKS fleet with an additional safety net.

Frost & Sullivan names Microsoft a leader as cloud and application security converge into unified, runtime risk reduction. The post Microsoft named a leader in the Frost Radar for cloud and application runtime security appeared first on Microsoft Security Blog.

Azure Chaos Studio helps organizations validate application resilience by simulating outages, failovers, network disruptions, and infrastructure failures before they impact production. The post Proving application resilience on Azure with Chaos Studio appeared first on Microsoft Azure Blog.

If you manage secrets across multiple AWS accounts or need faster secret access for latency-sensitive applications, this post shows you how to meet those requirements using two new features of the AWS Workload Credentials Provider (provider). You will learn how to configure role chaining for cross-account secret retrieval and prefetching of secrets to reduce cold-start

Modern software development increasingly depends on third-party open source components, which has spurred significant innovation by allowing teams to concentrate on delivering value. However, this reliance introduces risks and pressures for Application Security teams, who must navigate a barrage of threats that challenge even seasoned organizations. To manage their growing workload, effective teams prioritize efforts to tackle the most critical tasks first, ensuring essential security measures are addressed.

JFrog’s Security Research team consistently tracks and evaluates newly disclosed CVEs in the open-source ecosystem. Their findings reveal that often, the severity scores assigned to vulnerabilities do not accurately reflect their actual impact or risk of exploitation. In 2025, JFrog researchers reviewed critical-severity vulnerabilities from the National Vulnerability Database (NVD) and determined that 96% of these scores were misaligned with the vulnerabilities’ true severity.

We’re opening the waitlist for our Monetization Gateway, which will allow you to charge for any web page, dataset, API, or MCP tool behind Cloudflare. The charges will settle in stablecoins over the x402 open protocol, with no payments stack of your own to build.

One year after declaring Content Independence Day, a dynamic market for monetized content has officially emerged. In this report, we examine how the rise of autonomous AI agents is upending traditional search referrals and detail the new infrastructure required to support a sustainable web economy.

Search is how we find nearly everything on the web — creators, merchants, answers. AI is rewriting the rules, leaving creators caught between staying discoverable in an agentic era and getting paid for their work. Today we’re launching two initiatives to help.

For our second Content Independence Day, we’re giving website owners finer options to manage AI traffic. Instead of a one-size-fits-all block, all customers can now easily distinguish and manage Search, Agent, and Training bots, alongside the new ability to protect ad-monetized pages.

The Threat Intelligence Bulletin for the week of June 22nd highlights significant findings in cyber research. A notable incident involves the Texas Parks and Wildlife Department, which suffered a data breach linked to a third-party vendor for its license system. This breach compromised sensitive information, including driver’s license details, passport numbers, email addresses, phone numbers, and residential addresses. For more details, the full bulletin is available for download.

Research by Alexey Bukhteyev highlights the evolution of large language models (LLMs) in both software and malware development. Check Point Research details how cybercriminals have increasingly utilized LLMs, including tools like ChatGPT, to generate offensive components and create malicious tools. This trend has led to new attack techniques such as browser-only ransomware, showcasing the sophisticated ways AI is being leveraged in cybercrime.

Ever wonder how someone goes from studying human viruses to leading cybersecurity teams? In this Humans of Talos, we’re joined by Martin Lee, EMEA Lead, to talk about his journey into the industry.

Talos has identified “ARToken,” a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoint exfiltration.

Cloudflare’s new Attribution Business Insights dashboard helps website owners understand crawler behavior, appetite, and potential value, fueling business-level conversations around crawl compensation.

Secure your authentication pipeline. Learn how the new Auth0 and Incode integration uses biometric identity verification to halt account takeovers.

Asylon Robotics Chief Engineer Eric Timmons shares lessons from building autonomous robots, where software, hardware, and real-world constraints collide.

This post comes from Pushkar Joglekar, Principal Security Engineer at Broadcom, where he focuses on VMware Kubernetes distributions. Pushkar is a Kubernetes security maintainer and co-author of the security chapters in Nigel Poulton’s “The Kubernetes Book.” He writes from experience securing infrastructure at scale. It starts with a failing deployment. You attempt a quick fix—maybe

We’re accelerating quantum-safe readiness—and sharing what organizations can do now to transition earlier and with confidence. The post Accelerating the quantum-safe timeline appeared first on Microsoft Security Blog.

As organizations modernize infrastructure, migrate mission-critical workloads, build cloud-native applications, and scale AI—cost efficiency remains a foundational principle of cloud architectures. The post Azure IaaS: How to design, build, and optimize cloud infrastructure for long-term cost efficiency appeared first on Microsoft Azure Blog.

This month’s updates help security and IT teams strengthen identity and multicloud foundations, protect data wherever it lives, and secure the developer workflows powering AI innovation. The post What’s new in Microsoft Security: June 2026 appeared first on Microsoft Security Blog.

AI is significantly impacting federal mission stacks, necessitating security processes that can adapt to the increasing attack surface. It has transformed the way teams develop software, identify threats, analyze intelligence, automate workflows, and make mission-related decisions. This shift is particularly critical for defense organizations involved in intelligence, electronic warfare, cyber operations, and software-driven systems, making AI a fundamental part of their operations.

TL;DR Vulnerability management is collapsing under scale and the remediation timeline for production workloads is not going to shorten fast enough to keep pace with attacks that adapt at machine speed. Aqua vShield is a patented runtime capability that closes the gap between discovery and remediation by enforcing compensating controls directly inside running containers, blocking

AI is accelerating vulnerability discovery. Explore the latest trusted open source trends, dependency risks, and CVE insights from Chainguard’s report.

The AWS Customer Incident Response Team (AWS CIRT) encounters patterns that repeat across engagements when helping customers respond to security incidents. We’re passionate about making sure that information is accessible so that everyone can improve their security posture and their organization’s resilience to disruption. The primary method we use to share this information is the

This article details the experience of building and operating a large-scale, serverless SaaS platform across multiple AWS accounts. It covers key learnings including the importance of scaling to zero, quota management strategies, the value of early engagement with AWS support, and unexpected operational practices that arose during significant function scale-up (from thousands to over a million).

iBusiness built a secure machine learning environment using Amazon SageMaker AI, VPC endpoints, and WorkSpaces Secure Browser to prevent data leaks while supporting data scientist productivity. This three-layered architecture provides a model for building secure and scalable machine learning environments.

In this post, you learn how to configure an Amazon Cognito User Pool for SRP-based game client authentication with no client secret. You will implement a Go runtime hook that validates Cognito JWTs and bridges player identity to Nakama sessions.

Claude in Microsoft Foundry is now generally available, hosted on Azure, and running on NVIDIA GB300 Blackwell Ultra, giving teams a faster path from agent experimentation to production. The post Claude in Microsoft Foundry is now generally available appeared first on Microsoft Azure Blog.

Eliminate context-switching during authentication development. Learn how to connect the Auth0 MCP Server to Claude Code for real-time access to the complete Auth0 documentation directly inside your terminal terminal workspace.

At Microsoft, building trustworthy AI agents is as critical as building powerful ones. New research from the 2026 Agent Confidence Index shows where teams trust agents today—and why human judgment remains the defining skill in the age of AI. The post The 2026 Agent Confidence Index: Where 300 builders see real momentum appeared first on Microsoft Azure Blog.

Azure Files combines familiar file access with built-in performance, data protection, security, and Azure service integration. The post Accelerate modern Linux workloads with Azure Files appeared first on Microsoft Azure Blog.

The Threat Intelligence Bulletin for the week of June 29 highlights recent cyber research findings. A significant incident involved Polymarket, a cryptocurrency prediction market, which confirmed a supply chain attack. This breach occurred after malware was injected into its website via a compromised third-party frontend vendor. As a result, users were misled into approving fraudulent transactions. The report underscores the ongoing risks associated with supply chain vulnerabilities.

The Cloud Security Alliance (CSA) has partnered with AIUC-1 to create a new designation for enterprises to identify providers that have proven their AI agents and autonomous AI systems are safe, secure, and reliable. Announced on June 30, 2026, this initiative responds to the increasing need for verifiable assurance in AI technologies, emphasizing the CSA’s commitment to promoting education and standards in AI, cloud, and Zero Trust cybersecurity.

Snyk VulnBench JS 1.0: 300 repeated scans show LLM security findings vary by run, while SAST and models catch different vulnerability gaps.

The industry has recognized that shipping agent code at scale requires runtime verification, and it is moving that way fast. The post Greptile, Cursor, and Devin agree that agents should run their code. What they run it against matters. appeared first on The New Stack.

The Shai-Hulud Miasma campaign has introduced new malicious packages due to a compromised maintainer account affecting the Leo Platform and RStreams ecosystems. Sonatype has identified 23 malicious package versions, which exploit techniques like binding.gyp to execute malicious code during installation, thus bypassing standard detection methods. Organizations must treat potentially affected environments as compromised and conduct thorough investigations, removing malicious versions and rotating credentials carefully to prevent further exposure. This incident highlights the escalating risk in the npm ecosystem, where attackers compromise trusted packages and workflows instead of merely publishing new malicious packages. Regular scrutiny of package behaviors at install time is essential for security.

For most of my career, software security has been treated as an individual responsibility.

In this week’s newsletter, Martin considers how AI will help threat intelligence by creating an easily queryable data source of intelligence reports.

Cloudflare Workflows, our durable execution engine for multi-step applications, now supports saga-style rollbacks, allowing developers to specify a compensating action for each step.do().

Component Object Model (COM) is a fundamental Windows technology used by legitimate applications for object activation, inter-process communication, automation and language-independent component reuse. Those same qualities make it useful to threat actors.

Chainguard Repository adds malware and greyware scanning, expanded policy controls, and visibility to secure AI-driven software supply chains.

Get the details on everything Chainguard announced during AI Readiness Innovation Week, including new features for Chainguard Libraries and Chainguard Containers

Wiz now scans Chainguard Libraries for Python and Java, combining trusted, source-built dependencies with risk-based visibility and remediation.

NIST’s shift to risk-based enrichment makes one thing clear: modern security teams need more than a single public source. In the AI era, trusted vulnerability intelligence depends on multiple signals, human validation, and clear context.

Varonis Threat Labs has identified a significant vulnerability known as SearchLeak in Microsoft 365 Copilot Enterprise. This multi-stage vulnerability allows attackers to easily access and steal sensitive information, including MFA codes, emails, meeting details, and confidential organizational files, with just one click. The discovery highlights serious security risks associated with Microsoft 365 Copilot, which can be exploited for silent data exfiltration.

Amazon Web Services (AWS) recently announced support for resource-based policies and resource control policies (RCPs) for AWS Sign-In. By using resource-based policies and RCPs, you can restrict access to the AWS Management Console sign-in and aws login CLI sessions to requests from your expected networks, your on-premises data center networks, and your Amazon Virtual Private

Learn how CNAPP platforms are helping organizations prioritize exploitable risks, reduce exposure, and operationalize security across the application lifecycle. The post CNAPP evolution: How Microsoft aligns with leading cloud risk management platforms appeared first on Microsoft Security Blog.

Machine learning models are not like other software artifacts. A single fine-tuned LLM can weigh 70 GB. A model family may share 95% of its weights across dozens of variants. When hundreds of developers, training jobs, and GPU clusters all need the same model at the same time, the infrastructure underneath needs to be built

Organizations have traditionally viewed SaaS security primarily as an access management issue, focusing on implementing Single Sign-On (SSO), Multi-Factor Authentication (MFA), and efficient user provisioning processes. However, the landscape of SaaS breaches has evolved, as illustrated by the recent ADT breach linked to the ShinyHunters extortion group. Reports indicate that attackers exploited an employee’s Okta account via a voice phishing attack, highlighting the need for a more comprehensive approach to security.

The landscape for AI regulation is changing quickly, influenced by new federal policies, a surge of state-level laws, and specific industry compliance needs. Organizations recognize the necessity for AI governance but often struggle with the complexities of this evolving environment. Proactive companies are not waiting for definitive regulations; instead, they are developing governance frameworks to ensure they can adapt to and comply with emerging requirements effectively.

Claude Cowork is not just a chatbot with additional features; it operates as a local agent on employees’ machines. This allows it to access files, execute shell commands, navigate the web using stored cookies, and connect to various enterprise systems. According to Anthropic, the potential impact of an issue with Cowork hinges on its access and permissions, significantly altering the threat model. A prompt injection attack can have varied consequences based on what Claude can read and execute.

Organizations increasingly rely on complex digital ecosystems that encompass cloud services, SaaS applications, API integrations, and outsourced infrastructure. Although these technologies enhance scalability and efficiency, they raise significant security challenges. As businesses expand their vendor networks, security and procurement teams face lengthy due diligence processes, repetitive security questionnaires, and a lack of visibility into third-party risks, complicating risk management.

Quantum computing and artificial intelligence (AI) are commonly seen as distinct technologies, each poised to revolutionize their respective fields. Quantum computing expands the boundaries of computational capabilities, while AI is transforming software development, data analysis, and decision-making processes. However, a more intriguing aspect lies in the potential synergy between these two technologies. The CSA’s recent publication discusses how quantum computing could enhance AI, creating a future of Quantum Artificial Intelligence.

Security control frameworks are expanding in both scope and complexity, with the CSA AI Controls Matrix featuring 243 control objectives and the NIST CSF containing hundreds of subcategories. Organizations utilizing multiple frameworks must perform mapping for compliance, gap analysis, risk aggregation, and audit preparation. Large Language Models (LLMs) have become essential for this task, enabling rapid and structured mapping across frameworks, streamlining the compliance process significantly.

AI’s ability to identify vulnerabilities quickly does not guarantee enhanced safety for organizations. The effectiveness of vulnerability discovery hinges not just on finding flaws but on the capacity of defenders to remediate them. A recent report by CSA, titled “Core Collapse,” emphasizes that without effective action following discovery, merely increasing the number of identified issues may not reduce security risks. This highlights a critical gap between detection and effective risk management.

As organizations aggressively shift from static Large Language Model (LLM) chatbots to fully dynamic, autonomous AI agents (e.g. systems designed to plan workflows, call APIs, write runtime code, and modify enterprise databases), traditional compliance and governance frameworks are hitting a breaking point. A landmark press release from Gartner highlights a critical systemic risk: treating AI

There’s a category of security risk that most organizations aren’t ready for. It doesn’t live in your code repository, your CI pipeline, or your developer laptops. It lives in your runtime, in the autonomous AI agents already running in your environment, extending their own capabilities, and making decisions that no human explicitly approved. This is

A note to our customers and partners about Snyk’s AI transformation and organizational changes.

Self-Managed OAuth is now available to all developers on Cloudflare. Here’s how we executed a zero-downtime migration of our core OAuth engine to make it happen.

Chainguard expands Containers with RPM support, FIPS enhancements, and easier migrations, bringing secure-by-default software to enterprise workflows.

Connect Cursor to Chainguard in minutes and make secure, malware-resistant containers and libraries the default for AI-generated code.

Chainguard Actions enters Open Beta with 500+ hardened GitHub Actions, one-day request SLAs, and automated migration for safer CI/CD.

Chainguard brings secure-by-default containers and libraries to AI coding tools like Kiro and Cursor, making trusted open source the default.

Chainguard uses AI-powered agents to continuously enforce engineering standards, remediate drift, and keep codebases aligned at scale.

The new executive order sets a 2030 migration deadline and establishes a powerful foundation for post-quantum resilience. We look at what it gets right, where it can go further, and our migration playbook for government and industry.

In this post, we walk through the performance and scalability improvements we shipped across the four pillars of EKS Auto Mode: runtime, compute, storage, and networking.

Modern software teams do not have a visibility problem. They have a prioritization problem.

TL;DR When a container is compromised, the SOC needs the full picture of what happened and fast. The problem is that runtime security data from cloud native workloads often lives outside Splunk, in a separate tool the analyst must pivot to at exactly the wrong moment. Aqua’s integration with Splunk solves this by streaming its

Your developers install agent plugins every day: pulling from unmanaged GitHub repos, copying Cursor commands out of Slack, pointing Codex at a personal Git fork. Each of those is a new, uncontrolled distribution channel inside your software development lifecycle, and your platform team has zero visibility into any of it. A plugin is not a

Announcing Snyk Agentic Development Security, a new Evo solution that helps organizations securely adopt AI-driven development with visibility, governance, and control.

AI agents introduce security risk through the actions they take, not just the code they produce. Learn how agent behavior governance helps teams observe, steer, and block risky actions in real time.

AI coding agents are adding a new layer to the software supply chain. Learn what Snyk found in nearly 10,000 developer environments and how to secure the tools, instructions, and permissions behind agentic development.

A forgotten credential at vendor Klue let attackers reach customers’ Salesforce data. How modern SaaS breaches cascade, and the keys you should audit.

Chainguard Libraries for Java is now GA, delivering CVE-remediated dependencies with SBOMs, provenance, and scanner-recognized fixes.

How Elastic’s security team built an AI agent with RAG against MITRE’s CWE and CAPEC catalogues to draft CVE advisories from raw vulnerability reports, including the full prompt and crawler configs.

For years, the software industry has told teams to shift security left. That was the right instinct. Finding issues earlier is better than finding them in production.

By rearchitecting the Images binding, we accidentally uncovered a bug that existed in the open-source hyper library across multiple major versions.

This article details a two-layer authorization pattern for enhanced access control within Retrieval-Augmented Generation (RAG) applications. The “defense-in-depth” approach uses multiple, independent security layers to ensure access control even if one layer fails. The pattern is demonstrated using Amazon Bedrock, a managed service providing access to foundation models and tools for building generative AI applications with security and responsible AI practices.

Avanse Financial Services, a leading Indian education loan provider, transitioned to a cloud-native lakehouse architecture using Amazon SageMaker. This migration consolidated their data engineering, analytics, and AI workflows within a governed AWS environment. The post details their journey to help others replicate the approach.

This article details a five-layer AI-powered resilience framework. It addresses challenges in resilience testing by automatically discovering dependencies and generating targeted experiments, integrating with existing CI/CD pipelines. The post outlines the architecture and provides implementation guidance, including phased rollout strategies for pilot, expansion, and organization-wide deployments.

Amazon has introduced a new feature enabling customer-routed control plane egress for Kubernetes, allowing users to route control plane traffic through their own Amazon Virtual Private Cloud (VPC). This includes key functionalities such as admission webhook callbacks, OpenID Connect provider lookups, and aggregate API server requests. Users can now apply existing VPC routing, security group settings, endpoint policies, and AWS Network Firewall controls to the outbound traffic of the Kubernetes API Server on Amazon EKS clusters.

When securing an Amazon Web Services (AWS) environment, teams naturally prioritize inbound controls, firewalls, WAFs, and access policies, because that’s where the most visible threats originate. Outbound traffic, on the other hand, tends to get less attention. It’s often left open by default to avoid breaking application dependencies and because the risk feels less immediate.

Gartner names Chainguard a Leader in Software Supply Chain Security, highlighting its secure-by-default approach and market vision.

Chainguard proposes a Maintainer of Last Resort to patch abandoned open source projects, publish trusted builds, and keep critical software secure.

The moment an agent needs to deploy something, it slams face-first into a wall built for humans. Today we’re rolling out Temporary Accounts on Cloudflare Workers. Any agent can now run wrangler deploy — temporary and get a live Worker in seconds.

Azure AD Graph Activity Logs land in Elastic with full ECS parsing. Detect ROADrecon and AADInternals enumeration with ready-to-use detection rules.

Find out how a new obfuscated loader evades static detection using .reloc section abuse, five anti-VM/language checks and MBA obfuscation to deliver infostealer malware via Google Ads.

In the face of security incidents in Amazon Web Services (AWS), quick response is essential, yet many security teams find themselves hampered by lengthy manual processes. Analysts are burdened with the need to memorize intricate AWS Command Line Interface (AWS CLI) syntax and to manually integrate data from various security tools such as Amazon GuardDuty and AWS CloudTrail. This complexity can hinder efficient investigations and response efforts during critical events.

In the latest Threat Source, Hazel channels her inner Spielberg to explore why humans are delightfully irrational, reminding us that while security best practices are simple in theory, they’re a lot harder to pull off when you’re busy dealing with real life.

We break down the technical architecture behind our multi-stage vulnerability discovery harness and automated triage loop. Learn how we manage state controls, squash false positives through adversarial review, and route around LLM context limits.

Amazon Web Services (AWS) is excited to release the Spring 2026 System and Organization Controls (SOC) 1 and 2 reports in machine-readable OSCAL format alongside the PDF version of the reports. The reports cover 188 services over the 12-month period from April 1, 2025 to March 31, 2026, giving customers a full year of assurance.

The recognition is new; the commitment behind it isn’t. It’s official. Gartner just published the very first Gartner® Magic Quadrant™ for Software Supply Chain Security, and JFrog has been recognized as a Leader, placing highest for Ability to Execute among all the vendors included. For an inaugural report in a category this important, that placement

To mark the 12th anniversary of Project Galileo, Cloudflare has released its first comprehensive report analyzing cyberattacks against civil society.

Open source maintainers are drowning in real vulnerability reports and need help prioritizing, fixing, and shipping remediation faster. Snyk’s Secure Developer Program gives qualifying projects free access to the Snyk AI Security Platform.

Chainguard named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security, recognized for vision and secure-by-default innovation.

Chainguard launches a ready-to-run STIG scanner with a built-in GPOS SRG InSpec profile, simplifying compliance scans for containers and FedRAMP workflows.

The Agents SDK is now a runtime any agent framework can build on. Today we’re opening up the Agents SDK primitives, with Flue as a first framework targeting Agents SDK, and rolling out agents in the dashboard

What we believe We’ve been thinking deeply about enterprise security. The operating model that served us for the past decade (collect telemetry, store it, query it, build dashboards to watch it) is no longer keeping pace. We need to shift to the new world: telemetry, context, reasoning, and actions. An approach that produces outcomes. The

Vonage demonstrates how their network solutions integrate with Amazon Cognito for improved mobile identity verification. This integration, using the CUSTOM_AUTH flow, provides a silent authentication process with fraud protection, verifying identity in under 5 seconds without requiring user interaction.

This research examines a clipboard hijacker campaign concealed within a range of purported “solutions” and “tools” designed to give users an unfair advantage in cryptocurrency trading. The offerings include automated tools like Solana and Pump.fun sniper bots, which aim to facilitate faster purchases of new tokens or meme coins. The study highlights how fake reputations fuel these deceptive practices in the crypto space, ultimately putting users at risk.

A supply chain attack compromised all 143 @mastra packages. Chainguard customers stayed protected through malware blocking and source-built libraries.

Chainguard Agent Skills now offers 1,000+ hardened community skills, private registries, and beta hardening for first-party AI agent skills.

Explore a day in the life of an AI Engineer at Snyk’s Lisbon office. See what it’s like building AI-powered security tools, collaborating globally, and enjoying the vibrant culture of Portugal’s capital city.

Businesses of all sizes are increasingly recognizing the importance of data and AI governance as they scale their operations. Many companies prefer cloud-based ecosystems for their data management instead of investing in onsite equipment and software. This shift allows for better oversight and protocols while ensuring data protection and availability. Overall, the convergence of data and AI governance in the cloud is proving effective for enhancing compliance and operational efficiency.

A dormant contributor account was used to republish the entire @mastra npm scope, each injected with a single dependency, easy-day-js, that drops a cross-platform cryptocurrency stealer. Here is how the attack worked, how to check exposure, and how to remediate.

In this blog post you’ll learn how to detect and prevent subdomain takeover – a tactic where threat actors exploit dangling DNS records to redirect traffic to attacker-controlled resources. We’ll explain the issue, how the situation arises, and how you can use various AWS features and services to help mitigate the impact of this tactic.

In this post, we walk through the legacy architecture challenges, the stateless streaming solution, key implementation patterns, and performance results—a pattern you can apply if you’re building high-traffic APIs that aggregate data from multiple backend sources.

The Threat Intelligence Bulletin for the week of June 15 reports significant findings in cyber research. Notably, the University of Nottingham experienced a data breach when the hacking group ShinyHunters infiltrated its student records system. This breach compromised the personal information of approximately 454,600 current and former students, revealing their contact details and other sensitive data. For a comprehensive overview of recent threats and attacks, downloading the bulletin is recommended.

A government order abruptly took down a powerful AI model, exposing a new kind of supply chain risk for engineering teams. Security leaders need contingency plans before the next model disappears.

On June 12, 2026, a US export-control directive led Anthropic to disable Claude Fable 5 and Mythos 5 worldwide over a reported jailbreak. The reported trigger was a code-analysis capability that defenders use routinely. Here is what happened, how the security community read it, and what security teams can take from it.

Async agents are only useful if you can trust what they hand back. In a distributed system, that trust comes The post Agentic development hinges on verification. For cloud-native software, that is a runtime problem. appeared first on The New Stack.

Yarden Porat discusses the necessity of memory in AI agents, specifically through frameworks like LangGraph, which includes checkpointers for maintaining execution state. However, vulnerabilities can arise if the persistence layer is not secure. LangGraph, an open-source tool for creating multi-agent AI systems with state management, is an extension of LangChain. The article delves into the potential exploitation of its checkpointer feature, a topic of concern highlighted by Check Point Research.

This article introduces a new Snowflake and AWS Custom Well-Architected Framework Lens. It combines AWS best practices with Snowflake guidance for a streamlined review process, offering integrated recommendations for how the services work together. The post details each pillar, access methods (AWS Management Console, Kiro, and Snowflake Cortex Code), and provides instructions for conducting an initial review.

Chainguard often ships security fixes before advisories reach scanners. Learn why upstream speed matters in the era of AI-driven exploits.

In this post, you will learn how Amazon EKS Auto Mode and Istio Ambient Mesh work together to automate infrastructure management while providing automatic mTLS-based service-to-service security, helping reduce operational overhead and designed to help strengthen your security posture.

In this post, you learn how to build an automated, serverless pipeline that converts scanned PDF medical records into FHIR R4-compliant data using Amazon Bedrock Data Automation and AWS HealthLake. We walk through the architecture, explain how each AWS service connects to the next, show you what the pipeline looks like when it runs, and get you deployed in under 20 minutes.

TL;DR: Frontier AI models are discovering zero day vulnerabilities and weaponizing them in hours. Boards, regulators and underwriters have noticed, and they are asking a question most CISOs cannot answer: “What does our exposure cost in dollars?” Reporting in CVE counts and CVSS scores made sense when the threat timeline gave security teams room to

Agentic AI shifts the dynamics of red teaming, moving beyond the assessment of harmful text generation to consider the implications of AI systems that can plan, reason, and engage with various tools and workflows. This new approach highlights the necessity of red teaming specifically tailored for agentic AI. A recent research publication by CSA evaluates Microsoft’s Python Risk Identification Toolkit (PyRIT) as a means of effectively assessing risks associated with agentic AI.

A new survey report from the Cloud Security Alliance and Miggo Security reveals that despite extensive investments in shift-left security, application security teams are struggling to manage vulnerabilities effectively in production. The report highlights that the challenge now goes beyond just visibility; security teams face an overwhelming number of threat intelligence findings and alerts, indicating a need for improved strategies to address the complexity and volume of security issues.

Enterprise artificial intelligence has evolved from simple Large Language Model prompts to sophisticated multi-agent systems with significant operational autonomy. These advancements enhance software development, supply chain coordination, and threat responses. However, they also create new security vulnerabilities, making traditional methods of identity, data protection, and boundary defense less effective. Organizations must adapt to address these emerging risks effectively.

In cybersecurity, not all damaging attacks stem from complex techniques; some originate from overlooked issues like forgotten DNS records. This was highlighted by researchers who identified a significant campaign that exploited abandoned CNAME records across several universities, including UC Berkeley, Columbia University, and Washington University in St. Louis. Attackers hijacked these subdomains, leveraging the trust associated with .edu domains to facilitate malicious activities.

Chainguard’s new scanner blocks malware and ‘greyware’ before it reaches developers, protecting 100,000+ packages daily across open source ecosystems.

Read all about the latest AWS security features, compliance updates, and hands-on resources in our new, monthly digest posts. You’ll find expert blog posts, new service capabilities, code samples, and workshops. AWS Security Blog posts This month’s AWS Security Blog posts covered AI security, network protection, identity management, compliance frameworks, and supply chain security. Read

The latest Threat Intelligence Bulletin provides insights into recent cyber research, highlighting significant events from the week of June 8th. A notable incident involves DentaQuest, a U.S. dental benefits administrator, which experienced a data breach attributed to the ShinyHunters group. The breach compromised approximately 2.6 million accounts, exposing sensitive information such as names and emails. For more detailed findings, refer to the full report.

A new npm supply chain worm compromised 57 packages and 286 versions. Learn how Chainguard blocked the attack and protected customers by design.

A new npm worm is abusing binding.gyp to trigger node-gyp during install, letting malicious packages run code without lifecycle scripts. It steals credentials, persists in GitHub, and self-propagates across maintainers.

An AI security budget should fund more than visibility. The real priority is unified governance and enforcement across agentic development and production apps.

Secure-by-design types can turn common bugs into compile-time errors. This post explores how type-level security could help prevent entire classes of AI-generated vulnerabilities.

In this post, we show you how to run a one-hour prioritization session with your stakeholders, plot competing initiatives on a shared matrix by cost and impact and turn the result into an actionable architecture backlog - using a framework called Tech Roadmap Prioritization (TRP).

This post shows how to build a highly available Oracle database architecture using FSxN shared storage, Auto Scaling groups with dynamic AMI updates, and serverless orchestration to help reduce recovery times with current configurations.

Research conducted by Alexey Bukhteyev explores the various tactics used in a malware distribution ecosystem, including impersonation, click hijacking, and traffic distribution systems (TDS). Users often click the first search result on Google, typically an official project site, without scrutinizing the other results. This habit can lead to vulnerabilities, as malicious sites often mimic legitimate ones, posing significant risks to unsuspecting users. The study highlights the importance of awareness regarding these deceptive practices.

AI agents are changing how software gets built, and with it, where security risk begins. Learn why securing the process matters as much as securing the code.

In this post, we show you how Doczy.ai™ uses generative AI on AWS to automate contract intelligence at scale, transforming unstructured documents into structured, actionable insights, so organizations can automate critical business processes and unlock the full value of their data.

Find out how Elastic Security ingests Google Threat Intelligence for continuous detection and uses AI-driven workflows to enrich alerts in real time, from API key to live detections in minutes.

jqwik 1.10.0 added a hidden prompt injection aimed at AI coding agents, using terminal escape codes to conceal destructive instructions from humans while leaving them readable to logs and tools.

This post details how NYCBS partnered with Amazon Web Services (AWS) and AWS partner Pronetx (now part of Caylent) to migrate to Amazon Connect Customer, the AWS cloud contact center service. The migration delivered a 54 percent improvement in patient enrollment and transformed the way NYCBS connects with the patients who need them most.

The Threat Intelligence Bulletin for the week of June 1st highlights recent cyber research findings. A significant incident reported is a data breach at Carnival Corporation, impacting nearly 6 million individuals. The breach resulted from social engineering tactics that compromised an employee’s account, with potentially exposed data including names and contact information. The bulletin provides insights into these threats and more detailed analyses for cybersecurity professionals.

A new npm worm hit 90+ Red Hat packages. Chainguard customers stayed protected by blocking install-time scripts and hardening CI/CD workflows.

A supply chain worm dubbed Miasma has been found in dozens of @redhat-cloud-services npm releases. The malicious preinstall hook steals credentials, probes cloud identities, and can republish other packages.

Financial analytics at an enterprise level demands quick responses, with queries needing to return results in seconds rather than minutes. During monthly closing cycles, thousands of finance professionals require simultaneous access to data. As data volumes expand significantly—from hundreds of gigabytes to terabytes, covering billions of records—the underlying infrastructure must efficiently scale. This presents a challenge to engineers, who must balance performance with cost-effectiveness.

The OpenTelemetry (OTel) ecosystem provides us not only with a standard data format and transport mechanism for generating, processing, and The post Vendor neutrality isn’t magic: A hard look at the OpenTelemetry ecosystem appeared first on The New Stack.

Stop security backlogs. Snyk’s Remediation Agent in the CLI pairs AI reasoning with Snyk security intelligence to fix SCA issues at scale directly in your terminal.

See how Relay Network securely adopted AI coding with Snyk and GitHub Copilot, implementing “secure at inception” to reduce vulnerabilities and accelerate development.

Mythos is changing software security fast. AI-driven zero-days demand new trust infrastructure, coordinated disclosure, and secure open source consumption.

Snyk’s Continuous Offensive Security unifies DAST, AI pentesting, and agent red teaming to find exploitable flaws — not just bugs — before attackers do. Here’s why lineage matters.

Mythos and AI-driven exploits are breaking old security assumptions. Learn the five myths security teams must retire to survive the new era.

During the March-April 2026 reporting period, the utilization of AI in offensive operations evolved significantly, transitioning from planning and development stages to real-time deployments. There were several independent instances where various actors, including criminals, ransomware groups, and state-sponsored entities, employed commercial AI models to carry out autonomous attack workflows in extensive campaigns. The findings highlight the growing threat of AI in real-time offensive operations.

Chainguard and Upwind combine trusted, source-built artifacts with runtime verification to cut noise, reduce risk, and secure AI-era software.

Tycoon 2FA bypasses MFA on Entra ID and Google Workspace. We map telemetry fingerprints across both platforms, ship detection rules for both tiers, and contain incidents in under 10 seconds with Elastic Workflows.

Anthropic’s Mythos raises the stakes for software security. Learn how to survive faster exploits with secure-by-default supply chains and AI-assisted defense.

The Threat Intelligence Bulletin for the week of May 25 highlights significant cyber research discoveries. A key incident involved a data breach at 7-Eleven, where unauthorized access occurred to systems handling franchisee documents. The hacker group ShinyHunters has claimed responsibility, asserting that they stole over 600,000 Salesforce records containing personal information. The report details these and other relevant threats and breaches.

As someone who’s been maintaining Jaeger, I’ve watched users request ClickHouse support consistently over the past few years. With Jaeger The post How Jaeger hit 8.6× compression on 10 million spans with ClickHouse appeared first on The New Stack.

Hundreds of historical Laravel Lang Packagist releases were republished with malicious code, putting Composer installs at risk of credential theft and secret exfiltration.

How Frontier firms secure AI at scale: read how Microsoft customers embed governance, identity, and cloud security to make protection an enabler of AI growth. The post Microsoft Security success stories: How St. Luke’s and ManpowerGroup are securing AI foundations appeared first on Microsoft Security Blog.

Elastic Security Labs presents a detailed reverse-engineering analysis of PHANTOMPULSE, the long-lived RAT delivered to crypto-sector victims through the REF6598 intrusion set.

Snyk announces two new integrations with Anthropic that cover both sides of AI-assisted development. Evo by Snyk now integrates with Anthropic’s Claude Enterprise, and the Snyk Security Desktop Extension is now available in Claude for macOS and Windows.

Microsoft Security’s latest updates extend visibility, control, and protection across expanding ecosystems as organizations accelerate AI adoption. The post What’s new in Microsoft Security: May 2026 appeared first on Microsoft Security Blog.

The Cloud Native Computing Foundation (CNCF) on Thursday announced the graduation of OpenTelemetry, the open source observability framework that has The post After becoming cloud computing’s telemetry standard, OpenTelemetry graduates into the AI infrastructure era appeared first on The New Stack.

AI is accelerating code creation. Learn how Snyk is scaling its AI Security Platform and investing in new partner programs to help enterprises govern AI-generated code at scale.

This post demonstrates an automated solution that combines AI-powered risk analysis with GitOps principles to streamline Amazon EKS AMI updates while maintaining appropriate human oversight through familiar GitHub workflows.

Go behind the scenes with Lulu, a Strategy Co-Op at Snyk, and discover a day balancing high-impact AI security projects with a vibrant Boston office culture.

A day after the AntV npm supply chain attack, the same campaign appears to have struck durabletask, a Microsoft-associated Python package on PyPI. Snyk has coverage in the vulnerability database and package health pages. Here’s what we know.

Chainguard and Endor Labs help teams build securely at AI speed with source-built artifacts, exploitability analysis, and fewer vulnerabilities to triage.

The Mini Shai-Hulud npm worm compromised 314 packages in the AntV ecosystem on May 19, 2026 — including echarts-for-react and timeago.js.

A compromised npm maintainer account triggered an automated burst of over 300 malicious package versions across 323 packages in the AntV data visualization ecosystem, part of the ongoing Mini Shai-Hulud supply chain worm campaign. Here’s what the malware does, how to detect exposure, and how to respond.

On May 14, 2026, multiple malicious versions of the popular npm package node-ipc were published to the npm registry. Current public reporting identifies node…

CPCSC compliance is coming fast. Learn how Chainguard helps Canadian defence suppliers meet Level 1 requirements with secure, zero-CVE containers.

Malicious node-ipc packages stole cloud, SSH, Kubernetes, and AI keys. Chainguard customers stayed protected through source-built libraries.

Editor’s note: This article is an excerpt from Chapter 1 of the Manning book, Platform Engineering on Kubernetes. This excerpt The post Cloud native application challenges: installing the walking skeleton appeared first on The New Stack.

Coding agents perform better with a harness that gives them the tools, guidance, and feedback signals to know what to The post Why agent harnesses fail inside cloud-native systems appeared first on The New Stack.

A new supply chain worm hit 400+ packages. Learn why preventive security, not reactive patching, is the only way to stop the next attack.

Elastic Security is the first security vendor to ship an interactive UI in AI tools. Triage alerts, hunt threats, correlate attack chains, and open cases, all from inside your AI conversation.

On May 11, 2026, a breach known as the Mini Shai-Hulud worm affected 84 npm package artifacts within 42 @tanstack/* packages, alongside others like @squawk/* and @mistralai/*. The attack utilized a GitHub Actions “Pwn Request,” cache poisoning, and extracted OIDC tokens from runner memory, marking it as the first npm supply chain attack to achieve valid SLSA Build Level 3 attestations. The article outlines the details of the incident, what was compromised, and necessary immediate actions for users.

Chainguard adds first-party RHEL 9/10 RPM compatibility and joins FINOS, helping financial institutions modernize securely for the AI-driven threat era.

I still remember the first time we lost sleep over something that wasn’t a bug. It was a Tuesday. Grafana The post Why Prometheus couldn’t see Cilium metrics at 2 a.m. appeared first on The New Stack.

This research analyzes the Linux kernel privilege escalation vulnerabilities Copy Fail and DirtyFrag, which exploit subtle page cache corruption bugs to create reliable paths to root access. Additionally, Elastic Security Labs is releasing detection logic for these vulnerabilities.

Learn how modern cyber resiliency helps organizations prevent, detect, and recover from supply chain attacks like Trivy, Axios, and LiteLLM.

This article shows how a customized Elastic Security ES|QL detection rule can identify web server probing and fuzzing activity in Traefik logs and automatically block the attacking IP via Cloudflare.

Kubernetes is complicated; everybody knows it. Logically enough, Kubernetes deployed as a cluster of collected and coalesced instances at “fleet The post How Microsoft is governing thousands of Kubernetes clusters without manual intervention appeared first on The New Stack.

TL;DR AI-driven attacks on containerized environments are no longer theoretical. Frontier models can find vulnerabilities in hardened systems in hours and chain them into working exploits before your team has finished triaging the alert. When an attack moves that fast, the time your security program depends on between discovery and exploitation no longer exists. This

REF3076 uses a trojanized Logitech installer to deploy TCLBANKER, a Brazilian banking trojan with environment-gated payloads, WPF fraud overlays, and self-propagating WhatsApp and Outlook worm modules.

Kubernetes shipped a long-awaited security feature last week: user namespace support for pods. It may sound like an obscure feature The post Kubernetes finally lands user namespace support, but shared kernel problem remains appeared first on The New Stack.

Introducing AI-generated hunting leads, proactive, environment-aware threat hypotheses powered by Elastic Entity analytics and integrated AI reasoning.

Learn how Kyndryl reframed open source security as a business driver — reducing risk, lowering costs, and accelerating developer productivity.

Elastic Workflows is generally available in 9.4, bringing production-ready security automation with deeper case management integration, human-in-the-loop support, natural language authoring, and more.

Elastic Security v9.4 introduces Entity Analytics Watchlists, a way to codify what your team already knows about high-risk entities and feed that context directly into risk scoring, without custom pipelines or detection engineering overhead

Most entity analytics systems are confidently wrong. They track users who do not exist, generate risk scores built on noise, and call it behavioral analytics. Learn why the entities records you don’t create matter as much as the ones you do and how a confidence-tiered model changes the game.

Conversational Entity Analytics delivers Entity Analytics features as rich inline attachments and Canvas previews into Agent Builder, so you don’t have to leave the conversation.

Elastic Security now lets analysts describe a threat behavior in plain language and receive a complete, validated Elasticsearch ES|QL detection rule in return, no query expertise required.

With Chainguard Libraries, customers rely on a single controlled, auditable system.

Chainguard OS achieves 100% package test coverage, verifying every component runs correctly to make rolling updates secure, reliable, and enterprise-ready.

Stay ahead of emerging threats with Microsoft’s newest security innovations and updates, delivered through the In the Loop series. The post What’s new, updated, or recently released in Microsoft Security appeared first on Microsoft Security Blog.

Chainguard delivers zero-CVE, FIPS 140-3 EKS add-ons on AWS Marketplace, simplifying secure Kubernetes for regulated environments with full control.

A malicious release of the lightning PyPI package ships a credential-stealing Bun payload that runs on import. Snyk has a live advisory. Here’s what’s in the package, what to rotate, and how the payload pattern connects to the Mini Shai-Hulud npm campaign one day earlier.

A new npm supply chain attack self-branded “Mini Shai-Hulud” compromised four SAP-ecosystem packages on April 29, 2026. Snyk has live advisories. Here’s the technical breakdown, IOCs, and what to do.

Bridge the gap to autonomous fixes. Snyk and Atlassian integrate to transform Jira security tickets into precision fixes using Snyk Studio AI, eliminating context switching and resolving vulnerabilities in minutes.

New npm worm targets 2.25M-download packages. Chainguard customers stayed protected by blocking install-time scripts and malicious dependencies.

CMMC Phase 2 and NIST 800-171 are here. Learn how Chainguard helps teams meet compliance with FIPS, STIGs, and zero-CVE containers.

CVE-2026-40478: The Thymeleaf template injection (CVSS 9.1) is conditional. Patch to 3.1.4+ immediately, and audit your code for dynamic view or template expression misuse, which is the key precondition for exploitability.

Chainguard introduces a 1-day KEV SLA, ensuring exploited vulnerabilities are fixed fast—aligned with how security teams prioritize real-world threats.

Attackers exploited a GitHub Actions script injection vulnerability to publish a malicious version of the elementary-data Python CLI (v0.23.3), embedding a credential-stealing backdoor that targeted dbt profiles, cloud provider keys, and SSH secrets from data engineering environments.

Snyk Agent Fix upgrades to a new agentic architecture for faster, smarter, and more secure AI-powered code fixes. Now with full Snyk Code language coverage and verified remediation.

Anthropic’s Mythos is reshaping zero-day threats. Learn how Chainguard helps you stay ahead with source-built, continuously secure software supply chains.

Two authentication bypass vulnerabilities (CVE-2026-3965, CVE-2026-4047) in the Qinglong task scheduling panel were exploited in the wild to deploy cryptomining malware. Here’s what happened, how the attacks worked, and what self-hosted application operators should learn from this incident.

Malicious elementary-data version hit PyPI. Chainguard customers stayed protected by detecting malware pre-build and serving only verified safe versions.

Boris Cherny, who built Claude Code, recently shared on X how to get the most out of it following the The post Why Claude needs a real environment to validate cloud-native code appeared first on The New Stack.

Google’s Threat Intelligence teams are focusing on Indirect Prompt Injection (IPI) as a significant threat to AI systems, monitoring for attacks before they affect users. IPI can manipulate AI by embedding harmful prompts in web content, differing from direct injections. Using Common Crawl, researchers identified various types of prompt injections, from harmless pranks to malicious attempts for data theft. While current attacks show limited sophistication, a noted increase in malicious attempts suggests that IPI threats are evolving. Google is actively enhancing defenses against these emerging threats.

Snyk Secrets bridges the gap between code and credentials with real-time, high-precision detection, ensuring your most sensitive data stays hidden while your developers stay fast.

JPMorganChase published a 10-point cyber resilience checklist. See how Snyk covers 8 of the 10 actions and where it fits in your security stack.

TL;DR Security teams have spent years and billions of dollars shifting security left. This has changed what teams can see and introduced a new level of visibility, but it has not helped with what they can control. Last year, more than 48,000 new vulnerabilities were cataloged, growing at roughly 20 percent annually. Add to that

New npm and PyPI malware hit many popular packages. Chainguard customers stayed protected by blocking install scripts and rebuilding only verified source code.

Chainguard and Cursor partner to secure AI-generated code with trusted, source-built containers and libraries, reducing risk without slowing developers.

How NASA Artemis used AI and Chainguard to enable secure, compliant software and faster mission readiness in high-stakes environments.

Learn how to build a comprehensive cryptographic inventory and strengthen quantum‑safe readiness using Microsoft Security tools, best‑practice lifecycle models, and partner solutions. The post Building your cryptographic inventory: A customer strategy for cryptographic posture management appeared first on Microsoft Security Blog.

Learn how companies can scale third-party container image management with Chainguard to reduce risk, cut toil, and accelerate compliance and developer velocity.

Docker ships their own Linux distro, they just pretend not to. Learn how misidentification and VEX usage can mislead scanners and impact supply chain security.

AI is lowering the barrier to cybercrime. Learn why attacks are rising fast, and how eliminating entire classes of supply chain risk is the only path forward.

TL;DR We are about to have a serious problem: attackers no longer need months to investigate and exploit systems, they need minutes. Anthropic says its unreleased Claude Mythos Preview can autonomously find severe vulnerabilities, reproduce them and in some cases chain them into working exploits across hardened systems. The model was deemed too dangerous to

Google is enhancing security for Pixel devices by integrating a memory-safe Rust DNS parser into the modem firmware of the Pixel 10, building on earlier efforts to mitigate vulnerabilities in complex modem firmware. This development significantly reduces security risks associated with memory unsafety in DNS operations, crucial for modern cellular communications. The project emphasizes the importance and potential of using memory-safe languages in low-level programming, laying groundwork for future enhancements in device security.

Project Glasswing and Claude Mythos Preview reveal a surge in zero-days. Learn why reactive patching fails and how secure-by-default supply chains keep you safe.

AI can find vulnerabilities at scale, but enterprise security now depends on control, validation, and governance that can keep up.

Is Grype a single point of failure? Learn how Chainguard uses layered defenses, source builds, and multiple data sources to ensure trusted CVE detection.

Google has announced the public availability of Device Bound Session Credentials (DBSC) for Windows users on Chrome 146, with macOS support coming soon. This initiative aims to combat session theft, which typically occurs when malware extracts session cookies from browsers. DBSC works by cryptographically binding authentication sessions to specific devices using secure hardware modules, ensuring that exfiltrated cookies quickly expire and become unusable. The protocol is designed to prioritize user privacy, preventing cross-site tracking. Google collaborated with the web community on DBSC’s development and plans to enhance its capabilities for enterprise environments and broader device support in the future.

Until recently, running an AI model on Kubernetes was a guessing game. What worked on one cloud provider could fail The post The next stages of AI conformance in the cloud-native, open-source world appeared first on The New Stack.

Open source attacks are rising. Chainguard Libraries rebuilds packages from verified source to block malware—now free until June 30, 2026.

Five supply chain attacks in 12 days exposed a broken trust model. Learn why scanning and hardening fail, and why trusting the source is the only fix.

Chainguard is deprecating SecDB in favor of OSV, delivering more accurate, granular vulnerability data and better visibility for modern software supply chains.

At KubeCon EU 2026 in Amsterdam, I sat down with Mitch Connors, a principal software engineer at Microsoft and Istio The post Microsoft wants to make service mesh invisible appeared first on The New Stack.

AI is accelerating code and attacks. Learn why patching alone can’t keep up, and why securing the software supply chain starts with trusted inputs.

For years, the debate around digital sovereignty focused on infrastructure. Now the spotlight is shifting to a far more valuable The post True enterprise sovereignty is more approachable than ever, thanks to K8s-powered cloud-neutral PostgreSQL appeared first on The New Stack.

Announcing Snyk Container Registry Sync GA for automated image management and runtime intelligence. Scale container security effortlessly for the fast-paced AI era.

Modern supply chain attacks target CI, dev machines, and dependencies. Learn how building from source helps prevent malware and reduce risk.

Find out how putting runtime telemetry directly in the hands of developers can help your team debug faster, reduce escalations, The post Is observability still an operations problem at your organization? appeared first on The New Stack.

Adam Gavish from Google’s GenAI Security Team discusses indirect prompt injection (IPI) as a growing threat to AI applications like Workspace with Gemini. Attackers can manipulate AI behavior by embedding malicious instructions within data sources, sometimes without user input. Google employs a multi-faceted strategy to enhance defenses against IPI, including proactive attack discovery, red-teaming simulations, a vulnerability rewards program, and synthetic data generation. They focus on improving LLMs to better identify harmful commands while ensuring operational efficiency. Ongoing defense refinement involves updating configurations, retraining models, and extensive testing to validate improvements. Google’s commitment to AI security emphasizes a robust, agile response to evolving threats, aiming to provide a safe user experience in AI-first environments.

Broadcom has deep roots as one of the leading contributors to CNCF open source as it continues to extend its The post Why Broadcom gave Velero to the CNCF Sandbox — and what it means for Kubernetes data protection appeared first on The New Stack.

The LiteLLM compromise showed AI risk extends beyond dependencies. Use Evo AI-SPM to map your full AI blast radius, securing connected models, tools, and agent workflows.1

Learn how PeopleTec used Chainguard to reduce security friction, accelerate adoption, and align platform consistency with developer velocity.

Public registries create supply chain risk. Learn how source-built libraries help APRA-regulated teams improve security, resilience, and auditability.

Open Source Security Advisory Update: Wednesday, April 1, 2026 Boston, MA 10:00 AM ET Over the past week, we have nearly finalized our investigation and are now in the final stages of documentation and review. There continues to be no indication that Aqua’s commercial products have been affected. As part of this process, we identified

Learn 5 key lessons from Snyk’s Evo design partner program. Discover how AI discovery, risk intelligence, and policy automation help teams secure generative AI and govern AI sprawl at scale.

In 2025, Google celebrated the 15th anniversary of its Vulnerability Reward Program (VRP), enhancing collaborations with the security research community. The program awarded over $17 million to more than 700 researchers globally, marking a 40% increase from the previous year. New initiatives included a dedicated AI VRP and a patch rewards program for open-source vulnerabilities. Significant bugSWAT events resulted in numerous reports and rewards. Looking ahead to 2026, Google plans to continue these efforts, fostering innovation and security enhancements.

Malicious axios versions on npm delivered a RAT via a hidden dependency. Chainguard customers were protected by blocking unsafe packages and verifying source.

AI is accelerating software and CVE growth. Chainguard’s latest report shows rising risk in the long tail and how teams can stay secure at scale.

Meta description: Malicious versions of the Axios npm package (1.14.1 and 0.30.4) were published via a compromised maintainer account, injecting a hidden dependency that deploys a cross-platform remote access trojan. Here’s what happened, who’s affected, and how to check your exposure.

The mass adoption of WebAssembly has yet to be realized. The true turning point for WebAssembly — specifically its ability The post WebAssembly is now outperforming containers at the edge appeared first on The New Stack.

The ability to provision a Kubernetes cluster on demand, with full API access, custom RBAC, and isolated resource namespaces, defines The post How platform teams are eliminating a $43,800 “hidden tax” on Kubernetes infrastructure appeared first on The New Stack.

So many agents, so little time to evaluate them. Solo.io‘s new projects can help. Agentic AI has blown up. These The post Solo.io launches agentevals to solve agentic AI’s “biggest unsolved problem” appeared first on The New Stack.

Malicious telnyx versions hit PyPI in a wider supply chain attack. Chainguard customers stayed protected by using source-built, verified libraries.

Discover the 5 principles behind Snyk’s developer experience. Learn how seamless workflows, actionable fixes, and AI-driven security help developers ship secure code faster without disrupting productivity.

If you’re a platform engineering leader managing Kubernetes at scale, a new pressure has entered the room. The business wants The post Your Kubernetes isn’t ready for AI workloads, and drift is the reason appeared first on The New Stack.

Google is addressing the imminent threats posed by quantum computing to digital security through the introduction of Post-Quantum Cryptography (PQC) in Android 17. This transition aims to safeguard essential digital systems currently reliant on public-key cryptography. Key upgrades include PQC integration in Android Verified Boot and Remote Attestation, which enhance foundational security, and updates to the Android Keystore for developers to utilize quantum-resistant cryptography. The approach also promotes hybrid signing for Google Play apps to ensure app authenticity against quantum-enabled signature forgery. This initiative, part of a broader plan initiated in 2016, aims to fortify the entire Android ecosystem against future quantum threats.

AI red teaming is the next step after AI-SPM. Learn how Evo Agent Red Teaming simulates real attacks to uncover prompt injection, data exposure, and behavioral vulnerabilities in AI systems.

Chainguard’s Activity Center centralizes alerts for CVEs, breaking changes, and updates — delivering real-time notifications where your teams already work.

On March 24, 2026, threat actor known as TeamPCP published backdoored versions of the litellm Python package after stealing PyPI credentials via a compromised Trivy GitHub Action in LiteLLM’s CI/CD pipeline. Here’s what happened, how the three-stage malware works, and how to check if you’re affected.

Hackers compromised litellm on PyPI to steal secrets. Chainguard Libraries prevented exposure by rebuilding only verified source, blocking malicious releases.

Introducing Agent Security, a unified approach to governing AI agents and ensuring safe behavior from code to runtime. Start with Evo AI-SPM, now generally available.

My gut reaction has often been to compare WebAssembly to Kubernetes. Flash back to over four years ago: Then, I The post Why WebAssembly won’t replace Kubernetes but makes Helm more secure appeared first on The New Stack.

I recently caught a post from Hyperframe Research that asked a question many of us in the cloud-native trenches have The post Why the ‘glorified host’ for AI is exactly the Kubernetes we need appeared first on The New Stack.

Linux kernel developers operate under constraints that very few other open source community maintainers experience. Evolving the capabilities of the The post Linux kernel scale is swamping an already-flawed CVE system appeared first on The New Stack.

Chainguard customers are unaffected by the Trivy supply chain attack.

Static analysis tells you what might be vulnerable, but dynamic testing tells you what is actually exploitable. Learn why the next era of AppSec requires combining code-level context with live environment testing to secure AI-generated code.

In modern observability, distributed tracing is often considered the most expressive signal. It can be used to capture much of The post Sampling: the philosopher’s stone of distributed tracing appeared first on The New Stack.

Speed has outpaced validation. With 62% of LLM-generated code testing as insecure and AI agents using undocumented APIs, legacy tools fall short. Learn how Snyk’s AI-powered dynamic testing secures your expanding attack surface.

At Chainguard Assemble 2026, Outsystems shared how it transformed its release process through platform engineering.

Snyk is opening a new innovation hub in downtown San Francisco, creating a strategic center of gravity for AI security. This new community space invites all Bay Area builders to join weekly hackathons and technical sessions to help shape the future of secure AI innovation.

KubeVirt is an open-source project that brings virtual machines into the Kubernetes control plane, letting teams run VMs and containers The post What is KubeVirt and why it’s growing appeared first on The New Stack.

Cursor built AI security agents that review 3,000+ PRs weekly and catch 200+ vulnerabilities. Here’s what they get right—and what’s missing for enterprise security.

Snyk and Tessl have partnered to bring security scanning to every skill in the Tessl Registry. Every public skill now carries a Snyk security score, bringing the same trust signals developers expect from package managers to the agent skills ecosystem.

Catch up on all the announcements Chainguard made at Assemble 2026, featuring AI agent skills, CI/CD workflows, and more.

Chainguard Actions is a securely rebuilt catalog of GitHub Actions and similar CI/CD workflows built and continuously maintained in the Chainguard Factory.

Chainguard Agent Skills is a continuously maintained catalog of hardened AI agent skills.

Chainguard Catalog Starter is a new free offering that gives developers instant access to trusted container images from the industry’s most comprehensive catalog

Chainguard Commercial Builds is a new partnership program with commercial and open source software providers to package software using the Chainguard Factory.

Chainguard OS Packages are enterprise-grade, zero-CVE packages and base images built and continuously maintained in the Chainguard Factory.

Chainguard Repository is a single, Chainguard-managed experience for pulling secure-by-default artifacts with built-in, configurable policy enforcement.

Guardener is an AI-native agent that accelerates engineering teams’ adoption of trusted open source artifacts across software development and deployment.

Agentic AI development company Tetrate has launched Built on Envoy, a free and open source extensions marketplace for Envoy. Envoy The post Tetrate launches open source marketplace to simplify Envoy adoption appeared first on The New Stack.

Chainguard is the first and only to FIPS-validate OpenSSL 3.4, owning the validated cryptographic module that powers our FIPS images.

Chainguard delivers the FIPS-validated Apache Kafka images, enabling secure event streaming for FedRAMP and regulated environments.

AI coding assistants are resurrecting millions of abandoned open source packages. Learn how LLMs expose the “Dormant Majority” and why package health intelligence is critical for supply chain security.

The Chrome Secure Web and Networking Team has announced a new program aimed at developing quantum-resistant HTTPS certificates, specifically using Merkle Tree Certificates (MTCs). This initiative follows the formation of the IETF working group PLANTS to address the challenges of quantum-resistant cryptography in TLS connections. MTCs promise to enhance performance by minimizing the size of authentication data while maintaining transparency and security. Chrome is currently conducting feasibility studies with Cloudflare and plans a phased rollout over the next few years, ultimately establishing a new Chrome Quantum-resistant Root Store (CQRS). This effort aims to secure the web against future quantum threats while supporting existing CA partnerships and traditional certificates in private contexts.

Backporting Python CVE fixes is complex and risky. Chainguard Libraries delivers source-built, tested, and verified patched packages you can trust.

Anthropic has introduced Claude Code Security, leveraging its advanced model, Claude Opus 4.6. The tool identified over 500 high-severity security vulnerabilities in production open-source codebases, many of which had evaded detection for years despite expert reviews and automated scans. This revelation had a negative impact on the cybersecurity market, leading to a decline of approximately $15 billion in valuations.

Google has enhanced Android’s scam defenses using AI to protect users from over 10 billion suspected fraudulent calls and messages monthly. An illustrative case involves Majik B., who received a suspicious call but was saved by a Scam Detection alert on his Pixel phone. This technology is expanding to Samsung Galaxy S26 devices in the U.S. and will also enhance Google Messages’ scam detection abilities in over 20 countries, ensuring users can communicate securely while maintaining privacy.

Are all zero-CVE images truly secure? A deep dive into Debian no-DSA, VEX suppression, and why transparency matters in container supply chain security.

Snyk and uv have teamed up to provide high-performance package management with native security for Python-based AI development. Build, install, and secure your AI-native applications from inception with Snyk’s native support for the uv ecosystem.

As autonomous AI systems transform business, a new profession is emerging to protect them: the AI Security Engineer. Discover why this specialized discipline is becoming a survival imperative for organizations in an AI-native world.

Anthropic’s Claude Code Security marks a major shift in vulnerability discovery, but AI-driven development requires more than just reasoning to remain secure. Learn how Snyk’s AI Security Fabric integrates with Claude to close the loop between finding vulnerabilities and fixing them at scale.

Explore official write-ups and community highlights from the Fetch the Flag CTF 2026, featuring over 20 challenges in web security, AI, and crypto. Learn from the experts and dive into the technical details of this year’s most intricate binary puzzles and web exploits.

Discover how Chainguard and Second Front are partnering to help build a secure path into government markets for your organization.

Vijaya Kaza, VP and GM of App & Ecosystem Trust, emphasizes the importance of trust in the Android ecosystem, which safeguards users against malware, fraud, and privacy violations. In 2025, Google Play’s AI-driven protections successfully blocked over 1.75 million harmful apps and improved user safety measures, including enhanced app detection and spam rating protection. The ongoing commitment to partner with developers and utilize AI aims to maintain a secure environment while shielding users from evolving threats, ultimately fostering a trustworthy app ecosystem.

The Clinejection vulnerability chain marks a troubling development in supply chain attacks, using AI agents as vectors for exploitation. By merging indirect prompt injection with cache poisoning in GitHub Actions, attackers were able to deploy unauthorized code to numerous developers. This incident underscores the urgent necessity for strengthened CI/CD pipelines and enhanced security measures for AI-based coding tools to prevent similar breaches.

Snyk and Cline have partnered to integrate enterprise-grade security directly into autonomous coding loops. By bridging the trust gap, Snyk and Cline enable teams to innovate faster while maintaining rigid security and compliance standards.

Explore the latest Forrester Consulting Total Economic Impact™ (TEI) study, commissioned by Chainguard.

Snyk has partnered with Vercel to secure the skills.sh ecosystem, integrating real-time security scanning to detect malicious payloads and prompt injections before they reach your machine. Discover how this partnership is locking down the future of agentic AI.

Snyk Studio is redefining AI development security with new integrations for Gemini CLI and Claude Code, enabling developers to build fast without sacrificing safety. Bridge the gap between developer velocity and governance to ensure your code is secure at inception.

Chainguard’s expanded Helm charts deliver signed, tested, secure-by-default deployments that eliminate YAML toil and simplify Kubernetes at scale.

The Chainguard Factory and DriftlessAF automate CVE detection and patching, delivering fixes in hours and maintaining industry-leading remediation SLAs.

Cyber Security is cyclical. For years now cloud security has been focused on visibility: perform the scans, collect the data, generate the alerts, centralize the dashboards. That made sense when cloud native was new and teams were still figuring out how to operate in containers, Kubernetes, and ephemeral infrastructure. But the environment has changed. Cloud

AppSec is often stalled by a lack of trust: will this fix break my app? Snyk’s new Breakability Risk feature solves this by identifying which security updates are safe to merge and which require caution. By focusing on low-risk fixes first, developers can clear backlogs four times faster and reduce security debt without increasing their workload.

While AI accelerates software delivery, it also scales security risks by turning minor errors into systemic vulnerabilities. Learn how to transform AI from a potential liability into a secure engine for growth through robust governance and control.

AI agents introduce new security risks like prompt injection and data exfiltration. Learn how guardrails, hook-based controls, and Arcade’s Contextual Access secure AI agent tool calls in real time.

Linky’s Matchmaker converts your Dockerfile to Chainguard Containers, recommending secure, minimal base images and generating an updated file in minutes

Fulfillment Dashboard gives Chainguard customers real-time visibility, tracking, and community voting for new secure container image requests.

Are “Skill Scanners” on ClawHub actually safe? We tested popular community tools like Skill Defender and SkillGuard against real malware. The results were alarming.

The latest tag isn’t unsafe by default — pin images to digests for reproducible, secure updates while staying current with automated workflows.

Breaking: Snyk researchers uncover a malicious “Google” skill on ClawHub that tricks users into installing malware via a fake OpenClaw dependency. Learn how the attack works and how to protect your AI agents.

Discover how 7.1% of AI agent skills are designed to leak secrets, PII, and API keys through LLM context. Learn to defend with Evo & mcp-scan.

Snyk’s ToxicSkills research reveals 36% of AI agent skills contain security flaws, including 1,467 vulnerable skills and active malicious payloads targeting OpenClaw, Claude Code, and Cursor users.

Chainguard can help your engineering team accelerate sales velocity by reducing security friction and enabling engineering to be a growth accelerator.

Snyk introduces the AI Security Fabric and a prescriptive path to help organizations secure software at the speed of AI. Discover how to operationalize AI security and scale innovation without compromising on safety.

Learn how to move from vision to practice with the Prescriptive Path, a framework for operationalizing AI security at scale. By replacing fragmented tools with a unified platform, you can build trust and secure AI-native applications at machine speed.

npm’s token changes help, but MFA phishing and optional bypass tokens still enable supply-chain attacks. Source-built Chainguard Libraries reduce the risk.

Snyk Advisor is moving! Package intelligence, including Popularity, Maintenance, Security, and Community metrics, is now unified with vulnerability data on security.snyk.io for a better developer and AppSec experience.

Chainguard secures AI adoption with minimal, zero-CVE containers and source-built libraries that prevent supply chain malware while keeping developers fast.

Chainguard Factory 2.0, powered by DriftlessAF, brings AI-driven, self-healing reconciliation to build and maintain 2,000+ zero-CVE images — now open sourced.

Chainguard Containers ship richer SBOMs with binary-level library details plus new CycloneDX support, making CVE impact and compliance tracing fast and clear.


The Android Security Team, led by Nataliya Stanetsky and colleagues, announced new theft protection features for Android devices, enhancing security against phone theft and financial fraud. Updates include stronger authentication safeguards, user control over failed authentication locks, expanded identity checks for apps using biometric prompts, and heightened defenses against screen lock guessing. Additionally, recovery tools have improved, allowing more control over remote locking. In Brazil, certain theft protection features are enabled by default on new devices. These efforts aim to provide comprehensive protection for Android users.

Capture The Flag (CTF) competitions are a powerful way to accelerate your cybersecurity career by exposing you to real-world vulnerabilities and diverse technical niches. Discover why CTFs are one of the best methods to grow your expertise and professional network.

ML pipelines in 2026 still lack secure-by-default tooling. Learn the key security gaps in ML Ops and how teams can reduce risk today.

Chainguard and JFrog secure the software supply chain with secure-by-default container images, policy-based curation, and continuous compliance.

The Chainguard OS Fully User Directed Committee is a customer-led steering committee for Chainguard OS. Learn how you can be a member.

Learn how Chainguard tackled dependency resolution, toolchain challenges, and manylinux compatibility to deliver hardened PyTorch wheels.

Chainguard’s “How We Lead” program builds strong, intentional managers through shared principles, practical practice, and early investment to drive growth.

Our latest report highlights the urgent need for machine-speed defense as AI shifts from a tool to an autonomous actor in the face of automated cyberattacks. Learn the key strategies for leaders to bridge the visibility gap and implement technical governance in the age of AI agents.

Learn how Chainguard helps DevOps teams meet SOC 2 requirements with secure-by-default containers, automated SBOMs, and continuous, audit-ready evidence.

Gastown hints at the future of software: agent-driven workflows where CI, guardrails, and shared truth matter more than writing code faster.

Learn how Chainguard helps financial institutions meet NYDFS 500 with zero-CVE open source, signed SBOMs, auditable evidence, and vulnerability remediation.

Discover how you can run Renovate as a GitHub Action without needing a GitHub Personal Access Token by using Octo STS.

We added 10 open source projects to EmeritOSS—including MinIO, Prometheus exporters, and PgCat—to provide long-term, stability-focused maintenance and security.

New integrated authentication for Python Libraries with a keyring: use short-lived credentials for pip installs to stay secure without slowing developers down.

Chainguard CEO Dan Lorenc explains why real security comes from trusted, from-source software supply chains, not post-hoc hardening or zero-CVE promises.

The critical ServiceNow Virtual Agent vulnerability highlights a vital lesson: securing agentic AI requires a return to traditional AppSec foundations. While AI can amplify risks, the root causes often stem from classic failures in authentication and authorization.

Get ready for the EU Cyber Resilience Act. See how Chainguard helps teams meet CRA security-by-design requirements with zero-CVE container images and libraries.

The Shai-Hulud npm incident exposed the limitations of reactive security in modern software supply chains. To survive the next major attack, organizations must shift toward a multi-layered strategy of proactive prevention, real-time intelligence, and automated action.

Snyk and Augment Code have partnered to deliver real-time security scanning and autonomous remediation directly within AI-powered development workflows, allowing teams to maintain peak velocity while ensuring every line of code is secure by default and compliant with organizational policies.

Learn how Chainguard helps organizations in Australia and New Zealand apply the Essential Eight to cloud-native, containerized environments.

We updated our FIPS container images with OpenSSL 3.1.2 (CMVP #5102), clearer CMVP visibility in SBOMs, and a roadmap for upcoming FIPS 140-3 cryptography.

A refined variant of the Shai-Hulud malware, dubbed The Golden Path, has been discovered targeting the npm ecosystem during the holiday season. Security teams are encouraged to prioritize structural hardening, such as disabling lifecycle scripts, to mitigate risks during this testing phase.

Chainguard’s Vibelympics competition brought out the best and most creative ideas in vibe coding and AI-assisted software development.

Chainguard delivers Ruby 4.0 container images: secure, zero-CVE, FIPS-ready, and available free so developers can adopt the latest Ruby safely and fast.

Chainguard is keeping ingress-nginx alive through EmeritOSS, providing security-focused maintenance so teams can migrate safely without risk.

Enterprises face a critical visibility gap in AI models, creating security and compliance risks. Evo’s new integration with CycloneDX 1.6 delivers intelligent, actionable AI-BOMs, providing complete oversight and robust governance for your entire AI supply chain.

Custom Certificate support for Custom Assembly allows you to add your enterprise certificate authority certificates directly to Chainguard Containers

Chainguard’s State of Trusted Open Source for December 2025 dives into usage trends for Chainguard Containers, CVE data, and why remediation speed matters.

The rise of GenAI brings complex, non-deterministic security risks that traditional methods can’t handle. Discover Evo by Snyk, the world’s first agentic security orchestration system for AI-native defense.

EmeritOSS is a stability-focused program that preserves and secures mature, unmaintained open source projects, starting with Kaniko, Kubeapps, and ingress-nginx.

Startups can’t afford to trade speed for security. Learn how Chainguard gives startups secure-by-default foundations from day one.



Skip the “security gift traps.” This holiday guide flags common open source supply chain gotchas and shows what to choose instead for speed and trust.

Google’s Android Red Team, in collaboration with Arm, conducted a security analysis of the Mali GPU, crucial for billions of Android devices. They identified vulnerabilities primarily in how User-Mode Driver and Kernel-Mode Driver interact, leading to potential exploits. The analysis focused on reducing the attack surface by restricting access to certain GPU IOCTLs through a staged SELinux policy rollout. This effort aims to enhance GPU security, ensuring resilience against threats while providing guidelines for device-specific implementations. The initiative highlights the importance of proactive security measures in safeguarding against existing and future vulnerabilities in Android systems.

Snyk helps Federal Agencies secure software for the White House’s Genesis Mission, accelerating AI-driven science. Implement Secure by Design for the supply chain, cloud, and pipelines.

Chainguard now offers hardened, zero-CVE MCP container images, starting with mcp-grafana, with more on the way.

Explore all the latest features and releases for Chainguard Containers and Chainguard Libraries.

See how we give engineers protected space for self-directed, high-impact work; boosting innovation and improving engineering morale.



Learn how we keep Chainguard OS and Wolfi lean and secure with automated package garbage collection that cuts attack surface while preserving reproducibility.

Customers can now leverage Anchore Enterprise’s scanning capabilities for Chainguard Libraries for Python.

Google’s Android team is enhancing mobile security to combat scams using AI and advanced security measures. A recent survey indicates that Android users are less likely to receive scam texts compared to iOS users. To address evolving scams, particularly those involving screen sharing, Android has launched in-call scam protections. This feature warns users during calls with unrecognized numbers when using financial apps, leading to successful interventions in the UK pilot. Now expanding into the US and other countries, this initiative aims to safeguard users from potential financial losses.

Snyk joins the AWS Pattern Partners program, bringing its proven success with AI/ML and Generative AI. Discover how Snyk Studio accelerates innovation on AWS, embeds security at inception, and delivers measurable outcomes for enterprises modernizing critical processes and adopting AI safely.

Supercharge your AI agent! Learn how AutoMCP integrates Model Context Protocol (MCP) servers and Snyk Studio for secure, context-aware AI-driven development.

Critical RCE vulnerabilities (CVE-2025-55182/CVE-2025-66478) were found in React Server Components and Next.js via unsafe deserialization. Immediate upgrade to patched versions is mandatory to prevent unauthenticated remote code execution. Learn how to detect and mitigate the critical flaw.

Learn more about Chainguard’s Engineering Principles: reduce complexity, empower individuals, engineer value, and ensure production excellence.

Snyk Studio for Kiro ensures rapid, secure AI innovation. Stop security backlogs and prevent new risks at inception to ship with confidence, even with AI coding assistants.

Introducing Log Sniffer: an innovative open source solution powered by Google Gemini AI that transforms Snyk audit logs into instant, actionable security and engineering intelligence.

Snyk identified a new supply chain attack in the npm ecosystem, referred to as SHA1-Hulud. We believe this is a second wave of the Shai-Hulud attack. Learn what this attack is and how Snyk is responding.

OpenAI’s Aardvark signals the rise of agentic AppSec, and Snyk shows how policy, governance, and real-time intelligence keep enterprises secure.

Chainguard Libraries now integrates with AWS Inspector, bringing proactive malware prevention, CVE remediation, and vulnerability visibility across AWS workloads

Discover how the Snyk and Qodo partnership closes the AI security gap. Snyk Studio for Qodo embeds security into AI development to secure code from the start and clear security debt.

Dave Kleidermacher from Google highlights the introduction of Quick Share interoperability with AirDrop, enabling seamless file sharing between Android and iOS devices, particularly with the Pixel 10 Family. This feature prioritizes security, implementing a multi-layered protection approach and using the Rust programming language to eliminate memory vulnerabilities. The current implementation allows sharing with AirDrop’s “Everyone for 10 minutes” mode, bypassing server routing. The security features have been validated by independent experts, ensuring a robust, secure cross-platform sharing experience, with intentions to improve and collaborate further with Apple.

AI-native applications demand a security approach as dynamic as they are. Traditional threat modeling is no longer enough. Discover the shift to continuous, adaptive threat modeling for AI security.

Chainguard VM images are FIPS 140-3 validated, STIG-hardened, and CIS-compliant, giving regulated industries instant, secure, and audit-ready infrastructure.

We are incredibly proud and excited to announce that Snyk Learn has been recognized as a Silver Winner in the Responsible Technology: Education or Literacy Platform category at the 5th annual Anthem Awards!

Explore how Model Context Protocol (MCP) servers and integrated security scanning workflows are redefining guardrails for low-code/no-code (LCNC) and AI-driven development environments.

Snyk is excited to announce a new partnership with Continue, which will embed AI-powered security into every step of the SDLC. This partnership allows developers to scan code, dependencies, and IaC using natural language commands and get context-aware fix suggestions instantly, whether leveraging Agents in Continue Mission Control, an IDE extension, or a CLI.

Chainguard helps teams build developer-centric golden image programs with zero-CVE, purpose-built containers—balancing speed, security, and standardization.

In November 2025, a large-scale surge of package publications on the NPM registry with similar structures and naming patterns was discovered. Understand the details of the incident.

Chainguard SVP of Engineering Dustin Kirkland discusses why Chainguard builds every package, library, and image directly from source and why the approach works.

Organizations achieve 288% ROI with the Snyk AI Trust Platform, according to a new Forrester TEI study. Improve developer productivity, enhance security, and consolidate AppSec tools with Snyk.

We’ve improved the Chainguard Images Directory with Helm charts for faster deployments, an ROI calculator, and more refreshed data to improve your experience.

Explore how Snyk’s Evo Threat Modeling Agent automates and contextualizes security for AI-native applications, addressing prompt injection, data exfiltration, data poisoning, and agentic vulnerabilities.

Discover how AI and human security engineers collaborate to defend against evolving threats at machine speed. Learn about the new mindset for adaptive, intelligent, and symbiotic defense in the age of Agentic AI.

Chainguard helps Platform teams drive adoption with zero-CVE, customizable container images that make internal development platforms secure, fast, and trusted.

Snyk is thrilled to announce our partnership with Factory, which brings Snyk Studio directly into Droid workflows.

Chainguard launches the Self-Serve Experience for Catalog customers: instantly add, rename, or remove container images from our catalog, no tickets required.

Snyk Container rethinks security, moving beyond scans to deliver a comprehensive, end-to-end solution. It connects the entire lifecycle, from IDE to production, with continuous monitoring and AI-powered remediation.

Snyk Studio now offers secure AI development at scale for all customers, with streamlined setup via VS Code extension and enterprise rollout capabilities.

Chainguard joins IBM’s PDE Factory to deliver secure, zero-CVE containers for government agencies, accelerating compliance, modernization, and innovation.

As Cybersecurity Awareness Month concludes, Google highlights the battle against mobile scams, which have led to over $400 billion in global losses due to advanced AI techniques by fraudsters. Android employs multi-layered protections that block over 10 billion suspicious communications monthly. A recent Google survey revealed that Android users report fewer scam texts than iOS users. Independent evaluations confirm Android’s superior AI-driven safeguards against scams, emphasizing its extensive protection features compared to iOS.

Customize Chainguard Containers with the latest Custom Assembly update. You can create, edit, and manage secure, zero-CVE image variants directly in the console.

In October 2026, with the release of Chrome 154, Google will enable the “Always Use Secure Connections” setting by default. This change will require user permission before connecting to any public site that does not use HTTPS, enhancing web security. The setting aims to reduce risks from insecure HTTP connections, which can lead to navigation hijacking and malware exposure. Previous data revealed widespread HTTPS adoption, yet a small percentage of HTTP navigations persist, warranting this protective measure. Additionally, Chrome will release variants that address the unique challenges of private sites and encourage broader HTTPS usage, all while minimizing user disruption. IT professionals are encouraged to prepare for this transition.

Catch up on what Chainguard is doing with higher education institutions to advance open source security and build the next generation of innovation.

MinIO pulled its free images—but Chainguard has you covered. Get zero-CVE, continuously built MinIO and MinIO Client containers, free and secure from Chainguard.

FedRAMP 20x is transforming cloud compliance with automation and continuous security. Learn how Chainguard Containers simplify 20x readiness with 0-CVE images.

AI is changing development. Our DevSecCon 2025 recap covers the 3 critical stages: AI-Accelerated DevSecOps, securing code at the first prompt, and taming AI-native app chaos with Evo by Snyk.

Introducing Evo by Snyk, the world’s first Agentic Security Orchestrator. Learn why Evo is changing the game in cybersecurity to make security seamless, invisible, intelligent, and unstoppable—so innovation never has to slow down again.

Chainguard Libraries for Python, trusted open source language libraries designed for CVE remediation and malware protection, is now generally available.

Build secure software faster with Chainguard. Learn how secure-by-default SDLC practices eliminate CVEs, automate compliance, and embed trust from code to cloud.

Learn how Mercato Solutions, a fast-growing low-code application provider, achieved near-zero security incidents and maintained development flexibility by partnering with Snyk API & Web.

Enhance AI-native development security with Snyk & Cognition. Discover Snyk for Devin & Windsurf, embedding real-time security intelligence for faster, safer coding.

Chainguard and Booz Allen partner to help federal programs eliminate vulnerabilities, save engineering time, and accelerate compliance timelines.

AI is transforming development and security. Join dev & security leaders at DevSecCon 2025 on Oct 22 to get a blueprint for secure innovation. Learn to manage AI code risks, empower developers, and elevate your AppSec strategy.

Snyk is recognized as a Leader in the 2025 Gartner® Magic Quadrant™ for Application Security Testing (AST), validating our developer-first approach and comprehensive platform for securing the modern SDLC.

Turn compliance into a growth driver with Chainguard. Eliminate CVEs, stay audit-ready, and meet FedRAMP, SOC 2, and ISO 27001 with secure images.

A new phishing campaign weaponizes NPM and the unpkg CDN. Over 175 throwaway packages are used to host scripts that redirect users to credential-harvesting sites. The attack targets enterprise employees through the browser, not developers at install time.

Chainguard surveyed 1,200 engineers and technology leaders to better understand the state of the developer experience today and where teams can improve.

Chainguard’s zero-CVE containers come with broad compatibility, custom assembly, verifiable provenance and SBOMs, and more to help you ship secure software.

Chainguard has created the first-ever CVE-free, vulnerability-free Raspberry Pi image. Learn more about how it works and what makes this special.

In a recent analysis, Chainguard Libraries for JavaScript prevented over 99% of malicious npm packages published to the npm registry.

Chainguard SVP of Product Patrick Donahue shares why he is excited to join Chainguard and how he plans to help build products developers love.

Master CTFs from beginner to elite hacker in 6 months with this ultimate guide! Discover top competitions, understand difficulty classifications, and strategize your path to success from October 2025 to April 2026.

Chainguard implements Zero Trust principles into everything we do to protect critical infrastructure in the age of open source. See how we do it.

Urgent security alert: On September 25, 2025, the npm package ‘postmark-mcp’ was compromised, secretly exfiltrating email contents. Learn about the incident timeline, impact, and immediate mitigation steps, including uninstalling, rotating credentials, and scanning with Snyk’s MCP-Scan.

Chainguard Libraries for JavaScript is designed to protect developers and organizations from compromised packages, malicious updates, and registry-based attacks.

Elie Bursztein and Marianna Tishchenko from Google’s Privacy, Safety and Security Team emphasize the importance of using AI to strengthen cybersecurity. At DEF CON 33, they hosted the GenSec Capture the Flag (CTF) event in partnership with Airbus, focusing on human-AI collaboration. Nearly 500 participants engaged, with many using AI tools for the first time. Positive feedback highlighted the effectiveness of AI in cybersecurity workflows. Sec-Gemini, Google’s Cybersecurity AI, received commendations for its utility. The event’s success and community input will guide future improvements.

Discover how Snyk Learn helps organizations meet PCI DSS v4.0 developer training requirements by providing relevant, just-in-time, interactive, and trackable security education for developers.

Discover more about Chainguard’s new integration with Anchore Enterprise.

We’re thrilled to share that Snyk has, for the sixth time and fifth consecutive year, been named to the Forbes Cloud 100 ranked at #51, recognizing the world’s most innovative private cloud companies.

Learn how to evaluate and select the right Linux distribution to satisfy your team’s needs, simplify migration, and avoid vendor lock-in.

Gain visibility and control over your AI-driven development. Snyk’s new features help AppSec teams govern security, prioritize risks in AI-generated code, and scale your security program effectively.

Discover how Labelbox transformed security backlog management from two years to two weeks with Snyk’s AI-accelerated remediation.

Explore how aligning development and security teams can transform project efficiency and security protocols.

Rowhammer is a hardware vulnerability in DRAM that allows attackers to cause data corruption by repeatedly accessing memory rows. This can lead to unauthorized data access, privilege escalation, or denial of service. While vendors have implemented mitigations like Target Row Refresh (TRR) for DDR5, recent findings reveal these defenses can be bypassed by sophisticated attacks. Google’s collaboration with researchers has resulted in new testing platforms and insights into effective countermeasures, highlighting the need for ongoing improvements to DRAM security, including potential future standards like PRAC.

A supply chain attack hit the ngx-bootstrap npm package, embedding malware to steal developer credentials. See affected versions (e.g., 20.0.4-6, 19.0.3) and our playbook to contain the threat and rotate compromised secrets.

Learn how CTOs can tie technology investments to increasing revenue, speeding innovation, and reducing risk and cost to drive positive business outcomes.

Chainguard has been recognized by the Forbes Cloud 100, Fortune Best Workplaces in Technology, and received a Great Place to Work certification.

At the Made by Google 2025 event, it was announced that the Pixel 10 lineup will feature C2PA Content Credentials in both the camera and Google Photos. This integrated system enhances digital media transparency by providing verifiable information about the provenance of images. The Pixel Camera has achieved Assurance Level 2, utilizing advanced security features, including the Tensor G5 chip and Titan M2 Security. These innovations enable on-device time-stamping and a privacy-focused approach to certificate management, ensuring user anonymity. In essence, the new Content Credentials promise to combat misinformation by allowing users to trust the source and history of digital media, presenting a step forward in the use of AI and media integrity. Google aims to collaborate with developers to foster a more trustworthy ecosystem around digital content.

Chainguard Libraries provides a different and proven defense against supply chain attacks like the recent npm breach. See why preventing malware is important.

Chainguard has created a Slack community to foster a direct connection with the team, engage with your peers, and get the latest updates on Chainguard news.

We’re excited to announce that Snyk has been recognized as a Leader in the Forrester Wave™: Static Application Security Testing (SAST) Solutions, Q3 2025.

Our Chainguard Containers catalog now has more than 1,700 minimal, zero-CVE images, rebuilt from source every day – industry-leading in both breadth and depth.

On Monday, September 8th, a highly regarded open source developer, ~qix, was compromised via a phishing email.

Discover key insights from DevSecCon speaker Brett Smith on securing AI in your pipelines. Register for DevSecCon 2025 to enhance your AI security knowledge.

Chainguard VMs is expanding with new Application and Base VM Images — giving teams a secure, zero-CVE foundation to build and innovate faster.

Chainguard’s Value Calculator is a new tool we created to make it easy to quantify the value of using Chainguard Containers for your specific organization.

On August 26–27, 2025 (UTC), eight malicious Nx and Nx Powerpack releases were pushed to npm across two version lines and were live for ~5 hours 20 minutes before removal.

Gaurav Saxena, a Director of Engineering at an automotive company, talks through how internal developer platforms are an important part of resiliency by design.

Discover Snyk’s new default view, grouping vulnerabilities by library and fix versions to help you prioritize and remediate open source vulnerabilities more efficiently.

Chainguard uses compiler flags to be proactive in the security of our products. See how our compiler flag usage helped us catch a complex bug in glibc.

Chainguard released over 400 new container images from April-July 2025 with zero CVEs. Many of these images are also FIPS-enabled.

See what Chainguard was up to at Black Hat USA 2025, from a garden-themed booth to several engaging activations with organizations like Vanta and Orca Security.

We are witnessing a shift from reactive to proactive application security, with AI agents operating in autonomy. What are the benefits, risks & best practices of AI agents implementation in AppSec?

Kernel-Independent FIPS is now available across the full catalog of Chainguard FIPS images for Java, simplifying and accelerating compliance for FedRAMP ATO.

Learn how Snyk’s MCP server brings agentic security to container workflows. Automate vulnerability scanning and base image recommendations directly within your AI-powered IDE.

The Chainguard Partner Program is a global initiative to empower our channel partners to deliver trusted open source software to customers around the world.

Google announced that its protected KVM (pKVM), the hypervisor for the Android Virtualization Framework, has achieved SESIP Level 5 certification, the first of its kind for consumer electronics. This milestone enhances the security of mobile technology, enabling the support of high-criticality workloads like on-device AI while ensuring privacy and integrity. Certified by Dekra, pKVM addresses vulnerabilities with high resistance to sophisticated attackers. It will form a foundation for a standardized, secure environment for Android device manufacturers, reflecting a collaborative effort from various engineering teams.

Chainguard and GitLab recently recorded a webinar discussing challenges organizations face in building a secure software supply chain. Get the key takeaways.

Learn how Snyk for Government helps federal agencies meet AI mandates with confidence. Snyk’s AI Trust Platform ensures secure-by-design development, compliance, and transparent AI systems.

Insights from Snyk’s Silicon Valley Lighthouse event on building secure, trustworthy AI. Learn how to secure agentic apps, embrace a “secure by everyone” culture, and use guardrails for AI innovation.

Snyk and Akamai partner to streamline API security. This integration automates API discovery and schema ingestion from Akamai to power Snyk’s DAST engine, boosting scan coverage and efficiency.

Snyk’s CISO explains why we’ve joined CISA’s Secure by Design pledge. Learn about the 7 key goals for a safer digital world, including MFA, no default passwords, and vulnerability reduction.

Explore strategies to reduce false positives and enhance healthtech security with Snyk’s AI-powered platform. Increase efficiency and protect sensitive data effectively.

Snyk unveils innovations at Black Hat to secure AI development. Features include MCP Server for agentic workflows, AI-BOM for visibility, and Toxic Flow Analysis for novel AI threats.

Discover how a now-removed feature allowed private ChatGPT conversations to be indexed by search engines. Learn the privacy risks and how to protect your data from unintentional exposure.

The recent compromise of the num2words package never made it into Chainguard Libraries for Python. Get the breakdown from the team on our packages you can trust.

Chainguard goes through all the necessary steps to make things SLSA 3 compliant. Get the details on how we do it.

Scanfrog is a Frogger-style game created by one of Chainguard’s engineers to showcase how difficult it can be to dodge vulnerabilities in containers.

Overwhelmed by AI in dev workflows? The Snyk AI Trust Platform helps teams move fast, stay secure, and build with confidence, without AI expertise.

Chainguard Academy has implemented several new features to make training LLMs and AI models on Chainguard documentation easier. Learn more today.

Discover how to use Chainguard’s new Dockerfile Converter tool to close the gap between legacy Dockerfiles and secure containers in our new course.

Collaboraton.AI used a combination of Chainguard Containers, Second Front, and AWS to reduce vulnerabilities by 97% and lower compliance costs by $2 million.

Urgent warning: Maintainers of popular npm packages like ESLint Prettier Plugin were attacked via an npm supply chain malware incident. Learn about the typosquatting, phishing, and impacted packages, plus essential steps to protect your projects.

Google’s Open Source Security Team has launched OSS Rebuild, a project aimed at enhancing trust in open source package ecosystems by reproducing upstream artifacts. With the rise of supply chain attacks, OSS Rebuild allows security teams to reinforce package integrity without imposing on maintainers. The initiative automates build definitions for popular package registries and provides tools for verification and observability. It enhances transparency in the software supply chain and helps detect compromises, while engaging the community in bolstering open source security.

Learn about the recent $500K crypto heist caused by a malicious “Solidity Language” extension in Cursor IDE. Understand how compromised IDE extensions and third-party registries pose significant supply chain risks for developers and the broader AI ecosystem.

Learn how to navigate enterprise AI implementation with a focus on trust, security, and value. Discover key considerations, high-impact use cases like RAG and content generation, and best practices for building a secure AI foundation.

Chainguard Containers with Azure Functions offers the convenience of serverless and the confidence of a trusted, traceable image built for security.

Chainguard is now listed on the Microsoft Azure Marketplace. In addition, Microsoft Defender for Cloud can now scan Chainguard container images.

Custom Assembly and Private APK Repositories, two new features for Chainguard Containers, are now generally available.

The priniciple of reconciliation is what makes systems self-healing, adaptable, and robust in the face of change and failure.

Chainguard’s catalog of 1,400+ trusted container images includes 400+ FIPS-validated variants.

Learn how Chainguard OS and the Chainguard Factory delivers the only scalable path to secure, reliable software artifacts.

Android’s Advanced Protection program enhances security for high-risk users like journalists and public figures by implementing robust device-level protections. It integrates with Chrome on Android by enabling features such as “Always Use Secure Connections,” ensuring secure HTTPS connections to avoid data breaches. It also supports full Site Isolation for devices with 4GB+ RAM, enhancing protection against cross-site threats. Additionally, Advanced Protection reduces Chrome’s attack surface by disabling specific JavaScript optimizations. The settings from Advanced Protection can be accessed by any Chrome user, promoting a higher security standard across all platforms. Users are encouraged to join the Advanced Protection Program, which requires stronger security measures, including multi-factor authentication.

Chainguard first-party Helm Charts are designed to work seamlessly with our continuously updated container images. Discover more about our Helm Charts.

Discover how enhanced security tools reduce false positives and streamline threat detection for more effective cybersecurity management.

Build developer trust in AI security tools with verified fixes, real-time scanning, and frictionless workflows powered by Snyk Agent Fix.

Chainguard Containers have extensive scanner integrations with many of the most popular container image scanners. Discover more about our integrations.

Chainguard is enabling customers with an easy way to access the full Chainguard Containers catalog with Catalog Pricing. Learn more about the new pricing option.

Learn how to meet CRA requirements with integrated security testing, secure-by-design workflows, and scalable practices for modern dev teams.

Chainguard Libraries for Java is Chainguard’s repository of malware-resistant Java dependencies. Learn how we are building and maintaining over 50,000 projects.

Discover why AI Trust is crucial for secure, scalable software development in the AI era. Learn how Snyk’s AI Security Platform helps you manage risk, enforce policies, and ensure continuous compliance.

Secure your AI-generated code from Cursor in real-time with Snyk’s CLI Model Context Protocol (MCP) server. Detect vulnerabilities and accelerate secure development without compromising agility.

Secure and accelerate your adoption of AI coding with pre-screened auto-fixes and autonomous code security for modern, developer-loved SAST.

Chainguard evaluated the amount of money customers are saving and unlocking by utilizing Chainguard Containers as their secure container image solution.

As AI-native apps and agentic workflows expand the attack surface, new threats like prompt injection and data poisoning emerge. Learn why traditional AppSec falls short and how to secure your AI systems in this new threat landscape.

Chainguard now has an integration with Orca Security. Discover more about our new partnership.

Snyk is delighted to announce a significant milestone for our customers and partners in the Asia-Pacific region: the launch of a dedicated Snyk API & Web infrastructure instance, which is now available and hosted locally within the region.

Discover how Chainguard can help Australian organisations comply with ISM, IRAP, and the Essential Eight to maintain an effective security posture.

The pace of technological change is always fast, but with AI everywhere, things have gone into overdrive. In Australia and New Zealand, businesses plan to spend heavily on generative AI—about $15 million on average, more than the global average. This puts immense pressure on technology, security, and engineering leaders.

With the rise of generative AI, new threats, such as indirect prompt injections, are emerging. These attacks use external data sources to covertly manipulate AI systems. Google’s GenAI Security Team is addressing this risk with a comprehensive security strategy for its Gemini tool, which includes techniques like content classifiers, security thought reinforcement, and a user confirmation framework. These measures enhance defense against prompt injections and offer robust protection by requiring user interactions for certain actions while notifying them of potential threats. The ongoing collaboration with security researchers and rigorous testing further strengthens Gemini’s defenses against these evolving threats.

We’re excited to announce a strategic partnership with Azul that brings its curated OpenJDK® distributions to the Chainguard Catalog.

The Consortium for Information and Software Quality estimated that the cost of poor software quality in the United States reached $2.41 trillion in 2022. As we will show, it makes sense that the cost of poor software quality is so high. It’s also completely avoidable, and software flaws must be avoided with the world’s increased dependency on software.

Unlock AI coding benefits without risk! Learn how to implement smart security guardrails—PR checks, IDE scans, and adoption tactics—to secure AI-generated code.

Transform your AppSec program with Snyk Analytics. Gain centralized visibility, developer insights, and custom reports to improve productivity, streamline compliance, and build AI trust.

Chainguard’s Trusted Container Images and Open Source Artifacts Buyer’s Guide helps you improve supply chain security and reduce costly engineering toil.

Chainguard recently found that 98% of malicious Python libraries from the Backstabber’s Knife Collection could be avoided by using Chainguard Libraries.

Chainguard signed CISA’s Secure by Design pledge in 2024. One year later, we look at progress we’ve made in key areas like CVE remediation and disclosures.

Chainguard Containers support compliance with the United Kingdom’s Software Security Code of Practice. Check out what the framework entails and how we help.

Chainguard FIPS images have been upgraded to start using the OpenSSL project 3.1.2 module with FIPS 140-3 validation. Learn more about what this means.

Snyk for Government is our FedRAMP Moderate authorized solution for the public sector. This authorization underscores our unwavering commitment to providing secure development solutions that meet the rigorous standards of the Federal Risk and Authorization Management Program (FedRAMP).

Discover how developers can thrive in an AI-powered future by embracing new tools, building skills, and securing evolving workflows with help from Snyk.

Chainguard is taking over the maintenance of the Kaniko project, recently deprecated by Google. Learn more about why we’re doing it and what is next.

Discover essential steps for creating HIPAA-compliant APIs and web applications, ensuring patient data safety in the evolving healthcare sector.

The Future of Developer Upskilling Is Human-Led, AI-Supported | Snyk Assist for Developers.

With CMMC 2.0 compliance becoming an important prerequisite to research funding for R1 universities, Chainguard Containers are the perfect solution. See how.

Chainguard Containers support Post-Quantum Cryptography (PQC). Learn more about what PQC is, and what Chainguard is doing to offer it today.

Discover how Snyk Agent Fix delivers trusted, real-time vulnerability remediation with validated AI fixes built for developers and trusted by security.

Chainguard customer Ask Sage utilizes Chainguard Containers to build ATO in a Box, a solution utilizing automation to speed up the authority to operate process.

AI is transforming software development. Is your security strategy keeping pace? Learn about AI TrustOps, a new model to build secure software in the age of AI and stay ahead of emerging risks.

Empower developers with Snyk Learn and the new Learning Management Add-on. Build AI-enabled apps securely, reduce risk, and meet compliance with bite-sized lessons and AI-powered assistance.

Learn why AI-generated code, open source, and package hallucinations magnify risk. Discover the Snyk AI Trust Platform for safe, accelerated development.

EOL Grace Period, Private APK Repositories, and Custom Assembly features are now included for all Chainguard Containers customers.

Discover the Snyk AI Security Platform, purpose-built for safe AI innovation and building trust in AI-driven software. Learn how Snyk offers comprehensive visibility, intelligent prioritization, and scalable policy enforcement for AI.

Discover Snyk Labs, Snyk’s AI security resource hub for the latest technical demos, sharing emerging threats and standards, & early insights into the AI security landscape.

Multi-Layer Chainguard Containers with intelligent rebuilds are designed to increase bandwidth and storage efficiency and enable faster pull times.

The Chainguard Factory combines world-class talent and automation to produce packages and images at a level of speed unmatched by any other Linux distribution.

Discover the critical need for cybersecurity in space and how Snyk Learn bridges the security knowledge gap between academia and industry.

Snyk surveyed 101 US CISOs: 96% fear AI code vulnerabilities & 88% worry about US cyber readiness. Despite concerns, most CISOs remain confident in their org’s security.

Golden container image programs can be a great way to increase efficiency and security for your engineering team. Learn how to do it right with Chainguard.

One of the biggest challenges of embracing the development of Single-Page Applications (SPAs) is security testing. SPA security testing can’t just be about crawling the frontend URLs and using spiders like in traditional security testing. So, how can you make sure you’re properly testing your SPAs?

Chainguard developed Chainguard Libraries for Python to help guard the Python ecosystem against malware attacks. Discover why we did it and how it works.

Chainguard Libraries for Python is an index of Python dependencies designed to protect users from malware attacks at the build and distribution stages.

Explore Snyk’s highlights from RSAC 2025, focusing on generative AI, API security advancements, and community initiatives. Learn how Snyk is shaping the future of secure application development. Register for Snyk Launch 2025.

Chainguard Containers is a catalog of over 1,300 container images powered by Chainguard OS and the Chainguard Factory. Discover the safe source for open source.

Discover Snyk’s enhanced Partner Program for AI Security. Drive growth with optimized discounts, MDF, new GTM programs & dedicated support for mutual success.

Microservices can enable you to easily independently roll out services, but they can also provide security benefits. Learn more with Chainguard CTO Matt Moore.

Check out the new learning path that covers the OWASP Top 10 risks for open source software.

Explore the security risks of AI-generated code and how Snyk & ServiceNow offer AI-powered developer security integrated with enterprise workflows for effective remediation.

Dockerfile Converter is a new open source tool designed to reduce the manual toil engineers go through when migrating to Chainguard Containers.

Explore a personal journey through Black Hat Asia 2025 as a speaker, reviewer, and community connector. Discover insights on cloud security, women in cyber, AI, and building connections.

Chainguard is making changes to its Pytorch container images to make them more secure, easier to update, and simpler to use.

Chainguard has raised $356M of Series D funding at a $3.5B valuation. See how we are building the safe source for all open source.

Snyk launches Snyk API & Web, an AI-driven DAST engine that helps organizations automatically find and expose vulnerabilities at scale. Deeply integrated in Snyk’s Developer Security Platform, Snyk API & Web is the company’s answer to securing the complex, AI-powered applications developers are building today.

Chainguard will be at RSA 2025 at Booth #2441 on April 28-May 1, and will also be participating in ancillary events throughout the week.

Chainguard now offers FIPS-validated container images for Apache Spark and Spark Operator. See how we did it.

Snyk addresses the recent MITRE CVE funding news, detailing our independent vulnerability data capabilities & commitment to cybersecurity resilience.

Snyk joins forces with cybersecurity distributor Nova8 to accelerate developer security adoption in Latin America. See how the partnership helps reduce risk.

Secure AI coding with Snyk and Google Gemini. Learn how Snyk Code’s SAST integrates with Gemini Code Assist for seamless, secure development workflows.

Chainguard has announced Container Hardening Priorities (CHPs), a new framework to assess the security of container images. Learn how it works.

Chainguard was able to quickly respond to and handle the recent ingress-nginx-controller CVEs that were discovered by Wiz. See the actions we have taken.

FedRAMP 20x is a new initiative designed to automate and simplify the FedRAMP process. Get the rundown on what is changing, and how Chainguard can help.

Tired of boring scans? Meet Greybeard, Snyk’s humorous AI security CLI that gives unforgettable, brutally honest vulnerability feedback developers won’t forget. Greybeard is an April Fool’s tool that really works.

Here are five standout questions and answers from Snyk’s Fetch the Flag CTF event on February 27 and 28. Sit down with cybersecurity educator and developer influencer John Hammond—along with challenge designer Matt Kiely (aka huskyhacks), and developer advocates Micah Silverman, Sonya Moisset, Vandana Verma, and Elliot Ward—for a live Q&A session.

Chainguard will be at booth N300 at KubeCon EU 2025 in London to discuss Chainguard Libraries, Chainguard VMs, and Chainguard Containers.

Learn how governance in DevSecOps helps improve security outcomes by measuring risk, optimizing processes, and aligning security efforts with business goals.

Chainguard announced Chainguard Libraries, Chainguard VMs, and a new partnership with Datadog at Assemble, our inaugural event for security and developer pros.

Chainguard Libraries is a catalog of guarded Java dependencies built securely from source in Chainguard’s SLSA-certified infrastructure.

Chainguard VMs is a catalog of guarded, minimal, zero-CVE container host images that is now in Early Access.

Chainguard and Datadog announced a new partnership at Chainguard Assemble 2025. Learn more about what this partnership enables for customers.

On Friday morning, March 21, 2025, at 9:00 a.m. UTC, a security advisory identified as CVE-2025-29927 was published. It cited a critical 9.1 severity vulnerability for mainstream Next.js applications.

Join Snyk’s Field CTO, Steven Schmidt, and Mihai Saveschi, Senior Director of Security Service Management at CIBC, for an exclusive fireside chat on the evolving landscape of application security in financial services.

Chainguard OS is the next generation in open source software delivery. Learn all about the principles and technology that make it possible.

Chainguard’s defense-in-depth security strategy protected against multiple rsync CVEs before they were even reported. See how we did it, using compiler flags.

Discover practical steps to create a culture of secure coding, empowering developers to build resilient software and prevent costly vulnerabilities. Insights from Snyk.

Tired of endless security alerts? Snyk Delta Findings in the IDE helps developers cut through the noise and focus on new vulnerabilities introduced in their code. Reduce vulnerability fatigue and ship secure software faster. Get started for free!

The world is at an inflection point in open source software delivery. See where the software distribution status quo is at, and what is next.

A critical security exploit in the popular GitHub Action changed-files (tj-actions/changed-files) exposed encrypted secrets in plaintext within GitHub Action logs. This vulnerability, affecting over 23,000 repositories, was enabled by orphaned commits and manipulated release tags. Learn how to protect your GitHub workflows from similar exploits.

Chainguard’s defense in depth approach to security helped protect it from the recent tj-actions/changed-files GitHub repository compromise. Learn more about how.

Learn how to manage AI risks effectively with best practices, frameworks, and strategies to ensure secure AI adoption while mitigating vulnerabilities.

Discover best practices for responding to security alerts and remediating vulnerabilities early, reducing security toil, and improving DevSecOps efficiency.

Chainguard Assemble 2025 will take place in San Francisco on March 25. Take a deep dive into all the topics that sessions at the event will cover.

Learn how to optimize vulnerability management with ServiceNow Vulnerability Assignment rules and Snyk’s AppVR integration. Automate workflows, improve security visibility and reduce risks. Explore real-world examples and enhance your application security strategy.

Discover how Snyk helps secure the open source Golang project Bento by contributing vulnerability fixes and leveraging AI-powered tools. Learn about our efforts to enhance Bento’s security and support open source maintainers through the Snyk Secure Developer Program.

AI code generation accelerates development, enhances productivity, and reduces coding fatigue. However, it also introduces security risks and challenges. Learn how AI-powered coding works, its benefits and limitations, and how to secure AI-generated code using Snyk’s security tools.

Learn about the principles of DevSecOps automation, how to implement a DevSecOps automation strategy, & the best DevSecOps tools.

The traditional “distro” model of open source software delivery is ready for innovation. Learn how we got to this point and what comes next.

To enhance standardization and compatibility with modern Linux applications and other major distributions, Chainguard is adopting the usrmerge filesystem layout.

Snyk Learn, our developer security education platform, now includes lessons on API security! Check out the new learning path that covers the OWASP Top 10 for API security risks.

Chainguard Starter Images are zero CVE container images that are now available in the Iron Bank image repository.


Chainguard was able to create FIPS container images for Apache Cassandra 4.0, 4.1, and 5.0. See how we did it.

How to detect and prevent JWT security risks? Follow Snyk’s JWT security best practices for enhanced security.

We built a Minecraft Java server using a Chainguard Image, resulting in zero CVEs and a whole lot of fun!

We put Snyk Code Symbolic AI to the test to analyze code paths and detect security vulnerabilities.

Chainguard EOL Grace Period is a product that is designed to support Chainguard Images customers as they transition off end-of-life software.

This Black History Month, we celebrate the invaluable contributions Black individuals have made to our company, our industry, and our world. At Snyk, we believe that a diverse and inclusive workplace is essential for innovation and success, and we’re committed to fostering a culture where everyone feels valued and respected.

Chainguard builds all .NET8 and .NET9 components entirely from source to enable faster CVE remediation, full end-to-end integrity, and build transparency.

Weak encryption algorithms are cryptographic algorithms that provide inadequate security against attacks. Find out how Snyk Code can help find weak cryptographic algorithms and with weak cryptography testing.

Explore the business value of mitigating security threats early in the development process and embedding security at every stage throughout the entire application lifecycle, and some of the most effective ways to adopt a secure-by-design approach.

The European Union’s Network and Information Systems 2 is a compliance framework with strict requirements around vulnerability management.

Chainguard has recently signed CISA’s Secure Software Development Attestation Form, attesting to the security of Chainguard and its products.

Check out some of the previous Fetch the Flag challenges grounded in the same technical concepts and tactical material we’ve seen in the industry – and get excited for the 2025 Fetch the Flag!

Custom Assembly is Chainguard’s new image customization product that enables companies to consume zero-CVE open source software tailored to unique requirements.

Velotix utilizes Chainguard Images to help reduce CVEs, improve performance, and save time. Learn how Chainguard helps them build a more secure infrastructure.

Docker Bake is a great resource to define build configuration using a declarative file that integrates well with Chainguard Images. See how.

Recently, researchers have found another Software Supply Chain issue in BoltDB, a popular database tool in the Go programming environment. The BoltDB Go Module was found backdoored and contained hidden malicious code.

Chainguard Containers are a great way to consume third party applications like MySQL, NGINX, ArgoCD, and others while reducing size and CVEs.

New guidelines for HIPAA’s Security Rule have been proposed, which include updated requirements for vulnerability management, risk management, and more.

Snyk’s integration with Google Cloud Security Command Center (SCC) enables CISOs and security teams to monitor and manage AppSec vulnerabilities and misconfigurations from Snyk alongside cloud security issues from Google Cloud, all within a single pane of glass.

Chainguard Assemble is an event hosted by Chainguard for engineering and security professionals and leaders on March 25, 2025 at Convene in San Francisco, CA.

In this post, we’ll delve into what SBOMs are, why they’re necessary, and their role in open source security.

Chainguard CVE Visualizations, now generally available, is a capability that allows users to compare CVE numbers in both Chainguard Containers and upstream.

In this tutorial, we’re going to walk step by step through creating an npm package using modern best practices (as of 2022).

Chainguard Images are designed to make container image compliance for PCI DSS v4.0 easy for any company involved in card transactions.

Chainguard is building the future of secure software development, where security and innovation move in lockstep and every line of code makes software safer.

Snyk Accelerate is a new offering from Snyk and Accenture that aims to help clients adopt a developer-friendly security program that both reduces business risk and speeds up developer innovation.

Chainguard Images are designed to make achieving FedRAMP compliance for container images easier. Learn more about how we make vulnerability management simple.

Chainguard Images are now available for purchase by Government of Canada organizations thanks to our Software Licensing Supply Arrangement with Carahsoft.

DevSecOps isn’t dead, but organizations must continually adapt to align developer and security teams. Learn more about Snyk’s DevSecOps Maturity Framework here.

Probely, now a Snyk Business, is putting some UI changes into effect. We explain this first round of changes, and how we’re looking at further changes in the future to match Snyk’s design language.

Find out how the Cyber Resilience Act (CRA) sets new security standards for the EU and how Snyk can help simplify compliance with its developer-friendly tools.

Open SSF’s recommended compiler flags are a great way to improve memory safety and security. Check out what effect using these flags can have.

Fetch the Flag, Snyk’s annual Capture the Flag (CTF) competition, is back for 2025. Join this exciting virtual event on February 27, 2025, hosted by Snyk and cybersecurity expert John Hammond, from 9 am to 9 pm ET.

Chainguard released several new images in December 2024, including images for Adoptium, AWX, CouchDB, and others. Check out the full list.

Discover how BFI Finance Indonesia transformed their SDLC with proactive security practices, improving compliance, developer experience, and collaboration. Learn key insights from their journey shared at CISO Indonesia 2024, moderated by Snyk’s Didik Achmadi.

Snyk joined JPMorgan Chase’s Hall of Innovation for 2024, celebrating its impact on application security, market disruption, and overall partnership. Learn more about this collaboration.

Snyk Security Labs found no indications that Cursor was in any way vulnerable to dependency confusion.

Chainguard is building on the success they generated for their customers in 2024. Take a look back at the numbers, and see what’s next for us and our users!

AI-generated code is impacting how AppSec teams work. Learn more about the risks of AI-generated code and how Snyk can help secure your codebase.

Understand the basics of Docker security best practices with our Docker Cheat Sheet to improve container security.

Application security is critical to safeguarding customer data and maintaining trust. Explore best practices for AppSec, including secure coding, vulnerability management, and integrating security into continuous development cycles. Protect your digital services and stay resilient against evolving threats, ensuring a secure future for your customers and business.

Boost your AppSec in 2025 with resolutions like automating fixes, securing AI models, and building trust in AI-generated code for safer, smarter apps.

Is your team on the naughty or nice list? Read on to see if your security practices make the cut this holiday season.

Chainguard remediated two Golang CVEs just in time for Christmas. Read how we did it, with a poem in the style of “‘Twas the night before Christmas.”

Check out Chainguard CVE Visualizations, a new capability that allows for comparisons of CVE numbers between Chainguard Images and alternative container images.

Discover four practical tips for scaling your AppSec program to meet the speed of GenAI-assisted development. Read our whitepaper to learn more.

Check out the new zero-CVE Chainguard Images built in November 2024, including offerings for Bun, CockroachDB, Open Liberty, Selenium, and more.

Chainguard wanted to know more about malware prevention in Linux distributions. So we did a study to see what maintainers are doing about it. See the results.

With Snyk’s approach and Snyk AppRisk, implementing risk-based prioritization is easy. Here’s how Snyk’s developer-first, holistic approach works.

Discover the details of the Ultralytics AI supply chain attack, a sophisticated two-phase breach targeting PyPI releases and GitHub Actions with cryptocurrency mining malware. Learn how to detect exposure, secure your projects, and protect against future vulnerabilities using tools like Snyk.

Dive into Server-Side Request Forgery (SSRF) vulnerabilities in Go applications and explore mitigation techniques. Learn how to secure your Go code and leverage tools like Snyk Code for proactive security.

Chainguard has migrated its serving platform from Kubernetes to Cloud Run. Take a peek at how we did it, and how it makes Chainguard a more secure place.

Snyk now includes license information in its generated SBOMs, giving developers a clearer picture of their application’s components and associated license risks and simplifying compliance and security efforts. This new feature streamlines SBOM creation and empowers developers to make informed decisions.

Read top-level findings from Snyk’s 2024 Open Source Security Report, exploring slowing progress and new challenges for DevSecOps.

Finding and closing coverage gaps in your AppSec program is not a one-and-done process, it’s an ongoing combination of efforts. See how ASPM makes it easier.

Looking to turn a single-arch Docker build into a multi-arch? See how you can do that while still using Chainguard Images.

In the Women Leading Security series, Snyk CMO Jonaki Egenolf spoke with influential leaders about challenges and opportunities in the journey toward a more inclusive cybersecurity industry.

DevSecOps integrates security into the entire software development lifecycle. By empowering developers with automated tools and shifting security left, organizations can deliver software faster and more securely.

Learn how to measure AppSec success with key KPIs that demonstrate risk reduction, improve security posture, and showcase business value to stakeholders.

Looking to boost your cybersecurity skills? Snyk’s CTF 101 Workshop offers a hands-on introduction to Capture the Flag competitions, empowering students to tackle real-world security challenges. Learn about application security, network vulnerabilities, and more through free, engaging training.

Understand FedRAMP vulnerability scanning rules, scope, and SLAs. Get compliance clarity and learn how to simplify audits.

Learn how to use risk-based prioritization for vulnerability management. This blog will help you reduce alert fatigue and improve your security posture.

Women in security: Inspiring leaders of today and tomorrow

Chainguard Images are now built using enhanced compiler flags for C/C++ projects. See how this strengthens the security posture of Chainguard’s build systems.

Read how command injection works and the dangers it poses. Learn about practical guidance on how to prevent it. By following best practices and using tools like Snyk, you can significantly reduce the risk of command injection attacks in your Go projects.

Go over all the new Chainguard container images released in October, including new offerings for Swift, Dart, Linkerd, Jaeger, and more.

Snyk’s developer-first approach secures recognition as a Customer Favorite and a Leader in The Forrester Wave™: Software Composition Analysis (SCA) Software, Q4 2024 report.

Chainguard’s FIPS Images are available for deployment on any Linux kernel, thanks to some new innovation by our engineering team. Learn what this means.

Snyk acquires Probely to expand its DevSecOps platform with API Security Testing and modern DAST. Learn how this acquisition will help developers build and secure web applications faster.

Visibility gaps are a huge limiting factor for growing AppSec programs. Let’s discuss how Snyk can help you close them.

Chainguard now offers over 1,000 container images with zero CVEs in our Chainguard Images Directory. Discover how we got here, and how our images can help you.

Learn about the HTTP Archive’s Web Almanac, a valuable, community-driven resource for today’s security teams.

On October 31st, 2024, another package compromise and cryptocurrency hijack story unfolded for a popular npm package. Scan open source dependencies and container images in the CLI or your SCM with Snyk to determine if you’re using one of the vulnerable versions of lottie-player, and potentially uncover any other security vulnerabilities you may have in your projects.

Chainguard interviewed AI developers about containers and how they are used in the creation of AI applications. See the results.

Speed Up Code Remediation with AI-Powered Tools. Learn about the top 5 SAST auto-fixing tools and their features to streamline your development workflow. Discover how Snyk Agent Fix can slash your remediation time by 84% or more.

By integrating security practices into the development lifecycle, providing continuous education and training, and automating security workflows, organizations can effectively mitigate risks from open-source supply chain incidents, AI-generated code, and emerging threats. Snyk provides the tools and resources to establish a proactive security culture and ensure application security.

Snyk Agent Fix is a powerful AI-driven tool that automatically fixes code vulnerabilities. It integrates seamlessly into developer workflows and prioritizes critical issues. By leveraging AI, Snyk Agent Fix offers fast, accurate, and safe auto-fixing, empowering teams to improve application security.

Look into the security challenges facing the booming Software-Defined Vehicle (SDV) market. While SDV promises exciting features and revenue streams, its reliance on C and C++ code, notorious for vulnerabilities, raises concerns.

Linky’s Guide to Chainguard Images is a set of courses for customers and prospects of Chainguard to learn more about our container images product.

Learn how to secure applications with Snyk’s holistic, app-centered approach to risk management. Try Snyk for smarter and safer risk-based prioritization.

Discover how to break into the exciting field of application security. Learn about free online resources, community involvement, mentorship opportunities, and exclusive communities for women in cybersecurity. Get inspired by industry leaders and start your journey today.

Learn how to integrate comprehensive security testing into DevOps pipelines to protect your entire software development lifecycle.

Snyk Analytics is a comprehensive new offering that lets AppSec leaders improve program health by tracking coverage, exposure, management, and prevention metrics.

Snyk partners with the Service for America Initiative to offer free cybersecurity education through Snyk Learn. Discover Snyk Learn’s free, hands-on training and workshops designed to equip developers and security teams with the skills to build secure applications. From coding security to Capture the Flag events, Snyk helps prepare students and professionals for the ever-evolving cyber landscape.

Find out why developer experience is so crucial to Snyk and how we enable a more streamlined developer experience with our newest features.

Chainguard is going to be at KubeCon North America 2024 in Salt Lake City. See where we’ll be and how you can meet us to learn more about Chainguard Images.

Explore Snyk Deep Code AI Fix (DCAIF), a game-changer for developers. Unlike generative AI assistants that may introduce security vulnerabilities, DCAIF leverages a hybrid AI model to automatically fix common security issues like XSS right in your IDE.

Snyk Code’s enhanced dataflow analysis simplifies vulnerability identification and remediation. Learn how this powerful tool streamlines the security process and saves developers valuable time.

Learn about Snyk’s incoming GenAI Partner Program and how it secures the code produced by AI coding assistants, ensuring developers can code faster and more securely.

Read a recap of our SnykLaunch event for October 2024, covering our new features that power a developer-first, risk-centric security experience.

Npm package aliasing can be a security threat. Learn about how malicious actors can exploit this feature to introduce fake packages into your projects. Protect your projects with best practices and stay vigilant against supply chain attacks.

Check out Chainguard’s new image releases over summer 2024, including container images for GitLab, Amazon EKS, and PyTorch applications.

Protect against modern threats like open-source supply chain attacks and AI-generated code vulnerabilities. Automate dependency scanning, remediation, and container security to ensure your applications are safe and compliant. Secure your software development with Snyk’s comprehensive vulnerability management solution.

Snyk, the leader in developer security, is excited to share that we’ve been named a Customers’ Choice in the 2024 Gartner Peer Insights Voice of the Customer for Application Security Testing for a third consecutive year.

While static reachability can help teams better understand their app vulnerabilities, they must be paired with other types of context and risk insights.

Security researcher evilsocket.net (Simone Margaritelli) published information about several vulnerabilities in CUPS that allow for remote code execution (RCE)

Fortify your Node.js applications against log injection attacks! This guide dives deep into the dangers and solutions to protect your logs from malicious manipulation. Stop attackers and build secure Node.js applications today.

AI is keeping CISOs up at night. Learn about risks of generative AI and Shadow AI, and how to secure your AI deployments with Chainguard.

Learn how to create secure applications using Deno. Explore the default security measures provided by Deno, understand potential vulnerabilities such as Server-Side Request Forgery (SSRF), and uncover the best practices for minimizing risks. Enhance your application’s security by leveraging Deno’s advanced features.

Discover how to secure your C and C++ code with Snyk. Learn about common vulnerabilities like memory leaks and buffer overflows in C and C++ and how Snyk’s static code analysis tool can help you identify and fix them. Protect your critical software from security threats.

We’re excited to announce that Snyk AppRisk Essentials is rolling out for all Snyk Enterprise Plan customers.

Chainguard Labs explores FuzzSlice, a novel fuzzing technique, to improve vulnerability remediation by distinguishing exploitable CVEs from false positives.

Dive into the world of AI and LLM security with Snyk Learn’s new free learning path. Learn how to protect your AI systems from the OWASP Top 10 vulnerabilities. Master prompt injection, sensitive data disclosure, and more. Start your AI security journey today!

Discover how Snyk’s FedRAMP-authorized platform empowers developers to build secure applications. Learn about our comprehensive solutions for vulnerability management, supply chain security, and AI code scanning.

Concerned about data breaches? Exposed secrets like API keys and passwords are a major culprit. Secure your software development lifecycle, identify and remove hardcoded secrets in code, and leverage Snyk’s secrets detection tools to identify secrets early in development in order to prevent breaches and safeguard your applications.

We’re excited to announce a new Snyk AppRisk integration with Orca Security that brings together application security from Snyk and leading cloud security from Orca.

Learn why the development practices at financial services companies are outpacing older security technologies and techniques.

Gain essential insights and practical advice on navigating FedRAMP compliance from industry experts including how to integrate open source tools.

Let’s discuss the importance of PHP security and the business impact of some notable PHP interpreter vulnerabilities that are crucial for developers to get right.

Learn why modernizing application security is essential for today’s financial services companies.

Find out how Axel Springer’s National Media & Tech business division uses Snyk to empower its developers to find and fix vulnerabilities in their own code.

Achieve Zero CVEs on Cloud Run with OpenTelemetry sidecar. Learn how to leverage Chainguard Images for secure and efficient monitoring.

Read on to learn about the danger of the continued use of vulnerable Log4j and Spring Framework versions in many projects.

Chainguard’s ChainGPT: The LLM agent revolutionizing open source exploration. Browse code, execute commands, and gain insights faster than ever before.

Snyk Code is the only security tool featured in Stack Overflow’s 2024 AI Search and Developer Tools survey. Try Snyk Code to improve performance & developer security.

Chainguard Java Images now support FIPS 140-3 with Bouncy Castle 2.0. Future-proof your compliance and simplify audits with pre-configured, secure images.

In honor of this year’s International Dog Day, we’ve put together three lessons that we can learn from our four-legged friends about AI code security.

Read on to discuss the current status of AI-generated code and how to safely utilize it in financial services.

Chainguard’s Project Safe Source uses CodeQL to identify & fix vulnerabilities in open source projects packaged in Wolfi with automated pull requests.

Learn about three industry trends that affect how companies approach software supply chain security, along with actionable tips for responding to them.

Chainguard remains committed to securing open source software. Discover how our updated Developer Images offering supports your projects.

Secure by default starts with immutability. Discover how to control change and minimize risks.

New NIST AI standards address generative AI risks with a focus on risk management, security practices, and recognizing synthetic content.

Learn the basics of vulnerability remediation from this teaser of Chainguard’s Get Smart in Five Minutes series on Youtube.

In honor of the upcoming Olympics, let’s look at a few of the “training areas” that help security teams on their journey to AppSec gold.

Read four expert tips for establishing the right tools, process, and culture for a DevSecOps program, as discussed at the InCyber Forum Europe.

In this blog post, we aim to provide an overview of common security vulnerabilities and vulnerable patterns that can occur when writing C/C++ add-ons in NodeJS.

In this post, we’ll cover four simple methods for finding security vulnerabilities in your Java and Kotlin code.

Master CMMC 2.0 compliance! Get expert insights, downloadable resources, and guidance to safeguard your sensitive data.

A recent Gartner report shows that AI transparency is a common issue in many organizations. Snyk Code’s hybrid AI-powered SAST is the secret ingredient for AI security & coding.

Learn the basics of CVEs, why they matter for cybersecurity, and how to stay protected in this quick teaser of the Get Smart series by Chainguard.

Learn how Chainguard Labs is enhancing vulnerability data with large language models (LLMs) to improve the accuracy and efficiency of CVE identification.

Learn about application vulnerability management, including its basic definition, what it can and cannot do, and how to supplement it with best practices.

We are thrilled to announce the new Snyk Analytics for Snowflake, allowing Snyk customers to seamlessly access and analyze Snyk’s data from their Snowflake account.

Chainguard Labs analyzed the security of 1,500+ upstream Wolfi repositories using the OpenSSF Scorecard tool — uncover the key findings in the latest research.

4 takeaways about adopting AI securely from a session at Infosec Europe 2024.

We are thrilled to expand Snyk AppRisk integrations with additional leading Internal Developer Portals (IDPs) and service catalogs: ServiceNow CMDB, Atlassian Compass, OpsLevel, Harness, and Datadog Service Catalog!

Learn from Chainguard experts about strategies and tools for keeping Kubernetes container images updated and secure.

In this blog post, we are going to delve deep into the world of application security, specifically focusing on a vulnerability that can deteriorate FastAPI security: Denial of service (DoS) caused by insecure regular expressions (regex).

In this blog, we’ll discuss strategies to protect your C# code from SQL injection.

Learn how to use Chainguard Images to streamline compliance and avoid the “compliance end run” that slows down sales and creates friction with customers.

Learn to secure your AI/ML supply chain with Chainguard’s new course, designed to help you mitigate risks and build safer AI/ML systems.

Chainguard raises $140M to address the growing need for secure AI workloads and open source software in the enterprise.

Learn how Chainguard’s AI Images secure the foundations of AI applications by providing hardened, minimal container images for PyTorch, Conda, Kafka, and more.

It’s my pleasure to announce Diana Brunelle as Snyk’s new Chief People Officer (CPO). Diana comes to us with more than two decades of experience in global HR leadership and talent strategy. I’m eager to see her channel her passion and expertise to further build on Snyk’s inclusive company culture to drive organizational alignment and continued growth.

Join Chainguard at Black Hat USA 2024 for cybersecurity insights, networking, and fun in Las Vegas this August. Don’t miss our exciting events and activities!

In this post, we will be exploring the world of Deno, GitHub Codespaces, and Dev Containers, providing you with the knowledge you need to set up your development environment effectively and efficiently in the cloud. Our target audience for this post is developers, particularly those who work with the JavaScript and Node.js ecosystem.

Chainguard joins the Coalition for Secure AI with OpenAI, Google, and Anthropic, enhancing AI security. Discover our commitment to safeguarding AI technologies.

Python static analysis, commonly referred to as “linting,” plays a vital role in software development by examining Python code without executing it. This process aims to uncover potential bugs, programming errors, stylistic inconsistencies, or deviations from established coding standards. Additionally, static analysis facilitates early detection of vulnerabilities, thereby minimizing the risk of deploying insecure code into production environments. It is an essential practice for maintaining code quality and security.

Discover how Chainguard surpasses copacetic in the zero-CVE challenge. Ensure vulnerability-free deployments with our Chainguard Images.

Chainguard secure the web with new Laravel and WordPress images. Learn about enhanced security and seamless integration for your web apps.

In this blog post, we’ll discuss practical steps to ensure your S3 buckets are secure and compliant with best practices.

Learn about NIST’s latest updates on container image security and how it impacts your organization’s security posture.

The European Union’s Digital Operational Resilience Act (DORA) establishes a comprehensive framework to manage Information and Communication Technology (ICT) related risks and ensure business continuity for financial institutions and critical service providers.

Enhance your container security with Chainguard’s STIG-hardened FIPS images, now generally available, offering unparalleled compliance and protection.

Learn about the NVD’s recent updates, including CISA Vulnrichment data, CVSS v4.0 integration, and how they impact your vulnerability management workflow.

Read thoughts from our Vice President of Product Marketing after his time at RSA Conference 2024, including his thoughts on proactive security.

Learn how to create a secure and streamlined golden image program with Chainguard Images, JFrog Artifactory, and Xray.

NIST’s framework for enhancing software supply chain security: Learn how the NIST is guiding organizations to build a more secure software ecosystem.

Explore Chainguard’s new OSV advisory feed, delivering comprehensive and up-to-date vulnerability information to enhance your security posture.

In this post, we’ll discuss what REST APIs are and how to secure them.

Dive into our latest CVE patch report and see how Chainguard proactively mitigates vulnerabilities to enhance software supply chain security.

On June 25, 2024, the Sansec security research and malware team announced that a popular JavaScript polyfill project had been taken over by a foreign actor identified as a Chinese-originated company.

In this blog, we’ll show how you can use Snyk to locate hardcoded secrets and credentials and then refactor our code to use Doppler to store those secrets instead.

Snyk Code can now protect the use of supported LLM libraries in source code to detect any security issues and promptly alert users. Book a live demo.

Ensure Java compatibility & security with Chainguard’s JCK-conformant OpenJDK images. Streamline development and deployment with trusted, verified Java runtimes.

Stop wasting time on known exploits. Read our latest research and discover strategies to streamline your vulnerability management for maximum efficiency.

Upgrade your software security with the latest Chainguard Images, featuring FIPS, Harbor, Apache, and more. Streamline your development and enhance protection.

Read an overview of Snyk and Accenture’s recent whitepaper: Why ASPM is the future of Application Security.

Learn how Snyk’s developer-first application security tooling can support development teams in securing their development workflows on Google Cloud.

Worried about your software supply chain? Take 5 minutes to learn about the risks and how to mitigate them. Secure your software today.

We’re excited to announce that the Snyk Language Server (LS for short) can now be integrated with your existing IntelliJ IDEs.

Learn about the risks associated with AI-generated code in software development. Gain actionable insights on how to AI coding risks in this article.

In this blog post, we discuss the how “vulnerability management” tends to fall short when approaching modern application security.

Learn about the recent changes to LTS images in Chainguard Images developer tier. Discover how these updates improve security, reliability, and ease of use.

Boost your Node.js skills with these backend code snippets for 2024. Copy and paste them into your own projects to save time when building backends.

Snyk has now developed an AWS Marketplace add-on for Amazon Elastic Kubernetes Service (Amazon EKS) embedded directly into the AWS Management Console.

Are your vulnerability scanners missing critical security flaws? Discover how Chainguard’s research reveals hundreds of vulnerabilities hiding in plain sight.

In this post, we discuss AI output quality and how to avoid the common pitfalls.

Build secure, minimal Java images with fewer CVEs. Learn how Chainguard Images helps you optimize security and performance for your Java applications.

Dive into the world of STIG hardening for container images. Explore expert insights, practical tips, and Chainguard solutions to fortify your container security.

In today’s blog post, the Snyk CLI team will share how our research informs product discovery, development, and impact, where we need your help, and how you can share your experience and pain points with us.

Join Chainguard in celebrating 10 years of Kubernetes! Discover 10 things we love about the transformative technology and how it shaped cloud-native development.

Chainguard co-founder and Kubernetes co-creator Ville Aikas reflects on 10 years of innovation and shares his birthday wishes for the future of cloud-native.

Read the top highlights from the Black Hat Asia session hosted by Snyk, “Securing the Next-Gen Software Development: Challenges & Solutions.”

Secure and streamline your Node.js applications with Chainguard Images. Learn how to migrate seamlessly and enhance your software supply chain security.

In our latest report, Snyk surveyed security and software development technologists, from top management to application developers, on how their companies had prepared for and adopted generative AI coding tools.

We are thrilled to announce the strategic partnership between Snyk and Snowflake,two industry leaders coming together to revolutionize data and application security.

New to container images? Our quick guide will teach you the fundamentals in no time, covering everything from what they are to how they’re used.

Don’t let the unexpected derail your projects. Read our guide on embracing uncertainty in software development and unlock new possibilities.

Five actionable tips for using AI code assistants securely and integrating security checks for AI-generated code throughout the software lifecycle.

This post will explore 10 modern Node.js runtime features that every developer should start using in 2024. We’ll cover everything from fresh off-the-press APIs to the compelling features offered by new kids on the block like Bun and Deno.

Secure development environments with cloud workstations powered by Chainguard’s Wolfi. Learn how to reduce attack surface and improve developer productivity.

This blog post will focus on the foundational building blocks of building backend Node.js APIs using Fastify and its recommended plugins in 2024.

In this article, you’ll learn more about broken access control in Node.js applications and strategies to prevent such vulnerabilities when building web applications based on the Express web framework.

Struggling to adopt secure container images? Our new migration guides provide step-by-step instructions and best practices for a smooth transition.

The emergence of AI-generated code looks similar to cloud transformation in the past. We can take lessons learned from the cloud and apply them to AI.

In this article, you’ll learn about some best practices related to securing Python applications built with the Flask web application framework. You’ll start by looking at some insecure configuration examples and then learn how to mitigate and fix any issues.

Navigating PCI DSS v4.0 compliance? Chainguard Images simplifies the process with secure, compliant container images for your payment applications.

Learn how American Airlines enhanced Backstage security with Chainguard’s Wolfi.

In this guide, we’ll discuss symmetric and asymmetric encryption, implement them in Python, and explore their best practices.

Learn about the latest changes to Chainguard’s static, git and busybox Developer Images. Enhance your software development with improved security and efficiency.

Trust but verify: Read about Chainguard’s independent security assessment by Trail of Bits and our dedication to transparency in security practices.

Learn how Chainguard prioritizes security with our new Trust Center. Find info on our policies, certifications, and how we protect your software supply chain.

Dive into three tips for spring cleaning your AppSec program: organizing assets, decluttering alerts, and sprucing up policies/controls.

Strengthen your software supply chain security with audited least privilege. Learn how Chainguard’s approach minimizes risk and enhances trust.

We’re excited to announce that The Secure Developer has a new host! Let’s welcome Danny Allan, Snyk CTO.

Explore the latest features and security enhancements in Chainguard Images (April 2024 release). Strengthen your software supply chain.

Bridge the dev-security gap! Learn essential insights for fostering a collaborative, secure development environment.

This guide will detail all the steps to build a modern Python package.

Chainguard proudly signs CISA’s Secure by Design pledge. Learn why we support this critical software security initiative.

Today, we are excited to announce the addition of Snyk Code (SAST) results to our Snyk Security for Application Vulnerability Response solution.

Fixing security issues is complex, so to learn more about how we do this, we will deep-dive into the research paper that explains the star ingredients behind Snyk Agent Fix - CodeReduce technology and our curated security fix dataset.

Is your container security FedRAMP Rev 5 compliant? Discover the key requirements and how Chainguard can help.

Open Source Octo STS Released — Chainguard’s solution to eliminate long-lived GitHub credentials. Improve security, collaborate, get updates.

Find out how Snyk AppRisk Pro, our application security posture management (ASPM) solution, is designed to empower your application risk management programs.

Discover how Chainguard Images helped remove 150+ CVEs in March and April 2024. Learn more about our commitment to securing your software supply chain.

We are pleased to introduce Semantic Versioning and release channels to Snyk CLI from v.1.1291.0 onwards. In this blog post, we will share why we are introducing these changes, what problems these changes solve for our customers, and how our customers can opt-in according to their needs.

Learn how Mulesoft facilitates a DevSecOps culture by empowering its developers with fewer context shifts and more velocity.

Check out our analysis of the hardened container image landscape, including offerings from Red Hat, Iron Bank, and others.

RSAC 2024 with Chainguard: Lounge, movies, lightning talks, karaoke reception at MoAD, & AppSec Village workshops. Get your discount code here!

Accelerate AI development with Chainguard’s CUDA Optimized Images. Secure, streamlined NVIDIA deployments — join our Early Access Program!

Snyk Ambassador Soumen Mukherjee walks us through the various features of the Snyk platform and how it provides 360 degrees of application security.

Upgrade your Python and Go security without sacrificing speed. Chainguard Images offer zero CVEs and blazing performance.

Snyk Agent Fix now supports 8 languages, significantly improved accuracy with new proprietary technology, and multimodal, hybrid AI for robustness through model diversity.

At DevOpsDays Singapore 2024, Snyk’s Lawrence Crowther was featured as a keynote speaker. Here are some highlights from his presentation on the critical security integration within DevOps processes, focusing on AI-generated code and its potential to revolutionize software development while exposing vulnerabilities.

Understand exploit chaining — linking vulnerabilities for devastating attacks. Learn defense strategies with Chainguard Images and secure coding practices.

Publishing JavaScript packages that are compatible with both ECMAScript Modules (ESM) and CommonJS (CJS) is a critical skill for developers who aim to integrate wide-ranging libraries. This write-up focuses on practical approaches and best practices for maintaining ESM and CJS support.

Snyk’s Vandana Verma Sehgal sat down with Sherif Mansour, the Director of InfoSec at JustEat, for a “Day in the life of a CISO” session to learn more about his day-to-day experience as a security leader.

Tired of wasting time on CVEs? Learn how to streamline container security, boost developer productivity, and reduce risk. Data-backed insights inside.

In the following post, we will guide you through installing Java on macOS, ensuring you’re ready to start developing applications in no time.

This article looks at the potential security implications of large language models (LLMs), a text-producing form of generative AI.

Software backdoors are a threat. Learn how to mitigate supply chain security risks by responding faster to vulnerabilities like the xz flaw.

Generative AI is ubiquitous across the software industry. Learn more about its impact on today’s development teams and how to use it securely.

In this post, we dive into nine lesser-known yet highly effective commands that can significantly improve your Docker experience in Node.js.

Ditch GitHub PATs for better security. Learn how to replace long-lived tokens and reduce your risk of leaked credentials.

Read an overview of our ASPM masterclass, including the definition of ASPM, its uses in today’s organizations, and a few implementation tips.

Learn how Snyk’s new partnership with Gemini Code Assist empowers developers to develop with security and AI-powered velocity.

Chainguard enhances Big Bang with secure, smaller images: 100% fewer CVEs, 40% less components, 72% size reduction for fortified security.

This post covers all the info you need on the new HTTP/2 CONTINUATION frames vulnerability, including the affected versions, its impact, mitigation steps, and how to protect your applications.

Discover the latest Chainguard Images in March 2024, offering unparalleled security with low-to-zero CVEs for fortified software supply chain.

Chainguard jokingly revels its ‘most vulnerable’ Image with 300,000 CVEs as an April Fools’ joke, showcasing just how many CVEs they protect against.

On the 29th of March 2024, the high-stakes investment and prolonged campaign to plant a backdoor in the Linux software library liblzma to gain access to multiple operating systems via Linux distributions was carried out by a malicious actor.

Chainguard effectively addresses CVE-2024-3094 in xz library, showcasing quick action to secure images and uphold customer trust.

Learn how adding a few characters to your image names with Chainguard Images can slash image sizes by 93% and drop CVEs to zero.

Get an overview of NSA’s newest guidance on open source security and learn how to follow it in your Google Cloud environment with Snyk.

Discover why End-of-Life software poses a high security risk with over 400 CVEs annually, emphasizing the importance of timely updates and secure practices.

Explore the evolution of AI in software development and its current applications, and discover how Snyk leverages AI in its security products to safeguard the development ecosystem.

In this post, we cover the basics of static analysis and how to secure your PHP code in 2024.

See how Chainguard swiftly patched three Golang CVEs in under 24 hours, showcasing rapid response and dedication to secure software.

In honor of the upcoming March Madness tournament, we’ve put together our own dream team for AppSec. Read on to discover Snyk’s all-star application security features and how they can help your team get a slam dunk in protecting applications from code to cloud.

Chainguard Images joins Docker Hub as a Verified Publisher, offering developers secure, hardened images for open source projects.

Learn why NVD delays do not compromise the integrity or efficacy of Snyk’s security intelligence, including the Snyk Vulnerability Database.

GitGuardian partners with Chainguard, utilizing Chainguard Images to reduce CVEs, enhance security, and meet compliance standards efficiently.

In this post, we’ll discuss the recent discovery of malware repositories and repo confusion on GitHub, and cover how to keep your applications secure.

Snyk’s latest masterclass series, Unlocking AppSec Excellence, aims to educate the market on ASPM and how application security leaders can use it to build an effective risk-based AppSec program.

Join Chainguard at KubeCon in Paris, March 19-22, for insights, networking, and a chance to win big with our Passport Program!

Unlock the latest Chainguard Images for Selenium, Gotenberg, and more, boosting your cloud security with zero-CVE, minimal container solutions.

Learn what to include in your application security maturity model and how to assess your current level of application security maturity.

Find out how Snyk Learn helps development teams with the “Protect” function of NIST CSF 2.0.

Learn how you can safely adopt AI code completion tools (like Copilot) by applying these 5 best practices and see how Snyk can make it easy to stay secure.

Uncover insights on whether to build or buy in container lifecycle management with tips from Chainguard, balancing security and operational needs.

We’re thrilled to announce that Gary W. Olson has joined Snyk as our new Chief Revenue Officer (CRO).

Explore the top AI coding and security assistants like GitHub Copilot, Snyk Code, and more that are revolutionizing development - code faster, more efficiently, and securely.

Defense in depth is a cybersecurity approach that focuses on making it as difficult as possible for attackers to succeed by combining numerous security measures.

In this post, we’ll review Snyk’s approach to documentation, the recent improvements we’ve made, and what’s coming soon.

In this blog post, we will be exploring some essential Node.js security code snippets every backend developer should know in 2024.

Learn how the REI team built a strong security culture across development units in this AWS Re:Invent chat between Dan Ngo, Lead Security Engineer, Cybersecurity Engineering and Risk Management at REI, and Clinton Herget, Field CTO at Snyk.

Leverage Chainguard’s insights to forge low-CVE, compact images for compiled languages, boosting your security posture.

Explore Wolfi’s speedy updates: A key to securing Chainguard Images against vulnerabilities and delivering up-to-date software swiftly.

Organizations experience different pain points when implementing a DevSecOps culture, but the fundamentals of people, process, and tooling changes remain the same.

See how Chainguard mitigated the potential vulnerable GitHub actions workflow “Pwn request” in less than 24 hours.

Discover Wolfi: Chainguard’s answer to modern container security, creating minimal, secure Linux distributions for today’s needs.

This article will explore SSRF, its potential risks, and the strategies to mitigate SSRF in Node.js applications.

In this article, you’ll learn more about why SQL injection attacks pose a significant threat and how to shield your Node.js applications against them.

Uncover Chainguard’s approach to detecting and neutralizing hidden threats like CVE-2024-24806 in container environments.

Explore our FedRAMP container security compliance checklist. Tailored for CISOs and developers, it simplifies FedRAMP certification, ensuring robust compliance.

Developers are using AI, and there’s no turning back. Here’s how you can minimize vulnerabilities and security risks associated with AI coding tools.

This year for Valentine’s Day, we’re imagining what a love letter from your applications to the tools that keep them secure might look like.

Enroll in Chainguard Academy’s new course on Painless Vulnerability Management to master security practices and use Chainguard Images for safer software.

Learn what information CISOs need to know about your application security program in order to have a clear understanding of risk.

We recently released a series of improvements to Snyk IaC, and in this blog post, we’re taking a technical dive into a particularly interesting feature — automatic source code locations for rule violations.

Discover Wolfi, the ‘secure-by-default’ undistro for container security, enhancing open-source software with minimal CVE counts and robust protection.

We are excited to welcome two critical additions to the Snyk executive bench: Danny Allan, our new Chief Technology Officer, and Brian Rogan, our new Executive Vice President of Engineering.

Chainguard Labs surveyed nine companies to see how many hours they spent on vulnerability management each year. Check out this blog to see the results.

In this cheat sheet, we will discuss ten best practices you can implement to improve your GitHub security. Download the one-pager and read on for a more extensive explanation of all ten curated actions.

Chainguard swiftly addresses CVE-2023-6246 in glibc, reinforcing container image security with rapid patch deployment and updated advisories.

Chainguard’s response to ‘Leaky Vessel’ vulnerabilities: safeguarding container images with innovative, secure-by-default build processes.

Introducing the Chaingaurd Terraform Provider: Streamline your DevOps with secure, automated resource management for improved security.

Chainguard’s approach to zero-known CVE images safeguards against devastating cybersecurity breaches, ensuring secure software development.

In this post, we’ll cover what bug bounty hunting is, the difference between vulnerability disclosure programs and bug bounty programs, and seven tips to get you started.

Elevate your DevOps with Chainguard’s Autodocs: Continuous, automated documentations for secure container images made easy.

Learn how DevSecOps tools integrate security into your DevOps workflow from deployment to production.

Learn more about generative AI security in this recap from our recent fireside chat, featuring security and privacy experts from Snyk and Dynatrace.

Chainguard’s CTO Matt Moore describes the process of creating a declarative container image build for Chainguard Images.

This year, we asked the DevRel and SecRel team at Snyk and security experts from around the industry to drop in their personal and professional New Year’s security resolutions for 2024.

On January 11th, 2024, a significant security vulnerability was disclosed in Jinja2, a widely used Python templating library. Identified as CVE-2024-22195, this cross-site scripting (XSS) vulnerability has raised concerns due to its impact on numerous projects.

Wolfi is a Linux distribution built specifically for containerized applications. See how it can speed up your development process.

Snyk announces acquisition of Helios, accelerating application security posture management (ASPM) capabilities with runtime insights.

This guide covers everything you need to know about Python virtual environments — from creating environments with venv to containerization with Docker and securing your code with Snyk.

Want to contribute to Kubernetes but don’t know where to start? Learn how to do it in a sustainable way.

There are a multitude of considerations when it comes to picking the right security companion for your preferred generative AI tool. Here are the top 5 factors for you to consider when making your selections.

Secure your codebase with advanced supply chain security tactics: artifact authentication, minimal images and more from Chainguard.

In this guide, we’ll dive into the powerful combination of Platformatic, Fastify, and Snyk, unlocking rapid backend development with an emphasis on robustness and security.

Discover how Chainguard achieved SOC 2 certification by leveraging its own technology to streamline security processes.

CVE-2023-50164 is a critical vulnerability in the Apache Struts library. Learn how to find and fix by upgrading your package and using Snyk to discover and remediate.

Recently, Snyk hosted a wine tasting & customer discussion featuring David Imhoff, Product Security Leader at Kroger. The discussion focused on tackling the challenges of securing digital supply chains.

Navigate the cybersecurity landscape in shared work environments with essential tips on device safety and incident response.

Learn about three great ways to rebuild a Docker image faster: Add a .dockerignore file to your repository, use a dependency lockfile, and group commands!

In this article, you’ll learn more about open redirect vulnerabilities and how you can prevent them in Laravel. You’ll also learn how to use Snyk to detect this vulnerability in your code and dependencies.

In this article, you’ll learn all about command injection, including how this vulnerability can manifest in your programs. You’ll also learn about common security best practices to safeguard your Python apps from command injection attacks.

This holiday season is a good time to ask the same question in a different context: are your organization’s practices with AI, application security tooling, and other security-related practices putting you on the security naughty or nice list this year?

Sourcegraph’s story: leveraging Chainguard’s technology for streamlined software development and heightened security.

This blog aims to give a short overview of popular SAML vulnerabilities and how they can be remediated with some examples.

In this post, we cover the CVE reporting process using the Use After Free vulnerability type as an example.

Chainguard Images now supports Cilium and Istio. See how to integrate our container images into your environments.

In this blog post, we will discuss the top three security best practices for handling JWTs. We will also provide practical examples using Python and show how Snyk can help you identify and remediate security vulnerabilities in your application.

We’re proud that Snyk has been honored with inclusion on the inaugural Fortune Cyber 60 list as a top growth-stage company.

Experience hassle-free updates with Chainguard’s digestabot, ensuring your Images stay secure and up-to-date daily.

Discover Wolfi OS: Crafting minimal, always up-to-date cloud images for superior security and efficiency in the cloud.

To eliminate this burden and provide our customers with a clear security assessment for configurations across the SDLC, Snyk will be moving towards standardizing our code to cloud security rules set on the Common Configuration Scoring System (CCSS)!

In this blog, we recap the most exciting developments from AWS re:Invent 2023, including Snyk’s industry-leading progress with generative AI, ASPM, and the importance of AI security.

Discover how the updated Chainguard Images Directory simplifies finding container images and critical vulnerability advisories.

Announcing Snyk AppRisk for ASPM to revolutionize the way AppSec teams manage and enhance the security posture of their applications with Snyk

Learn three compelling reasons to invest in an application security posture management (ASPM) solution like Snyk AppRisk.

Chainguard Developer Images arrive on Magalu Cloud, Brazil’s growing digital ecosystem, ensuring hardened, CVE-patched Kubernetes service.

We are thrilled to announce that Snyk has been named as an Emerging Segment Leader in Application Security in Snowflake’s Next Generation of Cybersecurity Applications report.

Learn about the dangers and importance of secure coding conventions, particularly regarding code injection vulnerabilities and how these manifest in Python applications.


Today, Snyk is welcoming C/C++ security into the world of modern development with the general availability of C/C++ support for Snyk Code!

Discover new Image guides on Chainguard Academy: Master container security and management with our latest educational resources.

We’re excited to announce that Snyk has been named Customers’ Choice in the 2023 Gartner Peer Insights Voice of the Customer for Application Security Testing for a second consecutive year. This distinction is based on meeting or exceeding user interest, adoption, and overall experience.

Learn how Nylas leverages Snyk to drive developer security adoption and simplify the integration of AppSec tools into their workflows.

If you were at Snyk’s 2023 Fetch the Flag and are looking for the answer to the Off the SETUID challenge, you’ve come to the right place. Let’s walk through the solution together!

If you were at Snyk’s 2023 Fetch the Flag and are looking for the answer to the Honey Baked Messages challenge, you’ve come to the right place. Let’s walk through the solution together!

If you were at Snyk’s 2023 Fetch the Flag and are looking for the answer to the I Do Math challenge, you’ve come to the right place. Let’s walk through the solution together!

If you were at Snyk’s 2023 Fetch the Flag and are looking for the answer to the Protect The Environment challenge, you’ve come to the right place. Let’s walk through the solution together!

If you were at Snyk’s 2023 Fetch the Flag and are looking for the answer to the Silent Cartographer challenge, you’ve come to the right place. Let’s walk through the solution together!

If you were at Snyk’s 2023 Fetch the Flag and are looking for the answer to the Audiopolis challenge, you’ve come to the right place. Let’s walk through the solution together!

Use Snyk alongside Amazon CodeWhisperer to get best-in-class security while maintaining your speed of development

In this blog, we’ll demonstrate the best way to find and remediate open source vulnerabilities in Spring Boot.

While Snyk provides a comprehensive approach to developer security by securing critical components of the software supply chain, we recognize the increasing risk of exposed secrets in the cloud. So, we’ve tapped Nightfall AI to provide a critical feature for developer security: advanced secrets scanning.

AI code review reports on critical bugs in real time and shows you how to fix them. Discover even more benefits and how Snyk code review can help.

Learn how Chainguard Images go beyond reducing CVE count in your software supply chain, with hardened container images, SBOMs, and more.

In this blog, we’ll review the key concepts of application security posture management and walkthrough how ASPM fits into your application security lifecycle and makes your organization more secure.

Learn how Snyk can help you adopt a DevSecOps of continuous security for your apps on AWS.

Explore how easy it is to migrate existing container images to Chainguard Images, whether you are adopting Application Images or Base Images.

Snyk’s security researchers have identified and disclosed some vulnerabilities within some popular browser extensions: React Developer Tools and Vue.js devtools. This post will explore the WebExtension technology and look into the vulnerabilities identified.

This article dives into the world of encryption in Python. For symmetric encryption, we’ll focus on Amazon’s Key Management Service (KMS) and PyNaCl SecretBox. Then, we’ll look at asymmetric encryption and PyNaCl’s public/private box.

Fetch the Flag CTF 2023 took place October 27-28, bringing together thousands of players worldwide to compete to solve 30+ hacking challenges, ranging from web to cryptography. In this blog, we’re excited to share some of our favorite community writeups for these challenges.

Learn how Snyk’s product designers approached the UI/UX of the Snyk VS Code extension to improve consistency, reduce cognitive load and visual noise, and add delight.

Chainguard’s breakdown of KubeCon NA 2023: Top five highlights in software supply chain security, Wolfi, and more.

Snyk is excited to announce general availability of Snyk Apps, a framework for building and distributing custom security solutions to better inform security decisions and boost developer productivity.

Exploring the efficiency of debloated containers in the Zero CVE test: Chaingaurd’s analysis of security and efficiency.

Discover the final insights in Chainguard’s image tagging series, focusing on maximizing update speed and security.

Vulnerabilities and weaknesses both introduce risk but have key differences. Learn how to assess your apps to find and fix both vulnerabilities and weaknesses.

Learn about the different types of Values and Rules you can use to build policies in OPA & Rego.

Snyk has proudly attained the AWS Security Competency status, recognizing its extensive security expertise and dedication to providing robust application security solutions. This achievement underscores Snyk’s capability to support modern organizations in securely building and operating their applications on Amazon Web Services (AWS), further establishing its reputation as a leader in cloud-native application security.

Dive deeper into Chainguard’s approach to image tagging, a cornerstone for swift and efficient container updates in Part 2 of this series.

Revolutionize your enterprise’s software supply chain with Chainguard’s new Sigstore images.

Learn how AWS’s shared security responsibility model works and how Snyk can help you streamline your cloud and application security efforts.

Explore Part 1 of Chainguard’s image tagging philosophy series, focusing on enabling high-velocity updates.

We’re thrilled to announce Snyk’s integration with SentinelOne, offering a unified view that bridges the gap between build-time vulnerabilities and runtime threats to offer real-time threat protection.

Learn how to use AND and OR rules and custom messages using OPA and Rego in the second part of our beginner’s guide to Rego.

The Snyk Week of Impact, from October 22-27, was not just another event. It was a manifestation of our core belief in giving back. In a concerted effort that saw over 20% of Snykers participating globally, we aimed to create a ripple effect of meaningful connection and community engagement.

In this blog post, we will highlight Snyk’s view on the new vulnerability scoring framework, CVSS 4.0, which was released on November 1, 2023.

Chainguard’s new report reveals a crucial gap between developers and security teams on software supply chain priorities.

The new Snyk Vulnerability Intelligence for SBOM integration brings visibility to your SBOMs in ServiceNow Vulnerability Response for a more accurate understanding of risk within the enterprise supply chain.

To harness the full potential of developer-first security tools, a strategic alignment between the Development and Security organizations is essential. Learn steps to take to create that alignment.

Asset-first application security aligns developers, security teams, and executives by measuring cyber risk holistically based on business context.

Learn how to write your first policy as code rules in Rego. This Rego tutorial for beginners covers the basics of Rego syntax and using OPA.

Biden’s new AI safety executive order raises a lot of questions for the AI landscape for regulations, development, and cybersecurity. Learn more about the unknowns and our analysis.

Explore the fusion of open source innovation and container security with Chainguard Images.

Series B funding elevates Chainguard’s capabilities in pioneering next-gen software security technologies.

This tutorial will show you how DI works, how to use it, and how it can make your Python projects better.

Unveil the false positive of CVE-2019-3826 and combat phantom menaces with Chainguard’s vigilant security.

We’re excited to announce that Reviewpad is now joining Snyk to help developers code, commit, and stay secure without slowing down.

In this article, you’ll learn about the benefits of conditional rendering, how it differs from conditional routing, and how to implement both in React, Next.js, and Remix.

Experience secure, efficient GitLab operations with 0-CVE on-demand images, fueled by Wolfi OS.

Learn how to find and fix the new “Use of Weak Hash” vulnerability in crypto-js and crypto-es that was reported on October 18, 2023.

Speed up security for AI generated code with a security companion that works alongside generative AI, enabling both efficiency and security at scale.

In this article, we’ll discuss why and how to add Snyk security to Jira and Bitbucket.

Delve into the secrets of silent fixes with ‘CVE-unkown,’ elevating your code’s security with Chainguard.

This article will guide you through the process of securing your JavaScript applications using the Snyk CLI.

In this hands-on article, we’ll review how to leverage SQL query parameterization and stored procedures to prevent injection attacks, as well as some additional security measures that help keep our code safe.

Explore Bazel rules for Chainguard Images, your pathway to secure, effortless image extension.

In this post, I’ll cover how the open source project I created — ctfd-account-hook — evolved to support a long-running, secured HTTP request to notify nearly 4,000 registered participants over email.

We just released a new Snyk Partner Speak Video to showcase Snyk and Slack’s joint integration that enables you to view and use Snyk data on Slack channels.

Chainguard, the safe source for open source, is excited to be at KubeCon Chicago 2023. Learn where we’ll be and how we are securing the software supply chain.

In this post, we’ll discuss encryption and demo how to secure symmetric encryption algorithms in your Java applications.


Unveil ‘junk CVEs’ with Chainguard Images, your ally against disguised vulnerabilities, ensuring a secure codebase this Halloween.

Scaling a risk-based AppSec program involves adapting your security practices to accommodate the growth and evolving needs of your business, while effectively managing and mitigating security risks.

This article reviews how to install and manage different versions of Java on your macOS system to help you simplify this process.

Learn how to find and fix the HTTP/2 rapid reset vulnerability (CVE-2023-44487) that has been designated a High severity vulnerability with a CVSS score of 7.5 (out of 10).

In this article, we’ll provide remediation strategies for the recent curl zero-day vuln.

Learn about Chainguard’s proactive measures against CVE-2023-38545 and CVE-2023-38546 in curl for enhanced security.

Get the latest versions for Java 21 (OpenJDK and JRE), Python 3.12, and Node.js 20 complete with minimal CVEs, SBOMs, signatures, and hardened architecture.

Cybersecurity Ventures predicts the global cost of software supply chain attacks will reach nearly $138 billion by 2031. Learn more by reading the 2023 Software Supply Chain Attack Report.

“Build Horizon” is a practice that imposes a maximum age on build artifacts. Learn more about how it works and see an example in action!

Explore the risks of scanner false negatives, the pitfalls of missing the Bazel package, and how Chainguard Images ensure accurate vulnerability detection.

Open source vulnerability scanner Grype has added support for OpenVEX, making software supply chain security easier. Learn how to implement it today.

At a recent fireside chat, Jared Peterson, SVP of Engineering at SAS, and Ravi Maira, VP of Product Marketing at Snyk, discussed the future of AI for security and development teams.

Chainguard harnesses Grype’s open-source power to ensure minimal CVEs in images, prioritizing user security.

Last month, two Critical WebP vulnerabilities (CVE-2023-4863 and CVE-2023-5129) were discovered. In this post, learn how to identify where you use libwebp and how to remediate the vulnerabilities.

Snyk is proud to offer the first security integration for Compass. The new Snyk App for Compass connects vulnerability data to help teams track critical and high-severity vulnerabilities that put applications at risk.

Explore DEFCON 31 insights on Distroless container security. Delve into RCE vulnerabilities and Chainguard’s robust defense strategies for up-to-date software.

In this pre-announcement of a new High severity curl vulnerability, learn how to gauge the potential impact to your organization and get steps to prepare for the forthcoming patch.

A recent summit meeting convened by the OpenSSF with the White House brought together various US Government departments for a chat about open source security.

The latest Snyk Partner Speak Series video showcases how Snyk and HashiCorp enable development teams to easily build and deploy applications with integrated security at every stage.

Ravi Maira and Randall Degges discussed using AI in AppSec during a LinkedIn live discussion in June 2023. Read on to catch some of the highlights from their talk.

We’re excited to announce that IaC+ is available in early access via Snyk Preview starting October 3rd, 2023.

Unearth a haunting tale of overlooked threats in scanning. Discover how Chainguard Images counteract gaps, ensuring robust defense against CVEs.

In our first modern VS Code extension development blog post, we covered the basics of VS Code development, including the architecture and the various types you can create. This article will help you apply that knowledge by showing you how to create and code your very own VS Code extension.

CVE-2023-4863 vulnerability identified in the WebP library libwebp extends to more than just browsers - Learn how to find and fix this critical vulnerability with Snyk

This blog post will guide you through the best practices for developing with AI securely, focusing on AI-assisted applications, AI-assisted development, and general tips for productive software development with AI.

Explore Wolfi’s journey: A Linux un-distro revolutionizing cloud-native development with agile updates for robust software security.

In this article, we will compare three popular container signing solutions: Sigstore Cosign, Notary v2, and Docker Content Trust (DCT), (a.k.a. Notary v1). You’ll learn about their features, capabilities, and suitability for securing container image supply chains.

Swift action on CVE-2023-4527 in glibc: Discover how Chainguard ensured user security promptly.

In this article, you’ll learn all about NullPointerExceptions in Java, including their causes, consequences, and most importantly, prevention techniques.

Secure your software with Chainguard & Wolfi, now recognized by leading vulnerability scanners.

We’re thrilled that Snyk has been recognized as a Strong Performer in our first year participating in the Forrester Wave™: Static Application Security Testing (SAST) Q3 2023.

Developer-first supply chain security aims to minimize the risk of potential breaches, streamline the development workflow, foster collaboration, and instill a culture of vigilance that resonates across the entire supply chain

Three experts came together at Black Hat Asia 2023 to discuss how leadership can participate in fostering security success.

In this part of the “Modern VS Code Extension Development” series, you’ll discuss various extension types, delve into the typical architecture of VS Code extensions, and learn about some best practices for VS Code extension development.

Your guide to leveraging Dockerfiles with Wolfi-base images for hardened container images.

Discover the world of Capture the Flag (CTF) competitions and why they’re essential for mastering cybersecurity skills. Explore the history, significance, and unique challenges of CTFs that prepare both beginners and professionals for real-world digital threats. Learn how CTFs can transform your problem-solving and critical thinking abilities, setting you apart in the cybersecurity field.

This article will cover what CORS is and some of its use cases, as well as best practices for using CORS and testing the security of your code.

Need support on your FedRAMP journey? Chainguard’s FIPS Images use the OpenSSL 3.0.8 module that is validated by NIST for 140-2.

In this article, you’ll learn more about the various applications of Bean Validation, including how to implement it in Spring Boot, enabling you to effectively utilize it for your own projects.

Pioneering SBOM tools with government and industry allies, Chainguard advances open source security measures.

In this article, we’ll comprehensively explore web cache poisoning attacks and how they work. We’ll also discuss the most effective mitigation strategies to help safeguard our web applications.

Tackle false positive vulnerabilities with Chainguard’s innovative tooling to prioritize genuine threats and secure your software.

Welcome to our cheat sheet covering the OWASP Top 10 for LLMs where we’ll explore the top security risks identified by OWASP.

Fetch the Flag, Snyk’s annual Capture the Flag (CTF) competition, brings together thousands of players around the world to solve CTF challenges, build security skills, and have fun along the way… and we’re bringing it back in 2023!

Discover how Chainguard for OpenTF bridges the open-source community, ensuring secure and efficient container ecosystem transitions.

Node.js, Bun, and Deno: we compare these three popular JavaScript runtimes so you can determine which is the right one for your project.

Chainguard’s proactive approach to HashiCorp license changes: Secure image solution for hassle-free adaptation.

At this year’s AWS re:Invent, Mic McCully, spoke with Jacob Salassi, Director of Product Security at Snowflake. Read on to learn about the practices Jacob and his team established to create a successful application security program.

Explore how Chainguard and Isovalent utilize OpenVEX to enhance vulnerability data handling for improved security.

AI-assisted development helps developers build software more efficiently, learn how to leverage AI to write, test and review your code whilst maintaining security.

This article explains certificate pinning, highlighting its benefits and use cases in Node.js applications.

In honor of International Dog Day, we’ve created a quiz: What kind of (security) dog are you? And while you’re taking it, tell your dog that we say hi and give that good boy or girl a treat on our behalf!

Recorded at AWS re:Invent 2023, learn how Okta uses Snyk to simplify security complexity for Auth0 developers.

This article highlights the top five VS Code extensions to help us write more secure code and maintain security best practices.

In this blog post, we’ll present an in-depth exploration of utilizing JLink to optimize Docker image sizes, enhancing application security and performance.

Chainguard AI Images: Your pathway to a secure ML supply chain with hardened, efficient AI/ML lifecycle solutions.

Automate dependency updates with Mergify and Snyk.

Enhance your Python security! Learn how Chainguard’s new dataset is revolutionizing malware detection in Python environments.

Dive into Chainguard Academy’s new image vulnerability comparisons, shedding light on 306 CVEs for a safer container ecosystem.

In this tutorial, you’ll learn how to write a dependable Dockerfile for PHP applications.

Unveiling upgraded Chainguard Registry: Your hub for secure, efficient container image management.

In this post, we’ll explore GitOps’ core principles, how they enhance application security, and how GitOps’ rapid-change deployment process helps increase efficiency.

Introducing Chainguard Image for Zig: Bridging superior security and seamless Zig application deployment.

We’re happy to announce the open beta availability of Snyk’s new Risk Score!

In this blog, we’ll discuss the benefits and potential security risks posed by AI hallucinations.

Catch up on important updates for Chainguard Images Public Catalog users, fortifying your security framework.

This article discusses Java, why URL encoding and decoding are important, and how to approach it properly.

Dive into fully bootstrapping Go from source in Wolfi, paving the way for secure, independent development.

Snyk partners with GitGuardian to offer more complete security coverage and speaks at the company’s new digital CodeSecDays conference.

On August 8th 2023, the .NET community was made aware that the testing library called Moq exfiltrates developers emails from their development machine, and sends them off to third-party remote servers.

Snyk started gradually rolling out the Jira Security App and has significantly improved the functionality and features available to users. Snyk Security in Jira Cloud has quickly become a breakout leader in security in Jira.

Snyk has been named to the prestigious Forbes Cloud 100 list for the fourth consecutive year, coming in at #19. The full list was unveiled this morning.

As the partnership between Snyk and GitGuardian continues to grow, we’ve collaborated on a new cheat sheet that identifies key security considerations and tools that can help you mitigate risks and protect your code.

Explore the pivotal SSDF Security Self-Attestation Form, a key resource for CISOs to navigate and enhance security compliance.

Let’s discuss the limitations of relying on a single AI model and the pros and cons of today’s most popular models.

This article explores the concept of DOM clobbering and provides strategies for building more secure and robust web applications.

Join the Hacker Summer Camp: A hub for cybersecurity enthusiasts to explore, learn, and collaborate on cutting-edge security strategies.

With the SEC’s adoption of new rules on cybersecurity risk management, strategy, governance, and incident disclosure by public companies, one thing is clear: better definitions are required.

In this post, we’ll discuss how chaos engineering can enhance security in your organization.

Uncover the findings of the Zero CVE Challenge on Official Docker Hub Images, a step towards secure containerization.

Software supply chain security tools provide a range of features to identify and mitigate potential risks and vulnerabilities and play a critical role in safeguarding the integrity and security of the software supply chain.

This tutorial shows you step by step how to securely containerize — or more specifically, “Dockerize” — a PHP application. You’ll also use Snyk, a developer security platform that provides security tools for modern applications to identify and automate vulnerability fixes.

Snyk provides tools to create and scan SBOMs for vulnerabilities, helping organizations meet the requirements laid out by the METI Guide. This blog explores how Snyk can help to comply with the METI’s guidance.

This article will guide you through implementing a TLS connection for your applications on a Kubernetes cluster, providing you with a comprehensive understanding of TLS and its importance in securing your applications and data.

Probe the SBOM format wars: Can ProtoBOM herald a new era of consensus? Chainguard weighs in.

Developers are embracing WebAssembly for its ability to accelerate complex algorithms, enable gaming and multimedia applications, and provide a secure sandbox. But before adopting WebAssembly, it’s crucial to consider its security implications and how to mitigate the risks.

Harness Wolfi-Act’s dynamic GitHub action powered by Wolfi packages for efficient workflows.

In this article, you’ll learn what Kubernetes RBAC is, why you should use it, and how to configure it in your cluster.

Navigate fuzzy CVEs, tarfiles, and untrusted input with Chainguard, paving the way to secure coding practices.

Read Snyk’s 2023 State of Open Source Security report to learn why AI, false positives, and slow security tool adoption remain concerns but faster fixes and supply chain security progress are encouraging signs in open source security.

Elastic and Chainguard unite for enhanced software supply chain security and SLSA assessment.

Uncover the symbiosis of good MLOps and ML supply chain security with Chainguard’s expert insights.

No matter where you are on your journey to becoming secure at scale, here are four best practices you can implement immediately to get you closer to enterprise-level security.

In this post, we’ll cover using Snyk in your CI/CD pipelines to catch security issues quickly and empower your developers to fix them before they ever get to production.

In this post, we’ll look at how AI can improve the software development lifecycle (SDLC) and the pitfalls that can come from blindly applying AI to your existing processes.

In this post, we’ll review common patterns and types of IDOR vulnerabilities and how to protect against them.

This blog will detail deserialization vulnerabilities in Swift that can occur when using the popular APIs, NScoding and NSSecureCoding, and how to prevent it properly.

This article reviews several best practices we can implement to make an attack surface analysis more effective.

In this article, we’ll dive deeper into what XS leaks are and how they occur. Then, we’ll review some hands-on examples of how to prevent them.

Uncover the essence of Redpoint Infrared 100, Chainguard’s step towards nuanced vulnerability scoring.

Let’s look at the top 5 security concerns for IaC and the best practices we can implement to mitigate them.

Uncover Chainguard’s strategic vulnerability remediation, enhancing your software’s security posture.

The Open Container Initiative recently announced a list of major registry changes you can expect to see soon in OCI Image and Distribution Specs v1.1.

In this article, you’ll learn about security risks that can threaten your CI/CD pipeline. You’ll also learn how to build pipelines that are hardened against attack and how to test them to verify their security.

Venture into memory-safe programming languages with Chainguard, boosting your code’s defense against vulnerabilities.

In this hands-on article, we’ll review how to implement secure session management and the best practices for doing so.

TSA strengthens cybersecurity for airports & aircraft. Learn how Chainguard Images helps meet new software development requirements.

Learn about five challenges you might encounter when trying to verify container signatures at deployment time in Kubernetes.

Learn how to reproduce a Chainguard Images build using cosign and apko.

Fortify your CI/CD environments with insights from NSA and DHS CISA guidance, presented by Chainguard.

In this post, we’ll discuss CI/CD pipelines and how they can be configured to integrate security throughout the development process.

Webhooks are a callback integration technique for sending and receiving information, such as event notifications, in close to real-time. In this walkthrough, we’ll implement a GitHub webhook in Node.js that detects when users push code to a repository.

See a 57% reduction in your Pulumi image sizes with more security built in by default and a 97% reduction in CVEs with the new Chainguard Pulumi Image.

In this post, we’ll discuss npm postinstall, recent security events involving it, and how to protect the sensitive data stored shortcuts stored in your keyboard shortcuts from insecure npm package manager defaults.

We’re proud to announce the general availability of Project Collections. Project Collections aims to enable you to create collections of Projects based on the focus you and your teams need, whilst allowing you to perform actions on the Collection.

In this post, we’ll walk you through maximizing IAM security with AWS permissions boundaries and Snyk IaC.

As applications and projects scale, so will the number of secrets you need to keep safe. Learn the best practices and tools to use to secure your secrets.

Learn about the upcoming Chainguard Images catalog changes and the actions required for Public tier users.

In a recent research project, Snyk and Redhunt Labs set out to learn more about the security posture of popular GitHub repositories. Read on to learn more.

Learn more about the best ways and strategies to implement DevSecOps in 4 steps.

Catch the latest updates from Chainguard Academy, including a new design and software security resources for SLSA, SSDF and more.

Learn about the principle of minimalism in engineering, where your default should be the lowest-common denominator of what you actually need.

In this post, we’ll walk you through using SnakeYaml 2.0 to solve the unsafe deserialization vulnerability.

This month, we ran our “Patches of Pride” campaign to celebrate Pride Month adorably! Our Queer@Snyk Resource Group (SRG) members sent photos of their pets in attire that reflects the spirit of Pride.

In this post, we’ll delve into what the Kubernetes Pod Security Standards are, examine how the Pod Security admission controller enforces the standards, and explore use cases for each policy.

Discover how 0-known vulnerability containers from Chainguard Labs could accelerate software delivery to the government.

In this post, Snyker Sherica R. Bryan reflects on the importance of Juneteenth, what it means to be free, and the work required to maintain that freedom.

One way Java security has evolved (or devolved, depending on who you ask) is by removing the SecurityManager. But why is this significant? Is it any real cause for concern? This article will help you answer these questions.

Chainguard CEO Dan Lorenc and Chris Hughes, CISO & Cofounder of Aquia and CISA Fellow discuss the upcoming software self-attestation form.

Today, we’ll recap 5 episodes of TSD with the biggest names in security today and hear what they have to say about security champions and building a security culture.

We’re thrilled to announce that Snyk was named a Leader in The Forrester Wave™: Software Composition Analysis (SCA), Q2 2023 report!

We’re excited to announce Snyk’s integration with Amazon EventBridge to enable secure AppDev at scale.

Snyk’s most recent integration with AWS Security Hub allows security and operations teams to monitor and manage a variety of application security events, like critical vulnerabilities found in a production workload.

The new Secure Software Development Framework (SSDF) from NIST places toolchain inventory management and security front and center.

The latest video in our Snyk Partner Speak Series showcases how Snyk and Dynatrace bring complementary capabilities to different parts of the DevSecOps lifecycle.

Learn how we make Chainguard Images reproducible using build date epoch.

Snyk is excited to announce our intent to acquire Enso, the pioneers of application security posture management (ASPM).


Today, we’re excited to launch a few new features as part of our ongoing efforts in our Software Supply Chain Security solution.

We’re excited to announce Insights, a unique capability providing organizations with code to cloud application intelligence that enables development and security teams to manage their application security posture more effectively by identifying, prioritizing, and fixing those issues posing greater risk!

At this month’s SnykLaunch, we released 5 new features that will make finding, prioritizing, and fixing issues faster and easier.

We just released parlay, a new open source tool that can enrich SBOMs with additional information. In this post, we’ll give you some examples and a guide to getting started.

We’re excited to introduce parlay, Snyk’s new open source tool that enriches SBOMs.

Companies like Capital One, Twilio, and Uber have all suffered from AWS breaches. Learn from their experiences and prevent the next breach from happening to you.

Celebrate 5 transformative years of SBOM work with Chainguard, reflecting on the journey of software bill of materials.

Snyk Security in Jira Cloud is available in open beta in the Atlassian Marketplace, building on our widely adopted native integration in Atlassian’s Bitbucket Cloud.

Join Chainguard and industry leaders in software supply chain security during the inaugural Unpacked virtual conference from Cloudsmith.

This article will provide an in-depth look at a day in the life of an ethical hacker, and explore the various tasks and activities that ethical hackers undertake.

Ethical hacking is used to find potential security issues in computer systems and networks. In this post, we’ll cover a collection of techniques and procedures commonly used by ethical hackers.

Learn how Chainguard engineers created a chain of OpenJDK packages to provide full provenance from pure source code for the entire Java ecosystem in Wolfi.

Learn about the different tool types that ethical hackers are using to find vulnerabilities and our list of the top 10 tools ethical hackers are using today.

In this article, we’ll look at how LDAP injection works, the potential consequences of this type of attack, and the various means of strengthening applications against it.

We’re excited to announce a new Snyk app for Slack that provides notifications within the channels your teams rely on to address security issues in your code, open source dependencies, containers, and cloud infrastructure.

To observe mental health awareness this month, we asked several Snyk employees for wellness tips that may help others. Here are the biggest takeaways from our conversations with them.

Chainguard Labs announces, “Speranza: Usable, privacy-friendly software signing,” to help balance usability and privacy for software signing techniques.

In honor of Asian American Pacific Islander Heritage Month, we want to blend celebration with education on important issues in the AAPI community by amplifying the voices of our Asian@Snyk resource group members.

In this article, we’ll explore eight popular penetration testing tools, their benefits, and their ideal use cases.

Learn how Chainguard Images can you achieve or maintain your FedRAMP compliance authorization with secure-by-default base images.

In this article, you’ll learn more about what a data breach is and how you can prevent data breaches when designing and developing your software.

We’re excited and honored to announce that Gartner has recognized Snyk in the Leaders Quadrant in the 2023 Magic Quadrant for Application Security Testing report.

We built a passwordless container image registry with a focus on security to sustain the foundation for ongoing product growth & feature additions for our users.

We are happy to announce the addition of EPSS (Exploit Prediction Scoring System) to Snyk’s security intelligence for Snyk Open Source and Snyk Container vulnerabilities.

Follow our step by step guide to generating an SBOM for JavaScript and Node.js applications using the Snyk API or CLI tool.

Read the latest announcements in open source software security this spring including SLSA 1.0, Sigstore + npm, OpenVEX had its kickoff meeting, and more!

In this post from Snyk Ambassador, Mohammad-Ali A’râbi, we’ll use GitHub Actions to build Docker images and then scan them for security vulnerabilities.

We’re excited to announce the release of our Snyk Top 10 Code Vulnerabilities Report, covering the most common vulnerability types across seven popular languages.

Chainguard Images boosts support for enterprise development teams with expanded catalog offerings, a dedicated registry, and proactive security notifications.

Learn about Snyk Recharge — an initiative that enables Snykers to take time off simultaneously to ensure we all focus on our mental and physical health.

In a panel hosted by Snyk, we discussed the ins and outs of building an application security program, and how Snyk has helped simplify the process.

We are excited to announce a partnership between Snyk and New York University, Tandon School of Engineering that offers students a unique opportunity to enhance their developer security skills.

Snyk is excited to partner with ServiceNow again to support an upcoming feature in ServiceNow Application Vulnerability Response to secure your applications and its associated software bill of materials (SBOM).

We’re excited to announce the DevSecOps Lifecycle Coverage with Snyk application, which correlates Snyk Container and Dynatrace data and visualization capabilities to create reports.

In this article, we’ll explore XML vulnerabilities and learn how to prevent them from compromising application data.

At our April SnykLaunch event, we debuted our newest capability using AI to provide a fix right in the IDE so a developer can simply click the suggestion and automatically implement the fix in their code. Today, we’re happy to announce that this AI-powered fix functionality is now available in open beta!

We are honored and humbled to announce Snyk has been named to the CNBC 2023 Disruptor 50 List, following our debut on the Disruptor List in 2021 and our listing as a Top Startup for the Enterprise in 2022.

When developers need to handle URLs, we often turn to Java. However, its frequent use motivates attackers to exploit its vulnerabilities. This risk of exploitation is why we must implement URL validation in our JavaScript applications.

We want Snyk’s engineering culture to shape how our software engineers approach problem-solving, innovation, and collaboration. Learn about our values, how we live by them, and how that helps us succeed.

CISA’s draft self-attestation form clarifies the minimum requirements that software developers must meet to comply with OMB Memorandum M-22-18.
![Meet Chainguard at Open Source Summit North America 2023 [May 10 – 12 in Vancouver]!](/article-images/3b62ec0a-bfbf-435b-a0ca-f42dab4aa5e7.webp)
Chainguard will be at OSSummit NA May 8-12 in Vancouver. Check out our talks and sessions and connect to learn about OSS projects like Wolfi, Sigstore and more.

In this post, we review the results of this year’s Big Fix and the impact our participants made.

In honor of May the 4th, we’re featuring a narrative from an Imperial trooper in a faraway galaxy as he reflects on his organization’s worst day and how it could’ve gone differently.

This is a guest post by Alex Bovee, CEO and Co-Founder of ConductorOne, an identity security company.


This article spotlights several HTTP headers that impact security and suggests best practices for leveraging HTTP response headers to secure web applications.

60-day study by Chainguard reveals vulnerability differences in Docker Hub vs. Chainguard Images.

We just released a new Snyk Partner Speak Video to showcase how Snyk and ServiceNow work together to provide a complete view of your application security posture.

In this article, we’ll create a new Java application and validate some example strings to demonstrate how JavaBean Validation works.

Chainguard joins DHS S&T new startup cohort focused on strengthening software supply chain visibility tools.

Creating Docker images can sometimes be a pain. Here are alternatives for crafting containers, like ko, Bazel, Nix, and apko, and their strengths and weaknesses

This supply chain series centers on the lessons learned from OpenSSL and what you need to consider when enhancing your supply chain security. Let’s dive into part two and discuss how to find — and more importantly, fix — vulnerabilities in your supply chain.

Gartner recently predicted that API attacks would become the most frequent vector of attack. This article will explain why API security is essential and which best practices companies can implement to protect their APIs better.

Multi-cloud security is the practice and strategy of securing applications, data, and infrastructure distributed across multiple cloud environments. In this post, we’ll discuss the benefits of multi-cloud and some required security considerations.

In this post, we’ll demonstrate how Snyk Code can help you prevent cross-site scripting (XSS) vulnerabilities in Java.

We’re excited to welcome Beth Shea as Snyk’s first Chief Customer Officer. During a time where we know Snyk’s developer-led vision is more important for the cybersecurity industry than ever before, Beth will be the driving force behind further building a customer-centric culture at every level of the company.

Open source software security takes center stage in the 2023 RSA Trends Report. Learn why it’s a top concern.

This post will discuss lessons from our security experts and the four best practices to cultivate developer security adoption.

In this two part series, we’ll walk through some of the things you need to consider when finding instances of a vulnerability in your software supply chain. Let’s begin by discussing where you’ll need to look for vulnerable libraries, and review some tips and tricks for searching.

Chainguard and the CNCF partnered to conduct security assessments of Argo and Prometheus to ensure open source software projects apply security best practices.

npm launches Sigstore beta for end-to-end package signing, improving developer trust and security.

Wolfi has been accepted into Platform One, U.S. Air Force’s DevSecOps platform. Chainguard Images are now available on Platform One via container repo Iron Bank

To help unlock benefits of the Sigstore policy-controller, Chainguard open sources a policy catalog that can be adopted to improve your supply chain security.

This article demonstrates how to patch deserialization vulnerabilities in Node.js. We’ll create vulnerable code, demonstrate an attack, and then fix the vulnerabilities.

In this article, we’ll show how developer-centric DAST tools can help organizations improve security testing coverage and build more secure applications.

Check out the new Chainguard Image for Prometheus that is minimal in size and contains fewer CVEs than other alternatives.

As we’ve discussed over the past several quarters, we anticipated a tough start to 2023, but we were prepared to accelerate growth in the back half of the year. We now know that the challenging market conditions are likely to persist into early 2024, so we must once again adapt.

In this blog post, we’ll explore what a platform engineer is and highlight some of their challenges that product security teams should be aware of.

Join Chainguard at KubeCon EU in Amsterdam, April 19–21, for groundbreaking insights into cloud-native technologies.

Our new Snyk Parter Speak video series showcases technology partner integrations that extend the Snyk platform to fit into enterprise tools and workflows.

The goal of Distroless is to provide a more secure and efficient way to package and run software in containers by using only essential components.

Snyk’s updates to the Docker Desktop Extension ensure continued compatibility with the newest release of Docker Desktop. The Snyk Docker Desktop Extension enables you to scan your remote or local container images and identify vulnerabilities in them.


To show how to implement IaC security with a specific suite of tools, experts from Snyk, HashiCorp, and Amazon Web Services (AWS) created a new workshop that demonstrates how a security tool, an infrastructure as code solution, and a cloud provider can come together to deliver a seamless experience for developers.

Chainguard’s new OpenSearch image is smaller, more secure, and perfect for container deployments.

The Snyk Container team had this challenge: Given a tag, parse its parts to be able to compare it to other similar tags. It was a fun problem to solve, and we’d love to share how we got to our final solution involving timing out synchronous functions with regex!

What are the biggest threats to your organization’s software supply chain, and what are the best practices to facilitate supply chain security?

Today, we’re thrilled to introduce a new feature of Snyk IaC that enables you to “fix cloud issues in IaC” (infrastructure as code), making Snyk IaC the first solution to secure the cloud through code with remediation paths in IaC.

Today, we want to provide a glimpse at how Snyk currently uses AI and data science, as well as a sneak peek at what’s to come.

We’re excited to announce the Open Beta of C/C++ for Snyk Code and licenses for Snyk Open Source.

Check out the additions to our developer-first security platform, announced in our latest SnykLaunch presentation. Watch the full recording today.

One of the exciting new features discussed at SnykLaunch today was Custom Base Image Recommendations (CBIR). Read on for all the details.

Chainguard Enforce enables policy enforcement using attestations. Learn how to use these principles to create and enforce secure supply chain policies.

A recap of Snyk’s half-day virtual event on security for application workloads running on AWS.

We are excited to introduce our new Snyk Partner Solutions Directory. This new directory, designed to accelerate application engineering projects by promoting secure and efficient software production, comprises technology-driven solutions created by Snyk and our TAPP members.

We are thrilled to announce that Snyk has achieved Red Hat Vulnerability Scanner Certification, making it one of the few security platforms to receive this certification from Red Hat.

See what’s new in Chainguard Academy to help you level up your software supply chain and open source security knowledge.

Snyk’s newest product leaves all other key rotators eating dust.

Find your ideal base image with Chainguard’s insights at GitCommitted, tailored to your project needs.

In this post, we’ll discuss the recent data leaks in the Netherlands and what developers can learn from these security incidents.

Validating Admission Policies are here in Kubernetes 1.26. Read on to learn how they work and what they mean for admission controllers.

New Chainguard Academy tutorial unpacks Cosign the manual way and explores Cosign’s blob signing capabilities.

Last month, Lead Partner Solutions Architect, David Schott, presented a demo on how Snyk works alongside Amazon Web Services (AWS) to identify vulnerabilities at every level of development and infrastructure. Let’s dive right into his presentation and its biggest takeaways.

Chainguard breaks down the benefits of Sigstore’s policy-controller, a Kubernetes admission controller that integrates with Cosign and the Sigstore standard.

This article will demonstrate a mass assignment vulnerability in a Node.js project, how an attacker can exploit it, and ways to protect a web application against it.

We expect privacy and security controls to be in place for the web applications we use every day. This means not only the use of basic security encryption, but also proper security for stored data and secure environments for the development and deployment of applications. For all of these controls to be in place, web application developers should be more engaged in security practices.

Learn about our hardened Chainguard Image for NATS, which is built on Wolfi, our secure by default operating system for containerized workloads.

Chainguard announces its donating the Rekor Search UI project to Sigstore, allowing users to conveniently search entries in the public Rekor transparency log.

In this article, we want to share a broader picture of how the Snyk security team is monitoring and disclosing security incidents concerning malicious packages.

Chainguard believes open source is important and we mean it. Check out how we’ve been involved in OSS Security in the first part of 2023.

In this article, we’ll recap what Techstrong Research found when they polled Snyk’s community of DevOps, cloud native, cybersecurity, and digital transformation readers on SBOMs and supply chain security.

In this post, we’ll highlight the key components of the new National Cybersecurity Strategy, so you can stay informed without getting stuck in the weeds.

New Chainguard Image for Apache Zookeeper is over 50% smaller in size compared to alternatives. Powered by Wolfi, comes with our own JDK, and built from source.

This week marked the 10-year anniversary of Docker. Let’s look back at how much has changed, and hear some stories about what people experienced while moving toward the containerized world we live in today.

We’re excited to announce that we’ve now released language-specific Snyk Top 10 cheat sheets for Java, JavaScript, Go, .NET, PHP, Python, and Ruby.

In this post, we cover the top 10 AWS misconfigurations and how to fix them. Download our AWS security misconfigurations cheat sheet to learn more.

Findings on software supply chain security practice adoption from our joint survey with OpenSSF, Rust, and Eclipse with questions derived from SLSA requirements.

This guide discusses how XSS vulnerabilities originate in Django apps and what you can do to mitigate them. You’ll also learn how to use free security tools to detect and fix XSS vulnerabilities early in development.

Why do we test our code? Find out in this Chainguard post on the benefits of randomized testing and fuzzing practices.

In this playbook for Chief Information Security Officers (CISOs), we explore three tips for how to build a security culture across your organization.

In this article, we’ll look at three popular frameworks — Express.js, NestJS, and Fastify — and evaluate them according to how well they align with the Node.js security best practices.

Chainguard found a vulnerability in GitHub Actions that bypasses allowed Workflow settings by using commits from forked repositories. Read the report.

Whether you’re a developer or simply interested in learning more about security in Java, this post will provide you with information and insights to help keep your Java applications secure.

Run Postgres, now available as a Chainguard Image, as a hardened container image built on Wolfi. Secure Postgres images by default and reduce their size by 90%.

In our latest Snyk in 30 democast, I demonstrated working on an app, starting in an IDE and going all the way to the live app deployed in the cloud. Along the way, I showed how Snyk fits into the tools a real developer might use.

Chainguard’s vision for a ‘Secure by Default’ future: Pioneering strategies to integrate security into the tech fabric.

Cybersecurity hygiene is the process of developing healthy habits to guard you against threats online. Use our checklist to implement best practices.

Check out the top 10 challenges and risks to your AWS security. Follow our best practices to secure your AWS deployments and avoid security mistakes or misconfigurations.

How do today’s security teams overcome challenges and make secure software development practices a reality? Snyk interviewed some of the world’s most innovative security leaders to find out. Let’s dive into their tips for cultivating security adoption within development teams.

Chainguard, GitLab and OSTIF conduct a software supply chain security audit of the open source git project using SLSA levels.

CVE-2023-1065 is a medium severity vulnerability that does not expose the user of the integration to any direct security risk and no user data could be leaked, but it could have resulted in irrelevant data being posted to a Snyk organization — which could in turn obfuscate other, relevant, security issues.

Dive in to apko and learn more about the project; where it’s been in the past year, and where it’s going.

In this article, we’ll look at the pitfalls of worker threads and how they differ from the multithreading implementations in other programming languages.

Unlock advanced messaging capabilities with Chainguard’s RabbitMQ image, designed for robustness and security.

In this post, we’ll cover research conducted by Calum Hutton to try and identify YAML Deserialization issues in open-source projects using Snyk Code.

In this post, we’ll give you some tips and tricks for breaking into the tech industry, and showcase some exciting job opportunities we’ve partnered with other leading tech companies to promote during The Big Fix.

In this post, we’ll cover security concerns of a JavaScript sandbox with the Node.js VM module and how to mitigate them.

As the world becomes more architecturally diverse, we at Chainguard want to make sure our users are armed with the tools they need to remain secure.

In this tutorial, you’ll learn how to build Vue 3 components with Tailwind CSS by creating a responsive article card component.

Learn about OCI, which is inching closer to a v1.1 release which provides official guidance on how to connect things in a registry.

As a senior at Xavier University, I was fortunate enough to work at Snyk as a Social Media Intern during the 2022 Summer Internship Program. The experience provided me with ample time and opportunities to grow as a social media professional and dip my toes into the cybersecurity industry.

We’re excited to announce our collaboration with Dynatrace to enhance observability context even further with security posture information.

In this post, we’ll examine the potential risks from Python’s setattr() function, and discuss ways to prevent Mass Assignment vulnerabilities in your application.

The following think piece, written by Snyk’s Open Source and Open Standards Strategy Director, Daniel Appelquist, examines the origin of the term “supply chain security” and whether it’s a good fit for today’s open source software development process.

The IDC Innovators report profiles Chainguard as one of three companies offering enhanced capabilities for open source software supply chain management.

Love your software? This Valentine’s Day, show your software some love by fixing any lingering security vulnerabilities in both your open (and closed-source) code as part of The Big Fix!

SBOMs could be a lot more useful if the NVD implemented widespread usage of the purl naming scheme, which could reduce the false positive rate by over 50%.

In this post, we’ll discuss how to secure your random algorithms with cryptographically-secure pseudo-random number generators (CSPRNG).

HAProxy Chainguard Image now available: Built on Wolfi, up to 90% smaller, aims for 0-known CVEs, and is built with hardened toolchain, making it memory safe.

We’re excited to announce yet another new door opening in our partnership with Atlassian. The new Snyk integration for Jira Software will bring security and collaboration to Atlassian users at every stage of the development lifecycle.

CloudNativeSecurityCon: Marina Moore & Zack Newman on using Sigstore & The Update Framework TUF to create verification policies to secure software supply chains

Snyk IaC now supports 10+ compliance standards — including CIS Benchmarks for AWS, Azure, and Google Cloud, SOC 2, PCI DSS, ISO 27001, HIPAA, and more.

Today we’re announcing the first step towards this vision with some important changes to the Snyk CLI.

Kubectl added to Chainguard Images catalog. Chainguard kubectl build is 75% smaller than the usual image used & is the only supported image with arm64 support.

Learn four examples of bad security habits that are “so last year” and some better alternatives to adopt in 2023.

Chainguard & BoxBoat, an IBM company, partner to offer enterprises end-to-end security solutions and address security across the software development lifecycle.

VEX needs the industry to come together to build formats that integrate into existing practices. OpenVEX enables organizations to put VEX into practice.

In this post, we will cover three Advanced IntelliJ debugger features that I’ve found to be audience favorites when giving talks on this subject.

Python offers a range of libraries for encrypting and securing network communication. In this article, we will explore two of the most popular — cryptography and Paramiko.

We’re in Seattle next week for CloudNativeSecurityCon NA 2023. Find us at Booth S12 February 1-2 for swag and demos of Chainguard Enforce and Chainguard Images.

In this article, I would like to introduce you to the new Nuxt module that I recently created that should help you build more secure Nuxt applications.

GuessBOMs, SBOMs generated by reverse-engineering software artifacts, have severe limitations. The optimal point for generating complete SBOMs is at build time.

Thanks to our ISRG partnership, we are enabling memory-safe TLS by introducing Rustls to Wolfi, which now sets the standard for memory safety in distributions.

We’re excited to announce a new partnership to bring Snyk security insights to ServiceNow workflows. The integration between Snyk Open Source and ServiceNow Application Vulnerability Response, the first of its kind, gives application security teams visibility into vulnerabilities in open source dependencies to provide a complete view of an organization’s application security posture.

Go 1.20 now available in Wolfi and Chainguard Images. New Go 1.20 security features include experimental secure-by-default functionality for tar file handling.

GitHub Container Registry (GHCR) had an information leak bug, where names of private repos were exposed. Here’s the background on how it was reported and fixed.

Chainguard Images now contains Python 3.11.1, giving developers minimal, hardened base images that still contain everything needed to build and run Python apps.

Software supply chain: understand the relationship between software distributors and software consumers and what FOSS maintainers are or are not responsible for.

Do SBOMs meet the US government’s minimum elements standards? We created a dataset to methodically examine SBOM quality and check NTIA conformance to find out.

The Vulnerability Exploitability eXchange (VEX) helps efficiently assess vulnerabilities. If used with SBOMs, VEX improves overall security of a supply chain.

Snyk Learn just released a free learning path for the OWASP Top 10, a widely-recognized list of the most critical security risks facing web applications.

Chainguard Images adds Bazel to supported images portfolio. The Chainguard Bazel Image is built with the minimum required package set, keeping it minimal.

With the new year, we’re excited to announce the second wave of new companies joining our Snyk Technology Alliance Partner Program (TAPP), which enables application and developer-focused software companies to build, integrate, and go-to-market as quickly as possible with Snyk solutions.

In 2022, Snyk continued to expand on our developer-centric approach to software security, by adding several key enhancements to the existing solutions — let’s focus on three key capabilities introduced in the past year that can improve your software supply chain security.

Open Source Program Offices (OPSO) are popping up all over, in recognition of the facts on the ground: open source software (and I would argue open standards as well) plays an enormous role in building and maintaining the software that increasingly drives the planet.

Snyk IaC security takes a developer-first, application-centric approach to finding and fixing vulnerabilities in cloud infrastructure from the time infrastructure is defined in code, through to when resources are running in the cloud.

Learn about key AppSec investments Snyk made in 2022 to improve performance, add new ecosystems, and support the enterprise.

Open Policy Agent (OPA) adopts Chainguard Images to secure systems from vulnerabilities. Others like Tailscale and Vietnam-based VPBank are also following suit.

Looking under the Wolfi hood. Chainguard Images now multi-platform with added 64-bit Arm (arm64) support and continues to expand set of available architectures.

Now that it’s a new year, let’s take a look back at some of the amazing 2022 Snyk developer security platform highlights.

On January 4, CircleCI, an automated CI/CD pipeline setup tool, reported a security incident in their product by sharing an advisory.Learn about this incident, next steps, and about supply chain security.

Keyless software signing uses ephemeral keys (not cryptographic) to sign and verify software. Get started using Chainguard Enforce Signing, powered by Sigstore.

In this post, we’ll discuss several steps that your teams can take to create AWS efficiencies and streamline cloud security.

Chainguard Images adds Redis 7 to supported databases. The Redis image is based on glibc and built on Wolfi so it is minimal, secure-by-default, and up-to-date.

Chainguard is one of the top contributors to several key initiatives run by the OpenSSF including Sigstore and the Supply Chain Levels for Software Artifacts.

Take an in-depth look at HTTP Strict Transport Security (HSTS) headers to discover how they affect web security and why we should use them on Node.js. Then, learn how to enable HSTS inside a Node.js server.

New Ruby 3.2 build added to Wolfi and Chainguard Images. Better WASM support and yjit compiler improvements. Fewer 3P dependencies; easier to package and patch.

In this article, we’ll build a secure API gateway from scratch using only Node.js and a couple of open source packages. All you need is basic knowledge of your terminal, Node.js version 14 or later, and JavaScript.

Learn about the developer security tooling from Snyk that will help you level up your skills to find and fix security vulnerabilities in the code you write and the dependencies you use so you can build secure applications.

Get Adrian Mouat’s takeaways from his presentation at CloudNativeSecurityCon, including ideas for how the industry can build secure container images.

Read all about the important cloud security updates from re:Invent 2022.

This article will explore Kubernetes NetworkPolicy by creating an example network policy and examining its core parameters. Then, we’ll look at some common NetworkPolicy use cases and learn how to monitor them using kubectl. Finally, we’ll discover how to implement Container Network Interface (CNI) using third-party Kubernetes extensions.

Software bill of materials (SBOMs) are important tools to make software supply chain security easier? But are they effective? We did some research to find out.

Learn about Chainguard Labs, Chainguard’s research division, with a focus on software development and vulnerability research.

On December 8th, Clinton Herget and Simon Maple from Snyk discussed various topics with Corey Quinn, Chief Cloud Economist at The Duckbill Group. Their conversation included humorous takes on the long coffee lines at AWS re:Invent and Quinn’s provocative statement that “SBOMs are a fantasy.” The blog will highlight key points from their discussion, but those interested in the full dialogue can watch the panel for all of Quinn’s insights and commentary.

In the spirit of the holiday season, we’re laying out an application security “battle plan” for keeping out attackers — à la Kevin McAllister.

Congratulations to Cloud Security Podcast for being given DMA’s “Podcast of the Year” award!

Learn about the recently discovered Spring Security authorization bypass (CVE-2022-31692) and learn steps to mitigate.

In our latest Snyk in 30, we showcased Snyk Open Source security with a focus on our integration with Atlassian Bitbucket Cloud.

See Chainguard’s predictions for software security in 2023, including software bill of materials (SBOMs), software signatures, reduced security debt, and more.

Here are the major announcements at re:Invent that got our attention and some of the things Snyk was up to in Vegas.

SnakeYaml, a YAML 1.1 parser and emitter for Java, has been reported as vulnerable to CVE-2022-1471, a deserialization vulnerability that can lead to arbitrary code execution.

In those post, we look at Azure Bicep security fundamentals around inputs, outputs, secrets, Key Vault, and more.

Learn more about the archiving of the Gorilla Web Toolkit, a toolkit used to write HTTP-based Go applications. This presented two major security challenges.

During a discussion at AWS re:Invent 2022, Neiman Marcus Cyber Security Architect Omar Peerzada described how his team used Snyk to adopt a developer-first security strategy.

An overview of the benefits offered by Snyk’s newly enhanced reporting capabilities.

Catch up on all the things we discussed in our Christmas Twitter Spaces, including VEX, SBOMs, and secure containers.

In this tutorial, you’ll use the Fastify framework in a Node.js application to set up file uploading. You’ll learn how file uploads work on a typical server and how to handle file uploads on a Fastify server application.

Using TypeScript with React provides several advantages in application-building, including the option of simpler React components and better JavaScript XML (JSX) support for static type validation. Learn to stay safe with TypeScript security best practices.

Learn more about software supply chain security, and how the topic goes beyond famous attacks like Solarwinds and Log4J.

In this post we’ll discuss some of the adverse effects organizations experience from tool sprawl, and the shift towards security tool consolidation.

In this tutorial, we’ll walk through the process of verifying a Mastodon account, in order to gain a verification check mark and provide some legitimacy to the account.

There are many lessons to learn from leaked Android platform signing keys. See how they apply to secure software distribution.

In this article, we’ll dig into three tips that can make your developer security education program better and ensure that you’re reaping all the advantages of the golden era of application security.

Learn how to mitigate two new medium severity (CVSSv3 5.8) vulnerabilities in the Snyk CLI and IDE plugins: CVE-2022-24441 and CVE-2022-22984. Although hard to exploit, these vulnerabilities can lead to arbitrary code execution on the host system. Learn about these risks and how to stay safe.

We are excited to announce the general availability of a new Asia-Pacific (APAC) datacenter in Sydney, Australia, helping local organizations secure their applications with Snyk.

Discover ways to protect the machine learning supply chain, and why it is extremely important to do so.

Learn about the different AWS security considerations you should make when migrating to Amazon Web Services.

Gamification is a great way to make security exciting for developers. Learn about a few ways guests from The Secure Developer have gamified security.

What is Vulnerability Exploitability eXchange (VEX)? And can you trust it? We answer those questions and more in this blog.

This hands-on article discusses the environment variables available within GitHub Actions and when we should use them.

In this article, we’ll walk through setup, write, and test your first doctest in Python — giving you all the information you need to get started.

In this post, we’ll learn how to install and use JUnit 5 to write unit tests for some Java code. We’ll use the VSCode integrated development environment (IDE) for writing our tests and Java 11 with Maven to execute them.

This article demonstrates how to configure TLS/SSL certificates with the Ingress controller in Kubernetes. We’ll set up an NGINX Ingress controller, create a self-signed SSL/TLS certificate, create the necessary rules to link the SSL/TLS certificate to the controller, and hook it up to a Kubernetes sample app service.

In this article, you’ll learn what dependency injection is, when you should use it, and what popular JavaScript frameworks it’s implemented in.

Code signing is an important component of keeping your software secure. In this article, we discuss 7 reasons implementing Sigstore is worth your time.

In this article, we’ll explore best practices for Kubernetes Secret management. Check out our Kubernetes security article for more security risks and best practices.

In this post, we’ll recap Walz’s experience using Snyk to detect and remediate Log4Shell at Atlassian, as well as Silverman’s more in-depth talk about the impact of Log4Shell.

In this article, we’ll talk about some opportunities for community participationa few ways you can give back to your community while also developing your career.

Learn best practices for building modern access control for cloud applications, covering RBAC, security and compliace, IAM, access control layers, reducing attack surface area, and more.

We asked a few of the AWS re:Invent conference veterans on our team to share some words of wisdom in preparation for this year’s expo. Read on to see their tips on surviving Vegas, and making the most of your time at AWS re:Invent 2022.

Learn how to solve the Potty Training challenge from Snyk’s 2022 Fetch the Flag CTF competition.

A discussion of the fifth of five fundamentals of cloud security: measuring what matters. (Part five in a five-part series.)

Learn how to solve the Disposable Message challenge from Snyk’s 2022 Fetch the Flag CTF competition.

Learn how to solve the git-refs challenge from Snyk’s 2022 Fetch the Flag CTF competition.

Learn how to solve the Not So Smart Fridge challenge from Snyk’s 2022 Fetch the Flag CTF competition.

Learn how to solve the Roadrunner challenge from Snyk’s 2022 Fetch the Flag CTF competition.

Learn how to solve the Logster challenge from Snyk’s 2022 Fetch the Flag CTF competition.

Learn how to solve the Juggalo Central challenge from Snyk’s 2022 Fetch the Flag CTF competition.

Learn how to solve the Treasure Trove challenge from Snyk’s 2022 Fetch the Flag CTF competition.

Learn how to solve the Pay Attention challenge from Snyk’s 2022 Fetch the Flag CTF competition.

Learn how to solve the Moongoose challenge from Snyk’s 2022 Fetch the Flag CTF competition.

In this article, we’ll discuss what TLS is, what benefits it provides, and why you need it. Then we’ll walk through implementingTLS in Java.

Today we’re announcing the open beta of Snyk’s new reporting features, available to Snyk customers now. The new reporting capabilities provide improved visibility into application security risks.

Learn how to solve the File Explorer challenge from Snyk’s 2022 Fetch the Flag CTF competition.

Learn how to solve the Containers are ACE challenge from Snyk’s 2022 Fetch the Flag CTF competition.

What is “software dark matter”? And how popular is it in open source containers? Chainguard Labs finds out.

At SnykLaunch, our product leaders unveiled the latest additions to Snyk’s suite of developer-first products — including the announcement of Snyk Cloud. In this SnykLaunch recap, we’ll catch you up on the new and exciting features coming to Snyk.

In this post, I intend to unveil npm security practices and tooling available for you as a JavaScript developer (TypeScript developers are welcome too).

Author’s from Accenture and Google Cloud recently released a white paper, which details the current state of ransomware and solutions to address this growing problem. This article will provide an overview of the key points from the white paper.

Find out what a day in the life of a CISO and co-founder is like with this discussion between Chris Hughes (CIS & Co-Founder) of Aquia and Vandana Verma of Snyk.

In this article, we’ll explore the challenges of corrupted URLs, how they can damage your applications, and ways to tackle the problem.

A discussion of the fourth of five fundamentals of cloud security: aligning and automating with policy as code. (Part four in a five-part series.)

OpenSSL has released two high severity vulnerabilities — CVE-2022-3602 and CVE-2022-3786 — related to buffer overrun.

If you’ve been looking for an effective way to establish a Ruby on Rails Docker setup for your local development environment, then this post is for you. It’s a continuation of our previous article on how to install Ruby in a macOS for local development.

The increasing popularity of cloud technology has created a growing need for effective cloud security. Instead of simply expanding the size of security teams, organizations can improve their cloud security posture using policy as code.

Discover how Chainguard mitigated OpenSSL vulnerabilities to protect itself and its customers’ software supply chains.

Learn how to easily create a software bill of materials (SBOM) for your Java applications in Maven and Gradle.

Here are the top five AWS misconfigurations you should be aware of to prevent potential security gaps in your infrastructure.

Learn about the top five Docker vulnerabilities or CVEs development teams should watch out for, and how to remediate them.

An upcoming release of OpenSSL, scheduled for November 1, 2022, addresses a critical security vulnerability. This post explains how to detect the vulnerability in your code and describes mitigation steps.

To understand how fuzzing tools improve security, let’s explore the benefits of fuzzing, discuss some use cases for fuzzing, and review an example of how fuzzing would work in a real-world test.

Testing code is the first step to making it secure. One of the best ways to do this is to use unit tests, ensuring that each of the smaller functions within an app behave as they should — especially when the app receives edge-case or invalid inputs, or inputs that are potentially harmful.

Let’s explore the most common DNS attacks and review mitigation strategies to avoid them.

Multi-threading can offer substantial performance improvements for CPU-bound workflows by allowing arbitrary work to be performed in parallel. Although Node.js doesn’t offer real multi-threading, you can create something similar with the worker threads module. This article will explain what it does, and show how to use it in a few real-world applications.

Snyk is excited to announce a new, native integration with Atlassian Bitbucket Cloud. This new release improves Snyk’s functionality within Bitbucket Cloud, making installation faster, and easier to implement.

Curious about what Sigstore is, and what its components are? In this blog, we dive in to Fulcio, OIDC, Rekor, and more!

Sigstore has announced its general availability! See how you can try it and what it can do for your software supply chain.

Below is a message that was sent out to all Snyk employees today from Snyk CEO Peter McKay.

Learn to leverage the different options that the Snyk platform provides to send all your application security vulnerabilities found by Snyk directly to your New Relic observability platform

A discussion of the third of five fundamentals of cloud security: empowering your developers. (Part three in a five-part series.)

In this article, you’ll learn more about mock API servers, the tools you can use to create mock APIs, how you can use them to speed up your development and testing, and how to set up a simple mock server.

Check out Chainguard’s booth at KubeCon North America in Detroit from October 24-28. Chainguard offers zero CVE container images for many open source projects.

In this post, Snyk Ambassador Keith McDuffee will lead us through a discussion on how site reliability engineers (SREs) bring order to the chaos of development.

Learn about CVE-2022-42889, and how it really isn’t the next Log4Shell level vulnerability.

Learn about the 2022 Snyk Customer Value Study. The goal of this study was to understand our customers’ most important value drivers, discover how they think about their return on investment and find out how much quantifiable benefit they’ve realized by leveraging the Snyk platform.

Implement our list of 8 best practices to improve your overall AWS Security posture. Secure your AWS deployments to prevent data breaches.

Google donated ko to the CNCF, and Chainguard supports it. Hear why from two of the three core maintainers of the project.

As a developer, you probably rely on open source every day. But have you considered going a step further and contributing to open source projects as well? This post will cover the major reasons why you might choose to contribute to — instead of simply using — open source projects.

In this article, we’ll explore TLS and how to use Python to check for a website’s TLS certificate validity. Then, we’ll walk through the steps for adding TLS to your Python application on Linux.

In this article you will learn the basics of how to write end-to-end tests with Playwright, running tests from GitHub Actions, deploying to Netlify, and preserving debug traces.

A discussion of the second of five fundamentals of cloud security: prevention and secure design. (Part two in a five-part series.)

You spoke up and we listened (and we double-checked in our data). Find out why we removed Snyk Code’s HardcodedEmail rule for Ruby and what this means for you.

Chainguard conducted interviews to discover how administrators and contributors of PyPI feel about tools being the cure to malicious software packages.

How to use Snyk for application security in GitOps, focusing on the popular Kubernetes-native Argo CD tool.

In this hands-on article, we’ll explore how fast and easy it is to perform quick linting checks in Python using Pylint — one of the most popular linting tools. We’ll also see how linting code can help us adhere to the PEP8 code style guide.

In this article, I will explain how DTOs are used in modern Java applications, ways your application can benefit, and how Java DTOs can help you be more secure by preventing accidental data leaks.

A post from Ambassador Andres Haro, describing lessons learned from a recent security incident and how you can protect your application from similar attacks.

At SnykWeek New York, we heard lots of conversation about cloud security. The day also included a peek at our product roadmap and a fun interactive hacking session. We love #snykweek.

In this article, we’ll look at using Google Ko to build container images without Dockerfiles, SBOMs, and integrating with Kubernetes.

Red teams vs blue teams — we’ve heard the terms, but what does it all mean? This post will cover the basics of red, blue, and purple teams, and explain how they work together to enhance an organization’s security posture.

A discussion of the first of five fundamentals of cloud security: knowing your environment. (Part one in a five-part series.)

We’re announcing support for proxy authentication in Snyk CLI for Windows.

A recap of Snyk’s 2022 International Dog Day campaign, including a look at some of the custom dog sketches for our sweepstakes winners.

This week, at HashiConf 2022, Snyk was recognized as a HashiCorp Partner of the Year for Collaboration Technology.

The CNSA Suite is a suite of algorithms for encryption, signing, and integrity checking that will be required for all national security systems. What’s in it?

We’re excited to announce that Snyk was named a Customers’ Choice in the 2022 Gartner Peer Insights ‘Voice of the Customer’: Application Security Testing. This distinction is based on meeting or exceeding overall rating, user interest, and adoption.

As a Snyk user, we want to let you know about a medium severity vulnerability (CVSSv3 6.4) in our CLI that you should be aware of: CVE-2022-40764.

What is VEX, the Vulnerability Exploit eXchange, and how does it work? In this blog, we apply VEX to some basic operations.

A look at the advantages of empowering developers with the right tools and processes for mastering cloud security.

Snyk’s Liran Tal discusses strategies for choosing the best node.js Docker image.

We’re excited to announce that a new Snyk UI is coming soon! Starting October 12th, 2022 we’ll be rolling out some exciting new user interface changes for the Snyk application. Read on for a sneak peek.

Today, we’re excited to announce the expansion of our partnership with HashiCorp, Snyk IaC for Terraform Enterprise. With validation from HashiCorp, Snyk continues to deliver contextual security and compliance configuration guidance instantly while writing code in Terraform.

On September 15, Snyk kick off our partnership with 01Founders by hosting 30 learners at our London office. The event featured a panel discussion, capture the flag challenge, and networking opportunities with dozens of Snykers. Read on for a recap of the day!

Discover how software supply chain security impacts DevOps practices and outcomes in the 2022 State of DevOps Report.

In this tutorial, you’ll learn how to properly install Ruby on Mac, and properly install Ruby on MacHow to setup a local development environment that doesn’t conflict with brew or an existing macOS Ruby version.

Gone are the days of waiting until the end of a development lifecycle to execute security testing and implement security best practices.

SPDX 2.3 introduces new features and enhancements for improved software supply chain transparency and security. Stay ahead with the latest SBOM standard.

Learn about the importance of implementing rigorous disaster recovery testing, and best practices for ensuring disaster recovery testing.

The OWASP API Security Project released in 2019 is still vital in 2022. Learn how API’s are commonly exploited, and how to protect your API’s.

Learn about 5 importance of implementing rigorous disaster recovery testing, and methodologies used for ensuring disaster recovery testing.

Discover Wolfi, Chainguard’s Linux distro designed to make building secure, vulnerability-free software easier for all.

Software serves as the foundation of the digital technology we all depend on, yet it’s being exploited more than ever before. See how Chainguard Academy helps.

For the past few days, I’ve been getting a lot of messages asking about my experience at this year’s Black Hat USA. So in this post, I’ll be recapping the conference to give you an inside look at what was presented and provide some helpful perspective.

It is our great pleasure to officially welcome on board our latest Snyk Ambassadors! As you may already know, Snyk ambassadors are security champions on a mission to help developers build more secure applications.

This cheat sheet provides guidance on getting started with your compliance program, and information about controls that align with specific compliance standards.

Are you looking for best practices on how to build Node.js Docker images for your web applications? Then you’ve come to the right place! This cheat sheet provides production-grade guidelines for building optimized and secure Node.js Docker images.

his blog will discuss how common SMTP Injection vulnerabilities can exist in libraries and applications, and provide tips for finding and remediating them quickly.

Spotify’s engineering team recently published a blog discussing their use of Snyk to maintain security testing in the SDLC. The following is a recap of that blog written by Engineering Manager, Edina Muminovic.

In the 2022 cloud security report, Snyk outlines the biggest challenges to teams trying to secure their cloud native applications and some key strategies for achieving cloud security.

We recently sat down with Onna’s executives to discuss how they’ve used Snyk and Sysdig to secure the SDLC while saving time and money. Take a look below for some of the highlights from this fascinating conversation.

This article explores how ConfigMaps works, how to use ConfigMaps safely, and some use cases where we need to turn to other, more secure data storage.

Chainguard analyzes the top 5 takeaways from the NSA, CISA, and ODNI developer guidelines for securing your software supply chain.

This guide will walk you through integrating C/C++ security scanning within pipelines to get vulnerability information and remediation advice directly to developers.

In this article, we’ll look at the security benefits offered by API gateways and explore the best practices to follow while taking extra steps to keep our API gateways secure.

XML is a human-readable text format used to transport and store structured data. In this article, we’ll walk through some different ways to find and fix XML entity vulnerabilities.

Chainguard breaks down four clear boardroom benefits of a secure software supply chain.

We’re excited to announce that as we’ve published our Eclipse plugin, including the new Snyk Language Server Protocol.

There’s a week and bit in Vegas where most of the infosec and secure community come together for talks, workshops and training hosted by Blackhat, Defcon, Bsides Vegas, and The Diana Initiative — welcome to Hacker Summer Camp.

Developer-first security was invented at Snyk. Which is why the NSA, CISA, and ODNI’s recent publication piqued our interest. While the information was good, we felt it missed the mark on being a practical guide for developers. So, here are our suggestions on how to improve guides that address developers directly.

Liran Tal discusses real-world incidents that demonstrate how even the mightiest of open source projects can be defeated. He also addresses the continuous struggles of open source software sustainability, maintainer burnout, and how these things affect the greater developer community.

Vulnerability scanners have limitations. Learn how to proactively identify software supply chain risks beyond what your scanner can detect.

Hack The Box (HTB) is a platform that gamifies cybersecurity training. In this article, we’ll discuss how Snyk can help you solve Hack the Box and other CTF challenges.

In this post, we’ll cove some best practices for containerizing .NET applications — including those on the 4.x version framework. We’ll also discuss using small images and image scanning, to reduce security risks and remove unnecessary components from our containers.

In this article you’ll learn, how to build a Slack bot integration, create Triggers and Actions workflows in Zapier to post messages to a Slack channel, use a Reddit API key to access posts using native Reddit Access Tokens and Refresh Tokens, and more.

We are excited to share that now, when using the snyk container test/monitor commands, we will scan for application vulnerabilities by default.

This article explores the implications of container isolation and outlines best practices for security and methodology for Linux, sandbox, and virtualized containers.

In this article, we’ll explore how Kubernetes (K8s) supports PoLP by implementing role-based access control.

In this article, I’ll give you some advice and best practices for dealing with Java dependencies in your project.

This article will demonstrate how to use gRPC via a client and server-like communication between two Node.js applications. We’ll also highlight some safety measures when using gRPC as the communication mechanism in your services.

Secure your software supply chain with Chainguard’s expert guide & tools: Learn how to protect your software from build to deployment.

This article discusses managing secrets in Docker, exploring best practices and potential risks with their use.

Today we’re announcing a new container security cheat sheet and report — created in collaboration with our partner Sysdig. In this post, we’ll outline tips to help you successfully navigate the challenges of container security with a focus on three core principles.

Step-by-step best practices for building a Java container and running it inside a Docker image.

In this blog post, we aim to demonstrate common scenarios where, even when using a safe API, it’s possible to execute arbitrary commands through injection argument options.

While the transition from Drupal 9 to Drupal 10 is expected to be smooth, we can’t ignore security. So, in this article, we’ll explore 5 ways to secure Drupal 10.

This article explores how open source code introduces vulnerabilities into the software supply chain. It also highlights how you can identify vulnerabilities in C++ open source security using automated vulnerability scanners.

It’s no secret that we’re fans of dogs here at Snyk. In fact, you’ve probably noticed our logo is a Doberman. In celebration of International Dog Day, we’d like to tell you how Patch became our mascot, and how to get involved with Snyk’s #DevelopersBestFriend campaign.

This article explores how to use asserts safely and what causes them to be unsafe. By the end of this article, you’ll know how to use assert most optimally without inadvertently opening yourself up to security issues.

Vulnerability-free software is a myth. Learn how to proactively mitigate risks with Chainguard’s security-focused approach to software development.

In this post, we’ll look at the security blindspots of lockfile injection that a Ruby gem might expose via its Gemfile.lock.

This article explores the top five C++ security concerns that affect code development and offers advice on mitigating them.

Learn about the newly discovered PyPi malware that attempts to steal credential and payment information from Discord and Roblox users.

Learn how to secure container images and workloads across Kubernetes clusters with Snyk.

Learn more about the top Python code review tools for Developers that will improve the speed and efficiency, and security of software throughout your SDLC.

Snyk has officially launched Snyk Training, a free online resource to help developers and security teams learn how to implement, configure, and use Snyk on their own.

Snyk’s Senior Developer Advocate, Brian Vermeer, discusses how reverse shell attacks work and how you can protect yourself from them.

On behalf of the entire Snyk community, I am excited to share that Forbes has named Snyk to the Forbes Cloud 100 list for the third consecutive year, coming in at #20 — which is 19 spots higher than last year!

If you’re looking to catch up on what happened at this years AWS re:Inforce, this is the blog for you. There were many important announcements were this year, including some exciting updates on the cloud security front. In this post, we’ll quickly review the goals of the conference and who should attend, before diving into the keynote highlights, software updates, and helpful resources.

Ruby has an entire ecosystem of third-party open source libraries which it refers to as gems, or sometimes Ruby gems. In this article, I’ll run through the concepts and tooling that make up the Ruby dependencies ecosystem, and answer some of the common questions Ruby developers have.

Too often, developers assume that container isolation means containers are inherently secure. This incorrect assumption leads to complacency. In this post, we’ll explore some best practices for securing PHP containers and avoiding common pitfalls.

Building presentations can be a tedious process. Thankfully, there’s a better and more programmatic way of building your slides — Slidev, the open source project that allows you to code your presentations.

Secure your software supply chain with Chainguard’s guide to NIST SSDF and SLSA implementation. Learn how to protect your software from vulnerabilities.

Terraform is an infrastructure as code (IaC) solution that enables DevOps teams to deploy on-premise or public cloud infrastructure components. Today, we’ll discuss some common strategies for testing effectively in Terraform.

We’re excited to announce the Snyk Developer Challenge! This event gives conference attendees a chance to flex their security skills by fixing vulnerabilities to earn points on the leaderboard. At the end of the conference, the two highest scoring participants will be crowned the winners and receive a special prize.

We’re thrilled to welcome Manoj Nair joins Snyk today as our new Chief Product Officer. In this pivotal phase of Snyk’s growth, Manoj will lead our global product team, setting our comprehensive product roadmap and strategy in both the short and long-term.

A buffer overflow attack is the exploitation of a buffer overflow vulnerability, typically by a malicious actor who wants to gain access or information. In this post, we’ll explain how a buffer overflow occurs and show you how to protect your C++ code from these attacks.

Chainguard explains how Sigstore helps CISOs strengthen software security with integrity checks, easy developer adoption, and risk-informed software consumption.

To celebrate Disability Pride Month, Snyk’s Director of Inclusion, Equity, and Diversity, Ashley Ladd (she/her), sat down with Alex Fallon (they/them) to discuss what Disability Pride means to them, how able-bodied people can be better allies and advocates for the Disabled community, inspirational figures, helpful resources, and so much more.

We are excited to announce that the Cloud Security Podcast is now powered by Snyk!

Adopting a new platform can seem intimidating, but with Snyk it doesn’t have to be. We have three tips to help you roll out Snyk, and have a seamless and successful first 30 days across your business or enterprise.

Snyk’s Senior Product Marketing Manager, Frank Fischer, recently hosted a webinar about the value in using a developer security platform to secure code, dependencies, containers, and infrastructure as code (IaC). In this blog post, we’ll highlight some of the key insights from the presentation.

Secure your software factory with melange and apko, the open-source, reproducible, and declarative tools for building OCI images from Chainguard.

Snyk recently partnered with the Linux Foundation to produce a report focusing on the state of security in the OSS space. Following the report’s publication, experts from Snyk held a webinar with the Linux Foundation to discuss some of the key insights, read on for a recap.

C++ has become a pivotal part of the modern day tech industry. As with any widely adopted or user based development, it’s important to ensure that elements of security have been integrated throughout the application. So, let’s look at some security tips to keep in mind when building with C++.

Snyk’s Chief Architect, Josh Stella, recently hosted a webinar about cloud security. During this talk, he discussed the missing story in every cloud breach: the tale of how, when, and where attackers operate in the cloud. He also revealed a methodology for securing cloud resources against modern cloud attacks.

Discover essential strategies for securing your container images and infrastructure. This best practices guide explains why container security matters and outlines five key steps to increase developer security

We’ve created this checklist of React security best practices to help you and your team find and fix security issues in your React applications.

Log4j serves as a wake-up call for the industry. Strengthen your software supply chain security with Chainguard’s expert solutions.

Simon Maple from Snyk and Kalpesh Dharwadkar from Pinterest discuss using Snyk’s developer-friendly tools to integrate good security practices into the software development workflow.

Discover how minimal container images enhance software security and streamline your development process with Chainguard Images.

Discover how dependency trees of popular programming languages are growing and the implications for software supply chain security.

We ask why high school and college computer science programs are lacking content on cybersecurity.

Chainguard applauds PyPI’s mandatory 2FA for critical projects, a step towards securing the Python software supply chain.

In this post, we’ll explore CVE-2022-33980, the Apache Commons configuration RCE vulnerability. However, we want to make it clear that there’s no need for panic. This is not Log4Shell all over again. This is simple configuration manipulation.

Achieve immutable container image tags with Sigstore’s Rekor, ensuring transparency and tamper-evident logging for enhanced security.

Webhooks are one of the best ways to transfer information about occasional events from one system to another. In contrast to methods like HTTP polling, webhooks are triggered by events. In this blog, we’ll cover the most effective practices for securing webhooks so we can share data between applications without creating a large attack surface.

The article discusses the concept of bi-directional communication in web applications, specifically through the use of the WebSocket protocol. Unlike the traditional method where the client requests data from the server and then closes the connection, WebSocket allows the server to actively push updates to the client. The focus of the article is on how to build a secure WebSocket server using Python and JavaScript, providing a guide for developers interested in this communication method.

Earlier today, we informed the Snyk team of important recent organizational updates to better serve our customers and improve operational efficiency in order to support our continued growth. In the spirit of transparency to our customers, investors and partners, we are also sharing this internal memo below.

As Pride Month 2022 wraps up, we want to take a moment to highlight and reflect on of the events and activities Snyk hosted in celebration of Pride.

We’re pleased to announce Snyk’s new role-based access management capabilities, providing admins with greater flexibility in managing Snyk access in your organization!

Snyk has announced the general availability of a new EU region in Frankfurt, enhancing its commitment to enable development and security teams to innovate quickly while maintaining security. This expansion aims to support EU-based organizations in securing their applications with Snyk while also ensuring compliance with data residency requirements. The move underscores Snyk’s ongoing dedication to meeting the needs of its users in the EU.

At Snyk, we believe that every person should have the right to make a decision about their own reproductive health. As citizens, parents and leaders, we feel we have the responsibility to take a stand and fight back.

GitHub Actions has made it easier than ever to build a secure continuous integration and continuous delivery (CI/CD) pipeline for your GitHub projects. And by integrating Snyk into your GitHub CI/CD, you can automate security scanning as part of your build cycle prior to production.

For application security, the shift left strategy is something that every enterprise is embracing today, which essentially means putting the security controls in earlier stages of development. While most tools can only solve some of the problems, Snyk does it all — making it my preferred tool for shifting left.

Snyk Ambassador Tales Casagrande shares tips for improving container safety with Snyk.

Secure your software supply chain with Sigstore! Enroll in our free course, taught by Chainguard experts, and learn how to implement this powerful new standard.

We’re proud to present the 2022 State of Open Source Security report, a joint collaboration between Snyk and the Linux Foundation

Secure your Git commits with keyless signing using Gitsign and GitHub Actions. Learn how to seamlessly integrate Sigstore’s powerful security features.

This Sunday, June 19th, marks Father’s Day in many countries around the world. To celebrate this day, we’d like to highlight some of our amazing Snyk dads and the special moments they shared in our #fun-goodkids internal Slack channel. Take a look at these adorable kiddos! Happy Father’s Day to all of our Snyk dads, and to everyone else who celebrates!

Juneteenth, or freedom day, is one of bittersweet celebrations. The day, June 19th 1865, marks the day federal troops arrived in Galveston, Texas, to free the remaining enslaved people in the United States. Today we take a moment to honor and celebrate those who came before us and carry on their mission for true equality.

Chainguard at KubeCon EU 2022: Catch up on our talks about Kubernetes, Sigstore, Tekton, and more – secure your software supply chain with Chainguard.

Whether you identify as cisgender or fall somewhere under the gender-nonconforming umbrella, disclosing your pronouns early and often makes everyone’s lives easier. So, in honor of Pride Month, let’s discuss why pronouns are important, the benefits of disclosing them, and what to do if you make a mistake.

Base image version squatting: a significant security risk increasing vulnerabilities in containerized applications. Regular updates are crucial.

The cloud has enabled organizations to build and deploy applications faster than ever, but security has become more complex. In this post, we’ll discuss the need to bring application security and cloud security together to deliver more secure cloud native applications.

Kubernetes provides a powerful platform for container orchestration, but it’s essential to implement additional security measures to protect your applications. Explore key strategies to enhance the runtime security of your Kubernetes clusters, including network policies, role-based access control, policy admission control, secrets management, audit logs, and ephemeral containers.

Today, we’d like to share a story about our recent collaboration with the CISPA Helmholtz Center for Information Security, and walk through a few of the vulnerabilities we found together.

In this post, we’ll discuss Open Policy Agent (OPA) and its rule language, Rego, highlighting how we can use them to write a simple policy for a payroll microservice.

Chainguard secures $50M Series A to revolutionize software supply chain security with new, secure container base images.

A step-by-step guide to adopting Sigstore for signing code commits, build artifacts, and container images, securing your software supply chain.

In honor of Mental Health Awareness Month, Tim Leroy, Senior Solutions Engineer based in London, shares how he coped with the tragic loss of his father a few months ago. He discusses tools he used to cope, how he balanced his mental health struggles while working full-time, and gives advice to others who may be struggling with a similar loss.

In honor of Asian American and Pacific Islander Heritage Month, we sat down with Sarah Gibb and Dipti Salopek to learn about their cultures and family roots, and how their heritage impacts them on both a professional and personal level.

Managing multiple SBOMs: Strategies for consolidating and utilizing multiple SBOMs to gain a comprehensive view of software components and dependencies.

During SnykWeek Boston, Simon Maple (Field CTO, Snyk) led a panel discussion about developer adoption of application security. Read on to dive deeper into these illuminating insights around organizing security teams, setting security goals, empowering developers, improving compliance, and much more.

Snyk recently discovered overt 200 malicious packages in the npm registry. While we acknowledge that vulnerability fatigue is an issue for developers, this article is not about the typical case of typosquatting or random malicious package. This article shares the findings of targeted attacks aimed at businesses and corporations that Snyk was able to detect and share the insights.

SnykWeek was a success! We came, we secured, and we crowned a Best Hacker in Boston! We also talked about developer security, and heard success stories from Boston-based customers Datto, Kyruus, and Manulife.

When Log4Shell hit in mid-December 2021, LiveRamp had just completed its POC (proof of concept) trial with Snyk. While LiveRamp’s main motivation for deploying Snyk was to secure its CI/CD pipeline, Snyk was able to discover and remediate this major zero-day exploit.


Cybersecurity standards’ dirty secret: overemphasis on individual company security, neglecting collaborative efforts and open-source software integrity.

We sat down with Saar Kuriel, a Senior Software Engineer, based in Tel Aviv, to learn more about the exciting projects he’s working on as part of the Snyk Code team. We also discussed his career path, project management techniques, technical challenges he’s overcome, and his future goals.

Our very own GuyPo (Snyk Founder and CTO) discussed the importance of automation with several industry-leading technologists on The Secure Developer podcast. We’ll learn more about these guests and their insights as we examine security automation’s vital role in DevOps, scaling, and risk management.

Comprehensive guide to software supply chain security with curated resources and insights, covering build systems, open-source dependencies, and more.

Chainguard calls for software industry standardization on Sigstore and government support, pledging resources to the OpenSSF’s public infrastructure.

Small container image size doesn’t guarantee security. Focus on minimizing underlying components for a truly secure software supply chain.

In this SDR series, we get to know an SDR and an SDR manager in each of our three core regions: EMEA, North America, and APJ. In EMEA, we have SDR teams based in London and Tel Aviv. In this blog post, Jonathan Chetrit and Paula Kanikuru share what it’s like to be a part of our SDR team in EMEA!

Snyk is excited to announce the addition of Adi Sharabani as our new Chief Technology Officer (CTO).

Snyk Infrastructure as Code (Snyk IaC) now detects all types of infrastructure drift and reports them as Terraform resources, so developers gain complete visibility and remediate early.

Congratulations to Courtney Broadwell, Cyndi Doyle, Anna Hester, Kristina Onyon and Jill Wilkins for being recognized as 2022 CRN Women of the Channel

Snyk Code is turning one! We’ve hit so many milestones in the last 12 months, and today we invite you to look back, celebrate, and peer into the future of code security with us.

Motherhood is a beautiful and ongoing learning experience. But what about being a working mom? Today, I had the opportunity to speak with two super moms at Snyk, Noa Korem and Amanda Parks, about how they felt returning to work after maternity leave.

SurveyMonkey taks with Snyk about standardizing tools and getting developers more involved with security work at growing organizations.

In this SDR Series, we get to know an SDR and an SDR manager in each of our three core regions: EMEA, North America, and APJ. In North America, we have SDR teams based in Boston and Denver. In this blog post, Joe MacInnis and Ally Sirois share what it’s like to be a part of our SDR team in North America!

In our mission to make Terraform Cloud workflows more streamlined and secure, we’re excited to announce our new native integration into HashiCorp Terraform Cloud.

Earlier in the year, over 500 malicious packages were released into the npm ecosystem to create dependency confusion. Let’s look at some ways to help protect applications from dependency injection.

You might think of Star Wars as a movie reserved for geeks, but what if I told you that there are deep life lessons that can be applied to developer security practices? Get your lightsaber ready and prepare to dive into JavaScript security!

To celebrate May the 4th Day, we decided to release a special Snyk virtual background and show you how to create your own epic video scenes using an open source project.

Learn best practices and use cases for ignoring vulnerabilities in Snyk using the Snyk CLI, the Snyk UI, the Snyk API, and the Snyk Policy file.

Explore ways to build Docker images in a Kubernetes cluster for CI/CD processes. We’ll also discuss some advantages and disadvantages of using these methods.

Snyk’s strategic alliance with StackHawk brings modern approaches to developer-centric application security to provide a holistic, scalable approach to securing the SDLC in development.

Once in a while we encounter a truly malicious package that has a purpose, means, and is production-ready — this is a story about one found in npm: gxm-reference-web-auth-server.

Which industries use C++ to build their software, and what security challenges are they facing?

In this post, we’ll discuss why developers include native C/C++ extensions in their high-level language projects. Then, we’ll use Python and the PyPI registry to detect hidden C-related vulnerabilities in higher-level language projects and reveal how low-level vulnerabilities can impact higher-level code.

The 2022 Container Security Trends report examines the latest issues and challenges in cloud-native and container security.

Snyk has launched the Technology Alliance Partner Program (TAPP) aimed at helping application and developer-focused software companies quickly build, integrate, and market solutions using Snyk’s offerings. This initiative is designed to empower partners to develop new solutions that address significant security challenges in today’s digital landscape, enhancing overall security measures through collaboration and technology integration.

Software composition analysis (SCA) tools are used for finding vulnerabilities in open source packages & secure your code. Use these best practices as a guide when using SCA tools.

In APJ, we have SDR teams based in Singapore, Australia, and Japan. In this blog post, Gabriel Quek and Lea Chng share what it’s like to be a part of our SDR team in APJ!

Open source software (OSS) simplifies software development, which is one of the reasons why more than 90% of organizations utilize open source components in their applications.

Snyk recently open sourced our faker-security Python package to help anyone working with security data. In this blog post, we’ll briefly go over what this Python package is and how to use it.

Admission controllers intercept API requests before they pass to the API server and can prohibit or modify them. This applies to most types of Kubernetes requests.

Our own Steve Kinman and Adrian Guevara discussed the challenges hyper growth organizations face in implementing code security. During the discussion, Guevara described WillowTree’s security best practices and how he selected the right developer tool.

In honor of Earth Day and in celebration of our growing community of Snykers, Snyk will be planting a tree for each new Snyker hired in 2022.

Sigstore isn’t affected by the psychic signature vulnerability in Java, as it uses Go cryptography libraries and rejects signatures in its Rekor transparency log

Not all SBOMs are created equal: understand the differences and choose the right one for your software supply chain security.

A discussion of best practices for securing PHP Laravel, including framework configuration, preventing SQL injection attacks, managing cookies and sessions management.

This article will teach you how to safely use Python’s built-in pickle library to maintain persistence within complex data structures.

OpenSSF initiatives to enhance software repository security, safeguarding the integrity of open source software and mitigating supply chain risks.

Learn how the rule maintenance features of Snyk Code help developers and security professionals protect their application.

Following the addition of C/C++ security scanning to Snyk Open Source, we discuss some common C/C++ vulnerabilities and ways to mitigate them.

Customers discuss how they used Snyk tools to automate elements of their software development process.

Learn how you can improve your GraphQL security using Snyk Code static analysis to find common and more complex GraphQL vulnerabilities.

Embrace ephemerality for enhanced software security: Minimize attack surfaces by ensuring temporary access and resources.

You’ve heard of Spring4Shell, now learn about similar exploits for Glassfish and Payara that leverage the same issue in Spring, but with a different payload.

Explore React Native security challenges that developers encounter when developing mobile apps,including authentication protocols, and dependency vulnerabilities.

Snyk notifications can be powerful when they enable you to learn about a new vulnerability, license issue, or fix an issue in your projects on the same day we find it. Learn how to make them work for you.

Announcing the general availability of unmanaged C/C++ security scanning in Snyk Open Source, enabling developers to find and fix known security vulnerabilities.

Snyk is excited to be a Strategic Sponsor for Atlassian Team ‘22, April 5–7 in Las Vegas. We aim to expand conversations and collaboration around cloud security among the ever-growing Atlassian + Snyk user base.

An introduction to Open Container Initiative (OCI) reference types. This includes runtime specs, image specs, and distribution specs.

Learn how directory traversal vulnerabilities work on web servers written on C/C++, as well as how to prevent them, including arbitrary file read & write and the zip slip vulnerability.

Snyk’s newest product takes application security to a new level.

The open-roll vulnerabilty shows why you should never click unexpected links!

Alert: Faxios has been breached by the LaughTilYouCry ransomware, which has flooded the hard drives of users with horrible puns and dad jokes.

On March 30, 2022, a critical remote code execution (RCE) vulnerability was found in the Spring Framework. This vulnerability is another example of why securing the software supply chain is important to open source.

YOLO levels: a satirical take on software supply chain insecurity, highlighting the importance of robust security measures like SLSA.

In honor of International Transgender Day of Visibility, Martin McKeay, Snyk’s Sr. Editorial Research Manager, sits down with his daughter to discuss what their experiences were together when she first came out as transgender a few years ago.

Spring4Shell or SpringShell is a credible RCE vulnerability in spring-beans package, which is part of Spring Core. This is a key enabler of the inversion of control (IoC) capabilities of Spring. This is often referred to as dependency injection.

The official event may be over, but The Big Fix community is active as ever. Today, I’ll show you how to find a project with the Snyk Vulnerability Database, so you can join the movement making the internet more secure.

In this article, we’ll learn how to secure GraphQL APIs by building a simple Node.js application using Fastify and GraphQL.

Achieve zero security debt for container images with Chainguard’s “quiet” base images, featuring minimal vulnerabilities and built-in security features.

So say hello and connect with our Snyk Ambassadors! They share a wealth of cybersecurity knowledge and are also ? really ? lovely ? people ? in general!

Learn how to best hash passwords in Java applications using secure password hashing algorithms.

Learn about the White House cybersecurity recommendations and how Snyk can help satisfy the best practices within.

Learn how Snyk IaC helps developers to discover cloud resources that are not under infrastructure as code (IaC) control (unmanaged resources), or that have drifted from their expected state (managed resources).

In this article, we’ll create a sample Go application to demonstrate best practices when using Docker for containerizing Go applications.

Key takeaways from Kelsey Hightower’s Twitter Space on Sigstore: why signing and verifying software is crucial, and how Sigstore provides the tools to achieve it

At Snyk, we’d like to help the community reach a consensus on how to approach the various protestware springing into existence, and help differentiate between the different types.

A major RCE vulnerability has been identified in PHP library dompdf. Code can be loaded into an application and then remotely executed whilst a PDF is being generated.

Effective immediately, Snyk will cease from doing business in Russia and Belarus in accordance with new export control provisions by the United States.

Sigstore simplifies compliance with NIST SSDF recommendations by automating software signing and verification for a more secure supply chain.

Learn about the principles of infrastructure drift detection, the different kinds of drift and why it happens, and tools to help detect drift with a terraform example.

SLSA: Your shield against software supply chain attacks, ensuring software integrity and preventing vulnerabilities.

An SBOM is an inventory of all of the software components you utilize in your applications, made up of third-party open source libraries, vendor provided packages, and first-party artifacts

Enhance software supply chain security with SLSA, a framework for ensuring the integrity of software artifacts and preventing attacks.

Learn how to protect your containerized applications from from the “Dirty Pipe” Linux vulnerability (CVE-2022-0847), as well as how the exploit works. CVE-2022-0847 was created detailing a flaw in the Linux kernel that can be exploited allowing any process to modify files regardless of their permission settings or ownership.

Learn what infrastructure drift is, the causes of drift, and tips for managing drift — whether you’re a solo developer or a large organization.

A virtual CISO is a part-time or remote security practitioner or provider who offers their time and expertise to an organization on a temporary or ongoing basis.

Given the ongoing dark days in Ukraine, I’d like to use this post as a chance to shine a light on some of the amazing open source projects and technological initiatives made by Ukrainian maintainers, developers and passionate tech entrepreneurs.

Take a deep dive into the container security vulnerability world and then learn how Snyk can help.

In honor of International Women’s Day, we sat down with some members of SnykHer — Snyk’s employee resource group for those who identify as women and allies — to learn about what this year’s theme of #BreakTheBias means to them.

We’re excited to announce that the team at TopCoat is joining Snyk.

Container maintenance best practices to avoid hidden security debt and ensure the long-term security of your software.

We’re excited to announce infrastructure as code (IaC) and container security are joining code and open source dependency security in the Snyk free plugin for JetBrains IDEs.

Read our best practices cheat sheet to help you make the most of the integration between Snyk and Bitbucket.

In this blog post, we’re going to take a look at how you can secure your cloud infrastructure to be PCI compliant.

Key takeaways and insights from NIST 800-218, the Secure Software Development Framework, to help organizations mitigate software vulnerabilities.

Learn how Developers can take advantage of penetration testing tools and techniques to find and fix vulnerabilities in their software.

Learn more about the importance of Container Monitoring to maintain security across your container deployments.

Knative joins CNCF, boosting software security through open governance, wider adoption, and community-driven improvements.

DeveloperSteve provides a recap of a DevSecCon discussion around when to incorporate securtiy practices into the development process.

Chainguard joins the Open Source Security Foundation (OpenSSF) to collaborate on enhancing open-source software security.

A focus on attacks in the Node.js ecosystem via the yarn and npm package managers, examining how configuration abuse and hidden characters can lead to RCE.

Introducing apko, a tool for building minimal, secure, and reproducible “distroless” container images from Alpine Linux, enhancing software supply chain security

During our Big Fix-a-Thon earlier today, we announced that we’ve taken two initial actions as a company in direct response to the unfolding crisis in Ukraine.

In honor of Black History Month, we sat down with three members of Black@Snyk, our employee resource group for Black employees and allies, to learn more about their personal stories.

The Adobe patch for CVE-2022-24086 wasn’t enough to mitigate the code. This led to a new CVE-2022-24087 being raised and a second patch going into production.

Transitioning from SDLC to SSDF: Learn about the new Secure Software Development Framework and how it enhances software security practices.

Snyk is proud to launch a new Global Service Provider program designed to give leading solution providers the resources they need to bring our developer-first tools and methodologies into their services and support customers on their DevSecOps journey.

Even a non-technical person (like me) could be part of The Big Fix, and actively contribute to this global effort to make the internet a safer place.

Join us for an epic 24-hour livestream on February 25th to celebrate The Big Fix 2022, featuring expert guests from around the world.

SnykCon 2021 gave us insights on how developers have shifted the industry and forged a new and improved approach to software development.

Snyk’s developerSteve shares insight on understanding and fixing the CVE-2022-24086 Magento Ecommerce vulneratbility.

We’re excited to announce that Snyk has acquired Fugue. Combining the platforms of Snyk and Fugue enables us to offer security resources extending from code through cloud configurations.

Generate automatic SBOMs with ko to enhance software supply chain security for Go applications.

Use the Snyk Vulnerability database to help you find an opportunity to make an open source contribution to The Big Fix!

Snyk has partnered with Sysdig to build a combined solution that addresses security across the DevOps process, from code to Kubernetes cluster.

Build and run Sigstore locally to easily sign and verify container images without external dependencies.

I conducted research based upon existing Python vulnerabilities and identified a common software pattern between them. This led to the discovery of a stored command injection vulnerability in Celery.

A look at Kubernetes operators and their implications for security, outlining potential security risks, discussing how to use operators with security in mind ,and examining how the right operators can lead to a more secure environment.
![Automating Terraform security in Scalr deployments with Regula [Tutorial]](/article-images/1a7e39b4-bae9-427d-bc13-b8b49ff007ea.webp)
Regula enables cloud teams to evaluate Terraform, CloudFormation, Azure Resource Manager, and Kubernetes Infrastructure-as-Code (IaC) for security and compliance violations prior to deployment. Regula is an open source implementation of Rego, the query language used by the Open Policy Agent (OPA) project.

SAST and SCA are better when you use them together. Secure your code and dependencies at the same time with Snyk.

Learn about the Argo CD vulnerability (CVE-2022-24348), as well as the larger implications regarding securing yourself against the kind of supply chain attack this vulnerability could have caused.

Learn more about the unique requirements for microservices security architecture to keep your systems and applications secure.

Keyless signing with Tekton on Amazon EKS simplifies software signing and enhances security in your Kubernetes pipelines.

Join the thousands of developers already participating in The Big Fix, a global event recognizing the developers, DevOps folks, and security practitioners making their applications safer with Snyk.

In this blog post, we’ll walk through the process of using Pulumi to create all that is required to configure the Kubernetes integration in Snyk Container.

In this post, we’ll take a look at the requirements of PCI compliance, as well as how the use of static application security testing (SAST) and software composition analysis (SCA) tools can help you meet them more easily.

Keyless signing with Tekton on AKS simplifies and secures the software signing process in Kubernetes environments.

Today, we’re pleased to announce that Karyn Smith has joined Snyk as our new Chief Legal Officer.

Unlock the benefits of package signing to enhance software security and trust throughout the development lifecycle.

Check out this handy infographic to learn more about the Log4Shell timeline, how much time and money our customers have saved by using Snyk, and what some of those customers have said about their experience.

Learn about insightful talks from AB Inbev and Manulife at SnykCon 2021 about risk management and measuring key risk indicators for enterprise security.

Verify container image authenticity in AWS ECS with Cosign for improved security and trust in your deployment process.

Who among us doesn’t love Wordle? No one, that’s who! It’s gotten to the point that the NY Times announced they are purchasing the original Wordle from its author. There have been a bunch of copy-cats, both in app and web-app form. And, some of these have been up to no good!

Citi uses Sigstore and Tekton to build a secure software factory, reducing vulnerabilities and ensuring fast, reliable software.

Learn how Snyk is shifting left during API development, as well as the processes and tools we are using to create our API-first platform.

The Pwnkit vulnerability (CVE-2021-4034) disclosed in Jan 2022 has existed since 2009, but can now be exploited in the wild. Secure your projects with Snyk.

Last year’s SnykCon provided a wealth of AppSec tips and best practices. In this post, we look at two talks on the process of building and maintaining a culture of secure development in your organization.

A chief information security officer (CISO) has a lot on their shoulders to ensure an organization is secure. And for someone new to the role, the challenge is even more significant.

After a successful public beta program, PHP security support in Snyk Code is now GA.

Learn about a recent Stranger Danger live hack where Simon Maple, Field CTO at Snyk, Eric Smalling, Senior Developer Advocate at Snyk, and Micah Silverman, Director of DevSecOps Acceleration discussed the Log4Shell vulnerability and demonstrated how an exploit could work.

We’re excited to announce that both Kathleen Murphy and Zach Nelson have joined the Snyk Board of Directors effective as of January 1, 2022.

Join us in congratulating Josh Dolitsky as he is elected to OCI’s Technical Oversight Board to build collaboration across the OCI projects and Working Groups.

In this post, we’ll recap Kasper Nissen’s SnykCon 2021 talk about how his security team at Lunar was able to shift security left while building a cloud native bank.

Learn how the Open Policy Agent (OPA) and its Rego rule language can be used to help streamline your policy as code (PaC) efforts in applications and containers.

Snyk Code supports Microsoft Visual Studio so you can check your code quality and code security without leaving your IDE.

Having a team that’s focused on functionality and security is critical to successful software development. To that end, a secure SDLC is important because it prioritizes the security of software and helps make sure malicious actors do not target your application.

Learn more about the top 8 Java code review tools that will improve the speed and efficiency of software development, and protect security throughout your SDLC.

One of the best ways to improve the quality and security of software is to implement a formal process for manual code reviews.

Discover how SBOMs (Software Bill of Materials) enhance software security. Learn to identify vulnerabilities, track components, and manage risks effectively.

My new year’s resolution for 2022 is: Don’t expose confidential information while I hack my applications during demos or presentations.

On the year end episode of The Secure Developer, Guy sat down with Snyk Field CTO Simon Maple to discuss the themes, advice, and future expectations that appeared in this year’s episodes.

In this post, we will take a look at the history of URLs, explore possible sources of URL parser confusion, run through an exploit POC, and then provide recommendations for keeping yourself safe from URL confusion based attacks.

We are thrilled to announce that Samantha Wessels has joined the Snyk rocketship as our new Vice President, EMEA Sales.

Snyk issued a Denial of Service security vulnerability for colors@1.4.1, following this vulnerable code. We highly recommend you revert to colors@1.4.0, and pin your dependencies’ versions to avoid blind upgrades of the offending version. We also recommend you migrate to a different package.

Earlier this week, the FTC issued a warning to companies regarding the Log4j vulnerability. Given the rampant exploitation of the recently discovered vulnerabilities in this ubiquitous open source logging package, it’s encouraging to see the agency take this rare step, beginning to form a firm stance on software supply chain security.

Secure your AWS CodePipeline with cosign image signing. Learn how to integrate image verification and signature enforcement into your CI/CD workflow.

As we start to plan for SnykCon 2022, we’re once again reflecting on the interesting and inspiring customer stories we first heard back in October. Our customers are at the heart of Snyk’s success as each day, it’s these people and organizations that drive our mission to empower every software developer in the world to develop fast while staying secure.

Did you take part in Fetch the Flag this year? The inaugural SnykCon CTF featured a fan favorite challenge: TopLang. Learn how we approached creating it and how you can solve it.

Learn more about five of our developer security resolutions for 2022.

Here’s a recap of our latest Log4Shell webinar about mitigating the Log4j vulnerability.

Learn about the native integration of Snyk directly in Bitbucket and how it simplifies securing your DevSecOps pipeline.
![Checking Terraform IaC security in CI/CD with Regula and Bitbucket Pipelines [Tutorial]](/article-images/f78dd7b0-e4a1-4cd7-b345-54cf6d4bad8e.webp)
Regula enables teams to evaluate Terraform for security and compliance violations in CI/CD prior to deployment.

This new CVE-2021-44832 security vulnerability is affecting versions up to 2.17.0, which was previously thought to be fixed. This vulnerability is similar in nature to CVE-2021-4104 which affected the 1.x branch of Log4j.

The truth of the matter is this: open source is never going to be perfect (nothing is!). It’s up to us (as community members) to leave things better than we found them, and help improve the state of open source.

Just days away from 2022, we’d like to reflect and recap on the progress Snyk Infrastructure as Code has achieved over the year on the path to becoming the leading developer-first IaC solution on the market.

As we approach the end of 2021, we’re taking a look back at the big new capabilities in each of Snyk’s products, and in this post we’re going to focus on Snyk Container.

With detailed remediation guidance at every stage of the software development lifecycle (SDLC), Snyk Code revolutionizes static application security testing (SAST).

Let’s take a look at three key areas where Snyk Open Source delivered new capabilities: integrations, ecosystem support, and making fixes easier!

Due to the recently discovered Log4Shell vulnerability, and to support the tremendous effort being mounted by the community to address it, we are happy to announce that we are increasing the free test limit in Snyk Open Source!

Automated code reviews use analytical methods to compare new code with defined guidelines. This surfaces vulnerabilities much faster than manual code reviews.

Overnight, it was disclosed by Apache that Log4j version 2.16 is also vulnerable by way of a Denial of Service attack with the impact being a full application crash, the severity for this is classified as High (7.5).

Announcing a new Snyk CLI command (snyk log4shell) to find affected Log4j libraries that were not disclosed in the manifest file, forked, or repackaged.

It has been discovered that Log4j version 2.15.0 is still susceptible to arbitrary code execution (CVE-2021-45046) in certain circumstances. Upgrade to 2.16.0.

Learn about the general points of principle that we use to help guide our security thinking and decision making here at Snyk.

Kubernetes achieves SLSA security framework compliance! Learn how this enhances software supply chain security for cloud-native applications.

In this post, we’ll give an explanation of Log4Shell for non-developers and an overview of the Log4Shell vulnerability for non-Java developers.

This Log4Shell remediation cheat sheet summarizes the main fixes and recommendations being used to limit exposure to the vulnerability and to reduce the risk of this vulnerability being exploited in production systems.

The Snyk platform works seamlessly with GKE Autopilot: a revolution in managed Kubernetes. Customers can quickly get started securing workloads on GKE Autopilot with Snyk Container’s Kubernetes integration and can leverage Snyk CLI with Google Cloud Build as well as integrations with Google Container Registry, Google Artifact Registry, and one of the several Snyk Git repository SCM integrations.

Learn more about the massive impact of Log4Shell, the recently disclosed Log4j vulnerability. Learn how far spread it is, how it affects supply chain security, how to prioritize your response, and how to fix it quickly.

See how easy (and fast) it is to find and automatically fix Log4Shell with Snyk.

A new critical vulnerability was disclosed for log4j, a very popular Java logging framework from the Apache foundation. All current versions of log4j2 up to 2.14.1 are vulnerable. You can remediate this vulnerability by updating to version 2.17.1 or later.

With modern tooling like Snyk and Harness, you can find, fix, and remediate through a CI/CD pipeline and mitigate the risk to the business without affecting your ability to release software quickly.

Learn how CodeCov handled the responsible disclosure of their breach to their userbase in 2021.

We’re happy to announce the open beta of C/C++ security support in Snyk Open Source, enabling development and security teams to find and fix known security vulnerabilities in their C/C++ open source code and libraries!

Chainguard announces seed funding and launches Chainguard Services to help organizations address software supply chain attacks and insider risks.

Learn how Jackson ObjectMapper deserialization vulnerabilities work and how to make sure you are not affected by them.

Secure your GitHub Actions workflows with keyless signing. Enhance security, eliminate key management hassle, and simplify your software supply chain.

We are very excited to announce that Snyk has achieved AWS Security Competency status, further validating our commitment to security excellence in partnering with AWS!

We’re pleased to announce new functionality within the Snyk Visual Studio Code extension, making it easier for developers to find and fix vulnerabilities and license issues in their open source dependencies!

At Snyk, we are deeply invested in career progression and offer our teams tools, skills, and development opportunities necessary to enable our Snykers to become future leaders. One of the places we’ve seen our values in action is through our Snyk SDR program.

Debunk common Sigstore misconceptions and discover its true potential for revolutionizing software supply chain security.


Learn to use Snyk Code to find and fix Trojan Source in your source code.

We’re pleased to announce improved support for .NET applications in Snyk Open Source, allowing developers to fix vulnerabilities in .NET dependencies with the help of actionable advice and automated pull requests!

In this post, we’ll see how to maintain the health and hygiene of projects and repositories we are no longer working on, with a focus on Java security.

Hypergrowth companies face a number of challenges related to development and application security. Read on to learn how to overcome them by empowering developers.

Explore Fulcio, the open-source certificate authority for Sigstore. Understand how it issues and manages signing certificates for secure software supply chains.

In this post, we’ll attend to those concerns and take a look at some 6 best practices when containerizing Python applications with Docker.

Given the massive demand for and popularity of Azure Resource Manager (ARM), we are excited to announce you can now use Snyk Infrastructure as Code to scan ARM JSON files against our comprehensive set of security rules in the Snyk CLI.

We’re very excited to say that this week Snyk Infrastructure as Code (IaC) was named the winner of the cloud security category for the 2021 CRN Tech Innovator award.

Learn how to detect and prevent the Trojan Source vulnerability in your JavaScript ecosystem. This attack relies on reviewers confusing the obfuscated malicious source code with comments.

Snyk’s Priority Scores are more than just a number. Learn about the thinking process behind the score as well as give you some practical tips on how to use it optimally to prioritize your vulnerabilities.

Learn about Datto’s nearly painless adoption of developer-first security and how it offers a model nearly any company can follow at a time when developing safe software with speed has never been more critical.

Cloud misconfigurations can lead to breaches and security failures — especially when the vulnerability is related to Identity and Access Management (IAM).

Learn about a new extension to dependency confusion which has its premise on npm’s package aliasing capabilities.

We’re currently moving the “issues” tab of Snyk reports over to Elasticsearch. Read what we learned about in terms of analyzers, tokenizers, and search in the process.

Learn about Docker labels (“annotations” in the OCI Image Specification) what they are, some standardized uses as well as some practices you can use to enhance your container security posture.

Learn about common type confusions scenarios where input sanitisation and validation can be bypassed by providing an unexpected input type. We’ll also provide remediation examples or suggestions for open source maintainers who are looking to patch these kinds of input validation bypasses.

Streamline Kubernetes security with keyless signing. Secure your software supply chain without managing long-lived keys.

Learn how MongoDB built a successful security champions program and how they were able to encourage a mindset shift to embrace, rather than avoid, application security.

Security misconfigurations can have a huge impact on your application’s security. Read more on what security misconfigurations are and how to prevent them.

We are thrilled to welcome the team at CloudSkiff to Snyk! Learn why we’re excited about the addition of this fantastic group of people to Snyk, and our plans for the future of Snyk Infrastructure as Code (Snyk IaC), as well as our commitment to keeping driftctl open source.

We’re happy to announce the addition of Snyk Code support for Swift and Salesforce’s Apex, as well as API and GraphQL security.

Secure Kubernetes clusters on Amazon EKS with cosigned. Learn how to verify container image signatures and enforce security policies for a trusted environment.

Snyk is excited to announce today a new strategic partnership with the team at Hdiv Security!

Welcome to our first Security Horror Story of October. Steel yourself for this spooky tale of accidentally exposed PII! Halloween month just got scarier!

Recently, Java 17 — the new LTS version — was released. Learn how the new Java 17 features impact this problem, and can we prevent deserialization vulnerabilities better using these features.

Snyk is establishing itself as the preferred choice for companies aiming to integrate continuous security into their software development workflows. Their developer-centric tools and top-tier security intelligence facilitate the identification and resolution of security vulnerabilities throughout the software stack, including open source, containers, application code, and infrastructure as code. This comprehensive approach supports businesses in maintaining security during development.

Learn about the technologies that make Snyk Code so cutting edge, as well as how Snyk not only gives back to the open source community, but also how it promotes and works with the academic community in the field of static program analysis.

We are excited to announce the appointment of Sanjay Poonen to the Snyk Board of Directors!

We’re excited to share that Snyk has joined the Linux Foundation’s expanded support of the Open Source Security Foundation (OpenSSF) as a premier member.

Learn how to secure your S3 bucket configurations and the access to them with Snyk Infrastructure as Code and Solvo

Read some of the highlights and key takeaways from our “security champions” roundtable discussion with Dun & Bradstreet and Shutterstock.

Snyk Code now offers Go security scanning in beta. Learn more about this beta feature and how it can keep vulnerabilities out of your Go projects.

Organizations keep suffering their own cloud configuration errors. Here we lay out actionable steps they can take to prevent them.

I’m excited to announce that Dino DiMarino joined Snyk as our first ever Chief Revenue Officer (CRO) earlier this month.

Fugue demonstrate how to run Regula on a Kubernetes manifest to detect an insecure pod, and then we’ll secure it.

Hispanic Heritage Month is a time to celebrate the contributions of Hispanic Americans in the United States from September 15 – October 15. In this post, Luisamaria Hernandez, People Experience Coordinator at Snyk, shares what Hispanic Heritage Month means to her, why language matters, and how her Hispanic heritage has influenced her as an operatic performer.

Snyk announces HashiCorp partnership with a new plugin for Terraform Cloud (TFC) to solve configuration security challenges common when delivering infrastructure as code.

Let’s take a look back at the final day of announcements, sessions, and more from SnykCon 2021.

Using snyk test, Snyk users can execute a scan of their project, resulting in a list of all the vulnerabilities identified. The new snyk fix command, takes this up a notch by automatically applying these recommendations.

This week we announced Fugue IaC, which enables cloud engineering teams to secure their infrastructure as code (IaC) and cloud runtime environment using the same policies. For running IaC checks locally, Fugue developed Regula, an open source tool built on Open Policy Agent (OPA).

Let’s take a look back at the first two days of announcements, sessions, and more from SnykCon 2021.

The safe source for open source. The rapid rise of software supply chain attacks have shown that the software industry needs to change.

Introducing Snyk Learn: free, self-paced security education for developers. This new solution delivers high-quality, relevant educational content online that’s integrated within our Snyk security products, enabling any developer to become a secure developer.

We’re excited to share Snyk Impact, the ESG (Environment, Social, Governance) to formalize how we mobilize Snyk’s unique, compassionate culture and our valuable assets to scale social and environmental returns across all aspects of our operating model.

Snyk announces HashiCorp partnership with a new integration for Terraform Cloud (TFC) to solve configuration security challenges common when delivering infrastructure as code.

Announcing the open beta of Snyk Apps — new extensibility points that enable you to expand the Snyk platform to easily integrate into your specific workflows. With this new capability, our customers and partners can build apps for integrating Snyk into their tools and workflows in an easier and more secure way.

This past Saturday marked the 6th anniversary of Snyk! To celebrate, we’ve released 600 NFTs of a dressed-up Patch (our mascot/logo/pet) for Snyk users, customers, friends, and fans. Learn how to enter for a chance to win one for yourself.

Today’s the first day of October as well as the first day of the 18th annual Cybersecurity Awareness Month. Join Snyk for 31 days of security fun and learning!

Snyk Infrastructure as Code (Snyk IaC) now allows you to ignore IaC vulnerabilities that aren’t relevant to you.

Nominate the security champions in your life for the chance to win a Snykie for Secure Development. Learn more about the process and prizes!

In this installment of our cheat sheet series, we’re going to cover the best practices for Python security.

We’re exiting to announce that Snyk Container registry integrations now include Github Container Registry, Nexus, DigitalOcean, GitLab Container Registry, and Google Artifact Registry.

We are happy to announce that Snyk Code is now part of the Snyk command-line interface (Snyk CLI) in a public beta. Now you can easily make the Snyk Code CLI part of the CI/CD process, with the flexibility to trigger a scan and work with the results in an automatic fashion.

Snyk will be sponsoring the 2021 Open Source Summit and presenting a number of talks related to open source security.

You can now get better, quicker, clearer access to Snyk docs, allowing you to find the information you need, to get more and better use of your Snyk platform.

In this post, we’ll take a look at different ways to approach Python dependency management, and briefly explore dependency security.

Learn about dependency confusion attacks, how they manifest for JavaScript and Node.js developers working in the npm ecosystem, and how to prevent them.

It’s exciting to share the news of our new funding round. Learn about this new round of funding and why developer security is the future of application security.

We’re a month from SnykCon 2021 and we have a packed agenda full of expert talks, hands-on workshops, helpful demos, product roadmaps, opportunities to interact with some of the smartest speakers and leaders of developer security in the industry!

Learn best practices companies can follow to smooth and improve their journey to developer-first security as told by the guests of The Secure Developer podcast.

We’re happy to announce that PHP vulnerability scanning support in Snyk Code is now in beta. Now security issues in PHP code can be identified quickly and easily.

We are thrilled to announce that Adriana Bokel Herde joins Snyk today as our new Chief People Officer.

In this post, we’ll take a quick look at how malicious packages are used in software supply chain attacks, and then we’ll look at how Snyk can help in preventing them.

An application security assessment is the process of testing applications to find threats and determining the measures to put in place to defend against them.

Learn how Twilio’s Product Security manages security ownership to make sure code is secure at all stages of design and deployment.

At Snyk, we are passionate about helping organizations of all sizes — both in the private and public sectors — modernize their security workforce through the right approaches and tooling. Our company was founded upon the belief that the legacy security industry was broken and old methods must rapidly evolve from an IT and security-centric perspective to a developer security approach.

In this post, we’ll look at the 8 best IntelliJ plugins for improving your coding experience.

A key differentiator in a growing company’s success is the ability to scale its talent at the pace needed. Learn 7 best practices for hypergrowth to help your company scale successfully.

Snyk Container in combination with a build tool creating OCI-compliant container images will help you mitigate that risk and focus on what really matters: a first-class customer experience.

The wait is over! The SnykCon 2021 call for papers has officially closed, all the sessions have been reviewed and sorted, and the agenda is now live.

In this blog post, learn how to gain real-time code-level observability to your data structures right there in your IDE, how to find harmful user input in a production Node.js application, and how to find and fix Node.js application security issues in your code and open source dependencies.

In this post, we’ll discuss why speed is critical for SAST tools and how Snyk Code combines speed with accuracy and breadth to deliver a dramatic improvement in the security posture of an application.

Learn how to use Snyk Social Trends to prioritize vulnerability fixes in your applications.

In this article, we will look at Jib, a 100% Java-based tool for Java developers to build highly optimized images for their Java apps.

The Snyk Ambassador program is our groundbreaking effort to help engineers build secure software, through recognition of and support from fellow developers in the community who are passionate about application security.

We’re excited to announce our latest update to Snyk Container base image management capabilities: automatic base image detection.

Snyk security policies just got a whole lot more powerful with a new action and two new conditions, helping your development and security teams assess risk and focus resources more efficiently.

We’re honored to share that, for the second consecutive year, Snyk has been named to the prestigious Forbes Cloud 100 List, coming in at #39!

Learn how to improve your Ruby Gemfile security posture with Snyk.

Learn how to publish Node.js projects as Docker images that we build to the public Docker Hub registry.

To help make DEI&B a focus at DevSecCon24 — the global, vendor-neutral, community-driven, DevSecOps conference — Snyk included opportunities for those attending to learn and to give back.

Snyk makes secure Python development simple. Learn how to secure the code making up your Python app — your own code, the open source libraries you’re pulling in, your containers, and your infrastructure as code (IaC) — by integrating seamlessly into your existing development workflows.

When assessing a SAST testing tool, there are two relevant types of measurements — quantitative (meaning the number of results versus “noise”) and qualitative (specifically language depth and support). Learn about 3 parameters we recommend considering when selecting a SAST tool.

We’re excited to share that Brian Vermeer, Developer Advocate at Snyk, has been named to Business Insider’s Top 21 Developers Shaping Tech and Forging New Paths

The Secure Developer podcast has reached episode 100! Find out what some of the best security advice has been from those episodes. And be sure to subscribe so you never miss out.

Snyk Code now scans for security vulnerabilities and provides remediation suggestions in C# projects. This adds another major language to our portfolio that already includes support for Java, JavaScript, TypeScript, and Python.

We are excited to announce the availability of Social Trends, adding social media intelligence (SOCMINT) to Snyk security intelligence data to help development and security teams prioritize vulnerabilities more effectively.

We’re excited to announce that Tamar Yehoshua joined the Snyk Board of Directors in May. Tamar is currently Slack’s Chief Product Officer and previously held product engineering leadership roles at Google and Amazon.

In this post, we compare the difference in scan times between Snyk Code and two common SAST tools: LGTM and SonarQube.

Learn best practices for hardening your Amazon EKS security, including dedicated continuous delivery IAM roles, multi-account architecture for Amazon EKS cluster isolation, how to encrypt your secrets in the control plane, and incorporating static analysis tooling into your CD pipeline.

Learn how Snyk is using Gloo Edge to normalize authentication in our service-oriented architecture.

If you are still running on an old Maven version like 3.6.3 or below you definitely need to upgrade to version 3.8.1 because of security reasons. Learn more about why you should upgrade and how to do it.

As part of this year’s annual JVM Ecosystem Report, we raised money for Devoxx4Kids, an amazing organization that promotes computer programming, robotics, and engineering to kids in a fun and engaging way.

Learn how to take control of container image security with tips on mitigating risk and prioritizing vulnerabilities.

Learn how to publish Node.js projects as Docker images and then push them to the GitHub Packages container registry.

The SnykCon 2021 CFP is ending soon (July 16, 2021). Hear from Liran Tal, Director of Developer Advocacy at Snyk, to find out what he’s most excited for this year’s virtual event.

In this post, we will demonstrate how small misconfigurations or unwanted side-effects can create Amazon EKS security issues. Then we will look at resolving them.

Learn some best practices for building secure container images, like utilizing an upstream provider, pinning apps, using multi-stage builds, rebuilding often, and more.

Pride Month 2021 has come to a close, but LGBTQIA+ allyship is a year round commitment. Find out what Snyk did this year to support the community.

Machine learning can be a helpful technology or a marketing buzzword. So which is it with static application security testing? Find out in Frank Fischer’s talk from RSAC 2021.

Feeling like you need a career change, but not sure how to do it? Be inspired by Minsi Yang’s story about going from a freelance violinist to software engineer at Snyk

Learn some simple ways to make your applications more secure by preventing PHP code injection.

Learn more about the top 5 risks of open source software that should be considered when selecting packages for your project. Stay secure and code efficiently.

Snyk’s top 5 cloud application security best practices for implementing effective cloud application security, including IaM, encryption, threat monitoring, and more.

To celebrate Pride Month, we hear from Shlomi Rozilyo about the support and encouragement that allows him just be himself here at Snyk.

Snyk offers a variety of developer-first tools and products to make secure Java development simple. Learn how easy it can be to add security to the Java SDLC.

We’re looking for SnykCon talks that inspire, engage, and activate developers around the world to build securely, and your session could be the perfect fit. The CFP closes July 16, so submit now.

In just a few clicks, you can activate the Snyk Container extension in AWS CloudFormation Registry and have Snyk automatically integrated with Amazon EKS.

Snyk Infrastructure as Code (IaC) can now scan for AWS CloudFormation misconfigurations in YAML or JSON templates against our comprehensive set of AWS security rules.

Kris Broughton, Channel Sales Manager at Snyk, reflects on what Juneteenth means to him and the events in America that have led the country to grapple openly with the inconvenient truth of racial inequity.

Choosing the right SAST tool for your organization is important. Learn why it’s difficult to compare SAST tools using only lists (like OWASP Top 10 and SANS-25), test suites, and benchmarks

President Biden’s executive order regarding Improving the Nation’s Cybersecurity explicitly mentions the adoption of SBOMs and the formalization of SBOM standards as a goal. Learn how Snyk is contributing to this effort.

We’re excited to announce the release of the latest O’Reilly book from Guy Podjarny, “Cloud Native Application Security: Embracing Developer-First Security for the Cloud Era”.

Atlassian and Snyk released a new integration that natively embeds Snyk vulnerability scanning into Bitbucket Cloud security.

Using Cortex with Snyk allows teams to know what security vulnerabilities exist throughout their microservice architecture.

Learn more about the software supply chain security requirements in President Biden’s Executive Order on Improving the Nation’s Cybersecurity and how Snyk can satisfy them.

We’re pleased to announce our new Snyk extension for Visual Studio, making it easier for developers to stay both secure and compliant as they code within their favorite IDE.

Discover how Snyk enables AWS CodePipeline developers to make security an automated part of their build, test, and deploy phases.

On June 23, 2021, we’ll be opening the virtual doors to DevSecCon24 2021 — the free, global, vendor-neutral, community-driven conference that connects developers, security, and operations teams to learn and enable the integration of security directly into their development practices.

As companies begin to return to the office, many employees are refusing to leave behind the flexibility and productivity that come with remote work life. Read a note from Snyk CEO Peter McKay about Snyk’s philosophy on work flexibility.

We are happy to announce that this Python is now a fully supported language in Snyk Code. Now you can secure your Python code with Snyk directly from your favorite IDE.

Snyk has been named a Visionary in the 2021 Gartner Magic Quadrant for Application Security Testing, finished with the top score overall in three critical capabilities: Software Composition Analysis (SCA), Container Security, and Developer Enablement.

The theme for SnykCon 2021 is Build Securely. SnykCon is a free developer conference that brings development and security teams together to build software securely.

We are honored to share that Snyk has been named to the ninth annual CNBC Disruptor 50 List, coming in at #15!

This new VS Code extensions supply chain security threat has the potential to become a new attack playground, potentially impacting over 2,000,000 developers. Let’s take a deeper look.

Learn how to disclose vulnerabilities now that Snyk has agreed to take over from the amazing Node.js ecosystem vulnerability disclosure program.

Updating dependencies is a lot of work! Learn how a DevOps-focused team from Manifold put best practices in place for continuous dependency updates.

We’re excited to announce Snyk Preview — a new way for our users to easily get a first taste of upcoming features before they are generally available within the Snyk platform!

While PHP Composer makes app development faster, it does abstract away a level of control and visibility. So while it makes coding easier, it does beg the question… is it doing it safely? With Snyk, I’m able to answer that PHP Composer security question in a few clicks.

In honor of Asian American Pacific Islander (AAPI) Heritage Month, Jeff Yoshimura, Chief Marketing and Customer Experience Officer at Snyk, shares the story of his beloved grandfather, and why gardening is the way he pays homage to his grandfather’s legacy and Japanese heritage.

In our recent State of Cloud Native Application Security report, we found that 69% of respondents had a misconfiguration or known unpatched vulnerability in their cloud native applications. Learn about how we can work together to bring that number down.

With Snyk IaC, you can get immediate guidance on security configurations as you write, and scan your Terraform plans in your deployment pipelines to ensure they’re free from cloud misconfigurations.

We’re excited to announce the acquisition of FossID, extending Snyk’s developer-first security capabilities with deeper C/C++ support and enhanced license compliance.

Snyk is available to purchase on the AWS Marketplace through a variety of mechanisms including private offers, either directly, or through preferred partners.

Trend Micro Launches its Cloud One Open Source Security powered by Snyk. Learn more about what to expect from this expanded partnership.

When static code analysis is used as part of a DevOps process, the automated review process provides several benefits to development teams. Read these six reasons to use source code analysis

This advisory details a PHAR deserialization vulnerability that exists in SuiteCRM which could be leveraged by an authenticated administrator to execute commands on the underlying operating system.

We’re excited to announce that Snyk Code is now available as part of our Free plan, offering 100 free vulnerability scans.

In a recent npm security research activity, Snyk uncovered a total of 8 npm packages that matched a specific malicious code vector of attack.

Snyk Open Source support for GitHub Security Code Scanning lets you automatically scan your open source dependencies for security vulnerabilities and license issues, as well as view results directly from within GitHub’s Security tab.

As organizations continue to rely on software for core business processes, application security (AppSec) is an ever-critical consideration.

During our roundtable discussion with Intuit, we tackled the question, “How can we make security appealing to developers?”

A look at how Rego evaluation works, and how it affects performance. With Rego, there are two important strategies: bottom-up and top-down.

The future of code security depends on SAST tools that are fast, accurate, and developer-first. Additionally, they need to offer recommended fixes for vulnerabilities, putting security expertise in the developer toolkit.

Announcing Snyk support for secure Elixir development. Snyk enables development and security teams to easily find, prioritize and fix vulnerabilities in the Elixir and Erlang packages they’re using to build applications.

Snyk is celebrating our 4-year partnership with Atlassian at Atlassian Team ‘21 with a big announcement

Snyk Infrastructure as Code beta helps you perform Terraform plan analysis for security vulnerabilities before applying your changes.

Announcing the Snyk Team product plan, designed to help development teams build secure applications faster.

the Snyk Maven plugin so you can now scan your application for security vulnerabilities in third-party libraries as part of your build cycle—putting security expertise in the hands of developers.

Code Dx 5.3 now includes a connector with Snyk, giving customers visibility to open source dependencies, license issues, and container vulnerability management.


Snyk Code, the AI-based static application security testing (SAST) tool, now offers Python as a supported development language (beta). Snyk Code already fully supports Java, JavaScript, and TypeScript.

Simon Maple (VP of Developer Relations & Community at Snyk) and Chaim Mazal (VP, Information Security at ActiveCampaign) discuss the changing application security landscape and the impact it has had on ActiveCampaign.

Learn how to use the Snyk Vulnerability Scanner plugin for IntelliJ IDEA to make it easy to find and fix Java security issues earlier in the development process.

We’re pleased to announce our new plugin for JetBrains IDEs, making it easier for developers to find and fix security issues as they code!

View a complete picture of the open issues across your application, covering vulnerabilities from open source libraries and container images, licenses, and now configuration issues from your Kubernetes and Terraform files.

Learn some best practices for keeping your Node.js and JavaScript projects safe from code injection attacks.

Buying security tooling is easy, but changing company culture is hard. Learn how Shutterstock was able to adopt a security mindset from the ground up.

We’re excited to share that you can now scan container images stored in Red Hat’s Quay container registry and their hosted Quay.io service with Snyk Container.

Snyk Container offers support for scanning container images stored in the popular open source container registry, Harbor. Learn how to use it to keep your containers safe.

We started to investigate alternative workflows, specifically around application security automation, and quickly solved our scaling challenges with some Snyk API-based tools designed by the Tech Services team.

Snyk Code provides the ability to ignore suggestions. Learn about our take on this functionality using intermediate representation. We think you’ll like it.

The outdated version of snakeyaml contains a Denial of Service vulnerability. We highly recommend that you update snakeyaml to version 1.26 or higher to prevent this problem.


In this article, you will learn how to identify, prioritize and fix issues in your application’s container images using various tools and gain a better understanding of how those fixes can impact your applications at deployment.

Learn more about 10 DevOps tools that enable fast and efficient software development in complex projects involving multiple teams and developers.

Let’s take a look at installing Backstage and the Snyk plugin!

Learn more about DevOps security and how it can help deliver software faster and more securely while generating more value.

We’re happy to share that we are extending Snyk Container by helping you automatically fix issues in your Dockerfile to keep an up-to-date base image at all times.

We’re excited to announce our ability to automate fix PRs for containers, following on to our recent announcement of elevating Dockerfiles to first-class status in your git repos.

In October 2019, in order to improve the Docker Hub authentication mechanism, Docker rolled out a beta release of two-factor authentication (also known as 2FA).

For this article, I created a Spring MVC application with JSP web pages that runs on a tomcat server. Although the code works perfectly, I did make some security-related mistakes. Let’s see how we can detect these mistakes in my Spring MVC application performing Java static code analyses and how to fix them.

In this article, I’ll take you through a step-by-step process of container hacking, in which we will exploit a Node.js-based web application that uses a vulnerable, yet official, Docker base image for Node.js.

At the beginning of 2021, I noted that Snyk was ready to soar. And soar we have…the rocket ship’s next stop? Asia Pacific and Japan (APJ).

Today we came a step closer towards our ultimate vision - to empower every one of the world’s 27 million developers to develop fast while staying secure.

In this cheatsheet, we will take a look at the various securityContext settings, explore what they mean and how you should use them.

This article is part 3 of Snyk API Wednesdays - our new blog series covering different Snyk API use cases and customer stories. Part 1 covered the Snyk-Watcher by Twilio, and part 2 covered a new integration with Opsgenie using custom webhooks.

We’re excited to announce that we’ve redesigned Snyk’s issue cards to significantly improve its usability and value. It’s more than a fresh coat of paint and we haven’t taken anything out, but we’ve added value and feng shui’d the card considerably.

in this article, we’ll walk through the lessons learned from SolarWinds Orion security breach.

Security misconfiguration is part of the infamous OWASP top 10 vulnerability list and has a prominent spot on place 6.

We’re excited to announce a new integration with Opsgenie, making it easier to further integrate security into existing incident management and operations workflows. This integration is based on Snyk’s new custom webhooks API beta release announced last week.

In this post, we’ll review the IaC scanning tool, take a look at recent additions that have been made to it—including Azure, GCP, and AWS infrastructure as code—and how your teams can use it as an active part of your company’s DevSecOps efforts.

This is our newest blog series that highlights the different ways the Snyk API is leveraged by our customers. Snyk’s extensibility and API enable developers to tune Snyk’s security automation to their specific workflows, ensuring consistency in both developer experience and platform governance.

We are excited each time we learn of a new use case, and are committed to improving the experience our customers have with the Snyk API.

Learn about the 4 steps of the vulnerability remediation process and how to set up an efficient workflow that fixes or neutralizes bugs and vulnerabilities in cybersecurity.

We’re creating a comprehensive Java 2021 report that reflects the state of the JVM ecosystem. This post includes a summary of the JVM Ecosystem 2020 report.

Last fall, we made the decision to launch a Community Outreach Internship Program at Snyk. Like many across the globe, we at Snyk were troubled by how the economic impacts of covid-19 are disproportionately affecting women and underrepresented minorities, and wanted to ensure that Snyk was playing a role in being a part of the solution.

Learn more about security vulnerabilities in cybersecurity: vulnerability versus exploits and threats, website security vulnerabilities, and security and vulnerability management.

If you’re using the AWS suite of Kubernetes-related tools, you’ll be pleased to know that you use Snyk to scan directly into your workflows there, with integrations into Amazon Elastic Container Registry ( ECR ) and Amazon Elastic Kubernetes Service ( EKS ).

In this installment of our cheatsheet series, we’re going to cover eight Go security best practices for Go developers.

We’ve recently launched the 2021 survey and we want to hear from you!

Learn about the Verdaccio, get open source project insights, deep dive into the best parts of the project, and get to know the maintainers and contributors.

An overview of Snyk’s 2021 kickoff.

Since most organizations are taking steps to reduce the friction of application development, containers are rapidly becoming the de facto standard of abstraction and virtualization, helping development teams move code to production as quickly as possible.

In a perfect world, you want to do vulnerability remediation on all issues and end with zero vulnerabilities. But you may not be able to fix all the vulnerabilities at once. You want to start with the most vulnerable issues that impact your application and start vulnerability remediation from there.

When we come to using the container runtime in Kubernetes, these controls are used by the Kubernetes control plane to define which capabilities our container should be started with. The configuration for capabilities is surfaced to the user through various settings in the securityContext section of the YAML for a container.

Snyk CEO Peter McKay looks back at Snyk’s 2020 and talks about our opportunities in 2021.

Building your own Docker Node.js web applications may come with many security risks. So, how do we make security an essential part of Docker for Node.js developers?

We are pleased to start the new year with the beta availability of Reachable Vulnerabilities for GitHub, providing development and security teams with deep application-level context for vulnerabilities identified in GitHub-hosted applications and enabling them to prioritize fixes more efficiently.

This blog post provides an introduction to web cache poisoning and demonstrates why open source maintainers should take this issue into account.


Developing Kubernetes applications can be hard. This is where tools like Tilt come in.

In this post, we’ll look at some common software risks, how to measure security risks, and how organizations can use Datadog and Snyk to automate risk management.

Welcome to the fourth of four posts in which we take a look back at all the highlights we have shared across the Snyk blog across 2020.

Welcome to the third of four posts in which we take a look back at all the highlights we have shared across the Snyk blog across 2020.

Welcome to the second of four posts in which we take a look back at all the highlights we have shared across the Snyk blog across 2020.

Welcome to the first of four posts in which we take a look back at all the highlights we have shared across the Snyk blog across 2020.

In July, Snyk’s security team identified a potential vulnerability in the JWT package, which offers a Go implementation of JSON web tokens. The issue pertains to a malfunctioning function called VerifyAudience. This vulnerability is part of a broader trend, as Snyk’s research team has uncovered hundreds of proprietary Golang security vulnerabilities this year. The article discusses Snyk’s investigative processes and highlights trends in this rapidly growing ecosystem.

Learn why we consider Fastify — the open source Node.js web application server— to be a health project.

2020 was an incredibly challenging year for all of us but with the dawn of a new year just over the horizon, it’s a great opportunity as any to take a few moments to appreciate the work done by our engineering and product teams.

Java serialization —and deserialization in particular — is known as “the gift that keeps on giving” because it has produced many security issues and vulnerabilities over the years.

In this article, we look at security risks caused by marketing related scripts added to a website, such as A/B testing services, Google Analytics and others, and show options on how to mitigate them.

We’re happy to announce enhanced support for Go security in Snyk Open Source and Snyk Container, enabling development and security teams to find and fix vulnerabilities in their Go applications more efficiently!

Let’s take a look at branches in git and what git checkout remote branch actually means.

We’re pleased to announce a new feature that helps take some of the mystery out prioritizing and fixing container vulnerabilities: relative importance.

Snyk has added a new check to Snyk Infrastructure as Code (Snyk IaC) to check your Kubernetes deployment definitions and notify you if you are vulnerable to this type of attack.

In this blog post, we’ll look at how the use of open standards allows Snyk’s container scanning to work with open source command line tools.

Over the past year, we have been working hard to improve our testing for Gradle projects imported from Git repositories by making it more reliable, accurate, and scalable.

Snyk’s Liran Tal shares ten tips for getting that Call For Papers (CFP) proposal accepted into a conference.

In this post, we will explore how Kubernetes container isolation impacts privilege escalation attacks. We will use common kernel exploitation techniques to figure out how container abstractions layers can hinder our path to that precious root shell.

In this article, we’re featuring 10 git aliases that can help with a faster and more productive git workflow as an individual, or within a team.


Most of the engineering managers I have met have assigned their senior engineers to lead all the critical features, but I would like to “turn the senior engineer around” and suggest the opposite: the more senior you are, the less you lead engineering efforts in the team.

Let’s take a look at some of the popular Infrastructure as Code tools and what security hardening measures you can apply at the code level to protect your applications and platforms.

Tips on how to get the most out of the Snyk CLI as a tool to test, monitor, and remediate known vulnerabilities in your applications

Command injection attacks—also known as operating system command injection attacks—exploit a programming flaw to execute system commands without proper input validation, escaping, or sanitization, which may lead to arbitrary commands executed by a malicious attacker.

This post suggests some best practices, and discusses how maintainers and developers can adopt DevSecOps tools for open source projects to better improve their security posture.

Welcome to the Snyk Monthly Vulnerability Profile. This month we’re looking at a buffer overflow vulnerability discovered in the FreeType package used by Chromium and the subsequent work by Snyk to locate open source packages impacted by inclusion of vulnerable Chromium components.

In this blog, we’ll discuss the release process for our Kubernetes Operator, and show how we’ve automated deploying the release across multiple repository targets.

How do we make security an essential part of Docker for Java developers?

Today (Thursday, 19th November), is International Men’s Day, a day when we celebrate the positive value men bring to the world and raise awareness of men’s well-being.

For the past few months, as the engineers have been integrating our products, the Snyk and Docker teams have been collaborating on a security guide. We are pleased to announce the release of the Guide to Container Security for Development Teams.

OCI (Open Container Initiative) is a Linux Foundation project to design open standards for operating-system-level virtualization, most importantly Linux containers.

Here at Snyk, we are focusing on these groups and developing the Community Outreach Internship Program to open the doors of opportunity and help these impacted members of our community develop the skills necessary to begin the journey of a successful career.

RPM is used in many Linux distributions including Red Hat Enterprise Linux, Fedora, CentOS, and others. It originated in Red Hat Linux, and originally stood for RedHat Package Manager, although it’s now a recursive acronym that stands for RPM Package Manager. RPM can refer both to the package manager, and to the rpm file format which it uses to distribute applications.

Snyk recently introduced a new feature to support the Poetry package manager and the poetry lock syntax.

In this blog post, we’ll guide you through how to create a free Snyk account and import your first GitHub project into Snyk and test your open source dependencies for known vulnerabilities.

We’re pleased to announce the latest enhancement to Snyk Container—detecting Dockerfiles straight from Git repos to better empower shift-left security.


This post outlines how you can use GitHub Actions to publish npm packages that are maintained in open source projects.

How do you ensure effective security compliance across several teams when they experience an overwhelming number of vulnerabilities that need to be addressed?

Though it might seem a small step towards promoting D&I within our culture, creating inclusive job descriptions is something Snyk is focused on putting time into, and getting right.

This vulnerability report highlights several challenges that we face in the Node.js Security Working Group as security analysts who need to respond to security incidents.

This post discusses the OWASP Top 10 proactive controls and how to incorporate them into our web applications.

Even when running rootless, it’s always good practice to understand exactly what your container needs, and only give it those minimum permissions.

During SnykCon 2020, author and researcher Gene Kim sat down with Snyk co-founder and President Guy Podjarny and a small group of Snyk VIPs to talk about (Sec)DevOps—where we started, how far we’ve come, and strategies for getting the most value out of the practice. This post contains a few of the most interesting takeaways from the conversation.

Snyk has had the ability to test your Docker images using our CLI for over a year now. With the latest release of the CLI, we’re improving the user experience for container users, as well as adding a few more useful features for advanced users.

At last week’s SnykCon, Snyk’s Co-founder and President Guy Podjarny sat down with Adrian Ludwig, CISO of Atlassian for a fireside chat about the modern security market, how his security team is structured, and how to help developers embrace security.

“The safest thing is to do nothing” is a great cliche, but in the case of software security, this is almost never the case. Starting with the very first line of code we write, the line has been crossed—we have introduced security risk that needs to be managed.

Welcome to the Snyk Monthly Vulnerability Profile. This month we’re looking at a Regular Expression Denial of Service (REDoS) vulnerability discovered in the popular UAParser JavaScript package.

We’re excited to share that we have launched a Snyk User Community to bring our users and team together to share knowledge and experiences, personal and community projects built upon Snyk, discuss all things security—from DevSecOps, to AppSec, through Cloud Native Sec, as well as have quick and easy access to product & security announcements.

Gradle is one of the major build systems in not only the Java ecosystem but also for Android development. With Gradle, you can manage your dependencies, build, and test your project.



Day One of SnykCon 2020 is in the books. In this post, we’re bringing you a recap of all the news fit to print, plus a peek into some of the eye-opening sessions we heard today.

Snyk announced our forthcoming product, Snyk Code, our new developer-first SAST offering, expanding our cloud native application security platform.

The Mintegral SDK, a widely used mobile app advertising tool for iOS and Android, helps developers monetize their applications through third-party ads. The security research team at Snyk has recently revealed two important disclosures related to this SDK. This article aims to provide in-depth technical insights and findings from their research, offering more details than what has been shared in previous blog posts.

This week, Snyk was recognized by Comparably’s employer awards in 2 categories: ‘Happiest Employees’ and ‘Best Compensation’.

As part of this ongoing effort, Snyk has leveraged new information to conduct additional research into the Mintegral SDK. As a result of this research, additional findings have been uncovered.

Learn more about OWASP top 10 vulnerabilities in order to avoid frustrating and often costly application security failures.


While Snyk provides lots of details for each of the vulnerabilities we discover, and references to published advisories and associated CWEs, not everyone is a security expert.

Learn more about application security challenges and how to deal with them by implementing 15 application security best practices.

SnykCon is less than 2 weeks away! In 2020, meeting and engaging with others is more important than ever before.


ARM-based systems are increasingly popular amongst developers, for edge and IoT use cases as well as some server uses with the likes of the AWS Graviton Amazon EC2 instances. Docker provides an increasingly flexible toolset for building container images for multiple architectures. But how do you know those images are secure?

We’re pleased to announce the release of our advanced, developer-first project management capabilities, helping organizations manage application security at scale!

It gives us great pleasure to announce the release of the solutions that’ll help you scale your use of projects within Snyk effectively: Project Attributes and Project Tags.

Trek10, which helps clients design, build, and support AWS workloads, and Snyk have partnered to design and provide a CI/CD solution that provides an enterprise-ready, dynamic deployment pipeline for your serverless applications, follows AWS best practices for isolating resources and walks you through creating three AWS accounts (subaccounts): development, shared services, and production.

Fancy learning front-end security concepts while also learning how to deploy a static website on Netlify? Ready to learn how you can automatically detect and fix vulnerable JavaScript dependencies? Let’s jump right in.

On behalf of the Snyk team, I wanted to share with you why we are excited to integrate DeepCode’s technology to the Snyk Cloud Native Application Security platform, and what it will mean for our customers and users.

Since fixing each and every web application vulnerability in your backlog is simply impossible, you have to prioritize. Prioritization helps you focus on the issues that matter most to your organization and thus enables you to make the most out of the limited time and resources at your disposal for the best security impact.

We’re happy to announce our second AWS Quick Start, to help you get Snyk working with Amazon Elastic Container Registry (ECR) and AWS Lambda with just the click of a button.

BSD-licensed software is popular with teams that have specific goals in mind. Learn more about BSD license terms, conditions, benefits, commercial usage and more.

Welcome to the Snyk Monthly Vulnerability Profile. This month we’re looking at an arbitrary code execution vulnerability discovered in the popular Grunt JavaScript package.

In light of the recent BLM protests and the pandemic disproportionately impacting minorities in the workforce, DEI (diversity, equity, inclusion) have been a lot on our mind recently.

Rego code helps keep cloud resources secure. You can also use OPA and Rego languages to enable policy as code to automatically enforce coded policies. Here are some valuable tips for using Rego.

In the blog post, Rapid7 gives updates on the Snyk Intel Vulnerability database integration into tCell by Rapid7, a next-gen cloud WAF and RASP technology, including new expanded language coverage and functionality.

Snyk has been named to the Forbes 2020 Cloud 100, the definitive ranking of the top 100 private cloud companies in the world, published by Forbes in partnership with Bessemer Venture Partners and Salesforce Ventures!

If you find vulnerabilities in your Maven project using Snyk, how can you fix them? This post explains how you can fix vulnerabilities in third-party libraries when using Maven.

Today, we want to share another bit of vulnerability detail that Snyk adds to help you prioritize which container vulnerabilities to fix: exploit maturity for Linux vulnerabilities.

On behalf of the entire Snyk family, I’m humbled to announce that today marks the closing of our latest funding round—an investment of $200 million led by Addition, a firm focused on supporting visionary entrepreneurs.

We’re happy to announce Snyk’s brand new PyCharm plugin, helping Python developers find and fix security and license issues in their open source dependencies as early as their first lines of code!

A pragmatic approach to understanding S3 security. You’ll be able to build a secure S3 bucket that meets your particular needs.

In the article, Darshan Vandra, Associate Software Engineer, Red Hat, and Parag Dave, Senior Product Manager, Red Hat, walk us through Snyk’s vulnerability detection and fast identification and advanced capabilities for analysis and triage.

The 2020 Gartner Market Guide for Software Composition Analysis (SCA) has been published, highlighting the growing importance of open source software security, and outlining recommendations for effective risk management and mitigation.

We’re thrilled to deepen our collaboration with our long-standing partner Trend Micro, a global cloud security leader, to co-develop a first-of-its-kind solution that will help security teams manage the risk of open source vulnerabilities.

We’re happy to announce the vastly improved performance of security testing for Go projects via the Snyk CLI, in some cases improving scan time by more than 90%!

The Snyk research team has uncovered malicious behavior in a popular Advertising SDK used by over 1,200 apps in the AppStore which represent over 300 Million downloads per month, based on industry expert estimates.

The Mintegral SDK is a popular mobile app advertising SDK available for both the iOS and Android platforms. It is used by thousands of mobile apps with over a billion downloads per month. The Snyk security research team has made two significant disclosures surrounding the Mintegral SDK — vulnerabilities known as SourMint.

Welcome to the Snyk Monthly Vulnerability Profile. In this series, Snyk looks back on the vulnerabilities discovered by or reported to our Security Research Team. This month we’re looking at a prototype pollution vulnerability discovered in express-fileupload.

“Shift left” has become the holy grail for security teams today but organizations are still struggling to successfully implement some of the key application security processes that shifting security left entails.

When being overwhelmed with vulnerabilities affecting your app, a reasonable question to ask yourself is, are all of these issues even exploitable? At Snyk, we address this issue by combining expert security research with automated static analysis.

We’re thrilled to announce the launch of our developer-first Infrastructure as Code security capabilities, enabling developers to find and fix misconfigurations that can lead to security problems.

The key to growing in a scale-up environment is to be willing to continually give away what you were working on, give away that part of your ‘lego tower’, to free yourself up to focus on newer challenges. It’s in this intentional embrace of continuous change that growth occurs.


This post provides a quick overview of Java dependency management.

Previously, we have shared our AngularJS Security Fundamentals cheatsheet. This time around, we dive straight into the modern Angular security best practices.

Snyk has recently introduced a Priority Score to help prioritize vulnerabilities we detect, helping you identify the most important issues that need your attention.

This blog post outlines why message brokers can’t be trusted, and how to exploit Apache Airflow in order to gain privileges to machines that are supposed to be protected.


Snyk’s new Priority Score helps to drastically simplify one of the biggest challenges in using open source securely—working out which vulnerabilities to tackle first.

We’re excited to share that CRN has included Snyk in its annual Emerging Vendors List in the Security category.


Vulnerabilities are not born equal, and their risk variance is influenced by an array of objective and subjective factors. Effective prioritization depends on an accurate assessment of these factors.

We are delighted to announce a new AWS Quick Start featuring Snyk Container and sample deployments for quickly and easily securing workloads running on Amazon Elastic Kubernetes service (Amazon EKS).

We’re excited to unveil Snyk’s developer-first prioritization capabilities, helping development and security teams prioritize fixes for security vulnerabilities in their open source dependencies and containers more effectively!

For developers, deciding which security issue to address first is hard, requiring time and expertise developers often don’t have. This is a chance for the right tools to shine, providing the expertise to know which security questions to ask when prioritizing, and the technology to answer them quickly.

Welcome to the Snyk Monthly Vulnerability Profile. In this series, Snyk looks back on the vulnerabilities discovered by or reported to our Security Research Team. This month we’re looking at one of a series of Zip Slip vulnerabilities Snyk’s Security Research Team identified in Golang packages.

In this article, we will take a look at some top tips for handling remote working fatigue, and how we at Snyk have decided what works best for us.


As part of our Pride Month celebrations, we reached out to individuals and organizations in the tech industry and we talked about everything Pride—from their experience being LGBTQ+ in the tech industry, to heartfelt advice to newcomers in the industry, this Q&A blog series is sure to make you smile and inspire you!

In this article, we’ll quickly review the main ways to automatically generate existing infrastructure code from an existing environment — how to clone an environment, make it work, and ensure that it’s repeatable.

This blog post aims to demystify the vulnerability and provide remediation details for open source project maintainers looking to patch HTTP request smuggling within their projects.

Learn how to get started with managing multiple Terraform environments like a pro.

June 2020 has been revolutionary for many, as activists and supporters came together in response to many disruptive events. This year, Pride looks different.

This report sheds light on the current security posture of open source software and reflects on security concerns, trends in vulnerabilities across packages and container images, and also examines the practices employed by maintainers and organizations in securing their software.

Snyk has launched a monthly blog series that focuses on significant vulnerabilities identified or reported to their research team. Each installment highlights a noteworthy vulnerability from the previous month, detailing its discovery, research process, and disclosure. The series also acknowledges the contributions of researchers, developers, and users who play a vital role in identifying and addressing vulnerabilities within the open-source community.

DevOps Enterprise Summit London - Virtual is our first virtual event, and we’ve all been studying online events for months, trying to understand what makes the great ones great, and why the worst ones make you feel like you’re stuck on the worst, multiple-day video conference call ever.


Welcome back to the second part of how to work with git, the easy way! In this part, we will go over four more common scenarios and some conclusions.

When creating REST API projects or CLI applications in Node.js, developers often rely on the open-source npm dependency package manager to incorporate various frameworks and tools, which can save time and effort. Utilizing stable and well-maintained packages can address specific project requirements effectively. However, this practice is not without potential drawbacks, as over-reliance on external packages may lead to issues that could affect project stability and maintenance.

On Tuesday, June 16 from 10-11 am PT, three hands-on experts from AWS, CircleCI, and Snyk will host “The DevSecOps Journey Webinar” to demo how CircleCI and Snyk seamlessly port with you as you increasingly develop in the cloud.

This post digs into the options of the git rebase interactive command and that you can use to “rewrite your history.”

We are excited to announce that we power the security badge in JSDelivr.com!

In the face of systemic injustice arcing towards a specific community, we must have the courage to call it out specifically.

We’re excited to share that we’ve expanded our collaboration with Atlassian and have enhanced Snyk’s integration with Bitbucket Cloud.

Our new Kubernetes configuration feature in Snyk, which checks your configuration files for misconfigurations, now supports Helm Charts.

We’re excited to announce the beta release of Merge Advice — the latest enhancement to Snyk’s remediation capabilities that help you fix vulnerabilities reliably.

With the global economy in its current state, businesses are all impacted in different ways, making a standard “one size fits all” scripted approach to calling and messaging businesses difficult — it’s hard to tell what someone has been through before genuinely asking him or her.

As many sources have indicated that diversity in the workplace brings with it a number of attributes to companies including increased revenue and enhanced problem-solving skills through diversity of thought, it is important to address why there is a lack of women in tech, and what we can potentially do to solve the problem.

This post provides an overview of the work of Snyk’s Security Research Team.

Here are a few very basic tips for keeping multiple Terraform versions clean and organized.

Learn how to manage Terraform state, what a TFState file is, and how it makes Terraform code different from other configuration management tools.

We’re pleased to announce that we’ve added support for Azure Repos Server, enabling developers using Azure’s on-prem DevOps service to identify and fix security vulnerabilities and license issues in open source dependencies.

Snyk recently received reports that some of our inner domains are vulnerable to a clickjacking attack. Fixing the issue was easy, but we wanted to go one step further and ensure all our endpoints are protected — and stop worrying about this issue. This post outlines how we did that.

On May 23, 1995, Sun Microsystems released Java. This means that Java turns 25 years old and that is something we need to celebrate!

Every now and then, I need to do some basic stuff in Java and I wonder what is the best way to this. This happened to me a few days ago! I needed to simply get the sum of a List of numbers and I found out there are a number of ways — pun intended — to do this.

Learn different ways to manage drift from manual changes on your infrastructure in Terraform for different cases.

Some valuable lessons to consider during Mental Health Awareness Week.

Amazon S3 is incredibly flexible and easy-to-use, but S3 security is more complex and requires a deeper understanding of the layers of S3 security options and the full context of your unique cloud use case to get it right.

To help organizations more quickly and decisively evolve a DevOps culture that effectively incorporates security, Snyk has launched our DevSecOps Hub.

Tagging projects is possible today via the Snyk API and allows you to group and filter your projects based on the tags you’ve applied. This feature will be available in the UI soon.

Snyk now makes it even easier for you to detect vulnerabilities in container images, by identifying vulnerable application dependencies alongside the operating system vulnerability.

Learn about some great open source tools for Terraform code testing, like TFLint, Terratest, GOSS, and more.


The topic of mental wellness, most specifically in the form of burnout, is a very real one at Snyk.

You can now use Snyk to create your own policies and use these rules to help your development teams easily find and fix what is most critical to your projects, while minimizing the distractions created by less pressing issues.

We are excited to extend our partnership with AWS and announce we have achieved the AWS Lambda Ready designation, part of the Amazon Web Services (AWS) Service Ready Program.

We’re excited to share that Snyk and Red Hat have been working together to make it easier for developers to create secure applications built on open source and run them securely on OpenShift.

On the 25th of April 2020, version 2.2.0 of is-promise library on npm was released by JavaScript developer and maintainer Forbes Lindesay. Reportedly, this release caused failures in popular developer build tools used for scaffolding new projects, such as Facebook’s create-react-app, Google’s firebase-tools, angular-cli, and others.

Even large companies are taking advantage of open source programs to enhance their portfolio of enterprise applications. Still, everyone needs to know the myths and facts related to open source security.

We’re thrilled to announce Snyk’s developer-first license compliance management solution, designed to help you maintain a rapid development pace while also remaining compliant with the open source licenses you’re using in your code!

License compliance is crucial for being able to minimize the risk to the business but the only way to do so at scale and without impeding development is with a developer-first mindset.



It’s always a good idea to check for security issues in code that you review. In case you don’t know what to look for, here’s a handy checklist to give you pointers for your next code reviews!


In this post, we discuss options for ensuring the health of your Python projects, with the goal of making dependency management as straightforward as possible.


We start off with setting up an environment to build the plugin. Let’s begin with creating a new project that will be managed with Yarn 2


Today, we’re announcing two major pieces of news to take our ability to reach and service AWS customers to the next level.

This post examines new Snyk security features for Kubernetes configruations.


This article discusses building a full CI/CD pipeline for a VS Code extension using GitHub Actions.

Yarn 2 is the new release of the revolutionary and well-established npm package manager Yarn which features improvements, such as Plug’n’Play, Plugins architecture, Monorepos, and improved workspaces support, Zero installs.

Do you know for all the packages you import if they contain known security vulnerabilities? The free, open source, Vuln Cost extension for VS Code can help you with this.

A specially-created Atlassian, limited-time Bitbucket Cloud promotion bundles Snyk and other developer tools.

This post highlights the recently disclosed “Insertion of Sensitive Information” vulnerability, which affects Gradle’s plugin-publish plugin.


Snyk’s enhanced security and license testing for pull requests helps developers incorporate security thinking into their daily workflows.

In this post, Snyk founder Guy Podjarny offers a few suggestions for ways you can adapt your security policies for a newly remote workforce.

In this post, we discuss using Red Hat Universal Base Images in order to proactively protect your container images from vulnerabilities.

This blog post walks through the design and implementation process for what became autotest, our internal automated testing tool comprised of PyTest and Terraform.

This post discusses the prototype pollution vulnerability, explains how certain applications can be subject to it, and describes the rationale behind its severity classification.

Snyk is currently building our annual State of Open Source Security report and we want to hear from you! Complete this brief survey to help guide our research.

Learn some best practices for keeping your Django project secure.

Navigating an organizational change toward DevSecOps can be complicated, involving numerous teams, moving parts, and even new tools. Gartner’s analysts were able to pinpoint the most common challenges and provide recommendations to organizations looking to scale DevOps.

A backdoor in our code that can perform OS injection is a considerable threat.





Today we want to talk about two recent Kubernetes vulnerabilities (CVE-2019-11247 and CVE-2019-11249) and how you can address them.


This post focuses on women’s opportunity in the tech workforce, and how rapidly-growing companies can make a difference.

Urllib3, a powerful and popular Python http client, is subject to a newly discovered denial of service vulnerability.

We’re pleased to announce the graduation of Automatic Dependency Upgrades, a Snyk Open Source capability that helps developers proactively reduce security vulnerabilities and maintain dependency health when using open source software.

If you run a website, whether this is a full-fledged SaaS web application or a small blog — built by Gatsby, Wordpress, or an indie GitHub Pages setup — one of the key concerns you want to mitigate is security vulnerabilities.

We’re excited to share that CRN has included Snyk to its annual Security 100 list.

Coming out of a busy week at RSA 2020, one of the best aspects of attending was the chance to meet with so many passionate customers and fans of Snyk and listen to their feedback. What was clear this year was a growing excitement around Snyk’s accomplishments — a palpable sense of momentum for our developer-first approach to application security.

In this blog post, we will use our new product feature and enable new projects to be created in Snyk automatically.

As we wrap up February, dive into the JVM Ecosystem report, tune into DevSecOps learnings, catch up on the latest Snyk product updates, and mark your calendar for KubeCon EU!

Integration with Amazon Web Services Elastic Container Registry (ECR) is one of our most popular use cases with Snyk Container and so we’re happy to announce that we’ve made it simpler to integrate Snyk Container vulnerability scanning within your Amazon Elastic Kubernetes Service (EKS) and ECR services.

We’re pleased to announce improved support for Python in Snyk Open Source, allowing developers to remediate vulnerabilities in dependencies with the help of automated fix pull requests!

The vulnerability was found in the Apache JServ Protocol (AJP). The issue is that this binary protocol allows an attacker to read or include any file into Tomcat webapp directories.

We are excited to announce our new strategic partnership with Rapid7, a leader in security analytics and automation.

Our updated reporting feature makes it even easier for you to create application security reports.

This post discusses the concept of “Digital Trust,” why it matters at Snyk, and how we make it a priority.

On February 7th, 2020 I received an anonymous tip through the “leak inbox” of the Israeli CyberCyber podcast.

Implementing an airtight content security policy can go a long way in terms of protecting a site against XSS attacks.

You can now scan container images stored in JFrog Artifactory with Snyk Container.

Today, Node.js announced a critical security vulnerability. All actively supported versions 10.x, 12.x, and 13.x of Node.js are vulnerable. We’ll address how the vulnerability works what fixes are available.

Snyk’s annual JVM ecosystem report presents the results of the largest annual survey on the JVM ecosystem, which gathered over 2000 responses in the second half of 2019.

Our annual JVM ecosystem report presents the results from the largest annual survey on the JVM ecosystem (which gathered over 2000 responses in the second half of 2019).

Snyk’s annual JVM ecosystem report presents the results of the largest annual survey on the JVM ecosystem, which gathered over 2000 responses in the second half of 2019.

Snyk’s annual JVM ecosystem report presents the results of the largest annual survey on the JVM ecosystem, which gathered over 2000 responses in the second half of 2019.

Snyk’s annual JVM ecosystem report presents the results of the largest annual survey on the JVM ecosystem, which gathered over 2000 responses in the second half of 2019.

Snyk’s annual JVM ecosystem report presents the results of the largest annual survey on the JVM ecosystem, which gathered over 2000 responses in the second half of 2019.

This post outlines some of the work we do at Snyk to protect and maintain a supportive and collaborative culture as the company grows.

Deeply integrated security increases the sense of shared responsibility. Having a sense of shared responsibility across the organization contributes to an elevated security- first mindset among employees who will seek out to question and challenge solutions regarding the security impact of the products they build.

A monthly review of news from Snyk, and from the larger security space.

Local storage has caught the attention of developers as a lightweight solution for data storage that doesn’t involve databases or even the server. That’s neat, but is it always a good idea to use it? Here are a few thoughts from the folks at Snyk.


As we look into the way engineers audit their code bases, we see a strong adoption of automated security tooling, according to the Snyk State of Open Source Security report 2019, with 65% of respondents confirming that observation. It is also important to point out that, even when automated security tools are employed, 79% of the respondents still use security code reviews.

With every data breach disclosed, organizations become more aware of the need to address security early on and throughout the SDLC to ensure customer privacy and assets, feature security, and delivery speed. To do it all well, DevSecOps must be driven by security, but powered by developers.


This post measures the cost of implementing security against the cost of a security breach.

Digital transformation is a powerful movement influencing businesses of all sizes to integrate technology deeply into their operations. However, as companies adapt to this new landscape, security often lags behind. To effectively respond to the challenges posed by digital transformation, it’s essential to understand the major changes it brings, particularly in areas like Digital Business, Cloud, and DevOps, and their implications for security. This understanding is crucial for developing a robust security framework in a digital-first world.

We are thrilled to announce that Snyk has closed $150 million in funding to accelerate our vision to bring a new approach to application security, enabling businesses to continuously build security into their application development process and culture.


On the 11th of December, 2019 a security vulnerability which extends to all major JavaScript package managers (npm, yarn and pnpm) was publicly disclosed. This vulnerability, discovered by security researcher Daniel Ruf, allows malicious actors to apply varied tactics of arbitrary file overwrites.

Tasks for Azure Pipelines enables users to customize and automate an Azure Pipelines CI/CD workflow with a group of ready-to-use tasks that can be inserted into pipelines from the Azure Pipelines interface.

Connecting Snyk with the repositories you’ve stored in a source code management system such as GitHub or GitLab and then importing your projects to Snyk is a great way to leverage and benefit from security application testing throughout your core application development workflows.

Snyk CEO Peter McKay was recognized as a member of the top 10 “Best CEO” list by Comparably as part of their “Best Places to Work 2019” awards!

A summary of two malicious typo-squatting packages recently removed from the Python Package Index.

Snyk’s Director of Developer Relations, Liran Tal, discusses deploying a Gatsby site to GitHub pages.

Chef co-founder and CTO Adam Jacob joins the Secure Developer podcast to discuss security, DevOps, and what “continuous delivery” really means.

A look into some of Snyk’s defining values.

A look into how Coveo uses Snyk to solve license violations and security vulnerabilities.

How exploits in the wild translate into greater risk, how we can evaluate that risk, and discuss how to prioritize and quickly handle your vulnerabilities accordingly.

As 2019 draws to an end, we are going to be looking back on some great episodes of our podcast The Secure Developer.

Building on the new Kubernetes features in Snyk Container, we’ve been experimenting with integrating vulnerability data more closely into the Kubernetes ecosystem.


Similar to our report on Docker image security, we wanted to take a look at the state of vulnerabilities in the public Helm Charts repository.

James Kaplan is a partner at McKinsey & Company and co-leader of its cybersecurity practice. He’s been with the company for 20 years and is one of the lead partners in what they call “McKinsey Technology.” His specific expertise as a leader in the company’s IT infrastructure and cybersecurity service lines informed the topics discussed during a recent episode with the Secure Developer podcast.

Kind is a Docker-based tool for running local Kubernetes clusters that conform to the Kubernetes API. It fit Snyk’s needs perfectly, as it combines the advantages of having a clean environment for every test, with the advantage of a very fast setup.


The article discusses enhancements in container security integration within the Software Development Life Cycle (SDLC), focusing on the new Kubernetes integration offered by Snyk Container. It highlights the challenges of testing security locally, in the CI/CD pipeline, at the registry, and within Kubernetes clusters. The aim is to simplify security assessments in Kubernetes and provide developers with timely access to security information, enabling quicker fixes for vulnerabilities and improved overall Kubernetes security.

Snyk is excited to announce that today we are launching Snyk Container, a new product that helps developers easily find and fix vulnerabilities in their container applications.

This is the final part of a four part series about building your Kubernetes AppSec strategy.

We are excited to announce the release of a new way to take action on the deep insights Snyk offers regarding security and project health — auto upgrades.

In one of our previous posts we discussed how packaging of applications is shifting to developers as organizations embrace containers. But it’s not just packaging that’s moving from systems administration to development — it’s configuration management as well.

Welcome to Snyk’s State of JavaScript frameworks security report 2019. In this section, we review the impact that security vulnerabilities can have by looking at the severity, CVSS scores and more over the years for both Angular and React.

Welcome to Snyk’s State of JavaScript frameworks security report 2019. In this blog post we’ll review security vulnerabilities found in other frontend ecosystem projects.

Welcome to Snyk’s State of JavaScript frameworks security report 2019. Let’s begin this report by exploring the different security vulnerabilities found in the core Angular and React projects.

Welcome to Snyk’s State of JavaScript frameworks security report 2019. In this section, we review the security risk of the indirect independencies for both Angular and React, and then we also review the direct dependencies, first for Angular and then for React.

Welcome to Snyk’s State of JavaScript frameworks security report 2019. This section of the report is about Angular and React projects overall security posture.

Snyk’s State of JavaScript Frameworks Security Report 2019 explores the security landscape of the Angular and React ecosystems. It examines best practices, secure coding techniques, and identifies security vulnerabilities across popular frontend frameworks like Angular, React, Bootstrap, Vue.js, and jQuery. The report is available for download in PDF format, allowing readers to review the findings offline.

When it comes to security, the movement toward DevOps is really just beginning. If we want security to make this move effectively, we need to carefully select tools and deliberately build culture.

PCI has many requirements that apply to the implementation, configuration, and development of payment software. As with other compliance frameworks, these standards evolve over time. Several elements of this updated framework relate to third-party libraries, security best practices, and topics developers should understand deeply.

The container image, technically defined in the OCI image specification, is a key component of modern tooling, from Docker to Kubernetes to platforms like AWS Fargate and Google Cloud Run. What does this mean for application security?

We’re thrilled to join CloudBees’ new Technical Alliance Partner Program to take our collaboration with the CI/CD and application release orchestration (ARO) company to the next level.

In the State of Open Source Security Report 2019, we set out to measure the pulse of the open source security landscape throughout the different language ecosystems and have analyzed responses from over five hundred open source maintainers and users who provided us with insights into their processes and knowledge of open source security risks as well as the skill level of the average maintainer.

Open Policy Agent (OPA) is an open source general-purpose policy engine, and Rego is OPA’s declarative policy language. Combined with Fugue, it provides maximum flexibility when implementing cloud infrastructure policy.

We’re excited to announce a new strategic partnership with Trend Micro to help businesses quickly deliver secure applications.

We are excited to share that we now support customized license instructions, helping the teams in your organization collaborate better together on licensing compliance: legal teams can better equip developers to shift compliance left by customizing license policies with clear instructions, and developers can then more easily integrate license analysis as part of their routine workflow.

Snyk wants to help developers adopt a security mindset throughout their development process, and The Secure Developer community is the place where you can do just that

In this post, we show you how easy it is to introduce back doors that are easily missed by project owners… leaving your code insecure.

The Auth0 team uses Snyk to “make sure we are running on a secure foundation, no matter what.”

Here at Snyk we try to make the process of choosing the most secure base image smarter, smoother and most importantly, more data-driven. First, let’s start with some background about Linux distro security, since we focus on Linux-based images in this blog post.

In this cheat sheet edition, we’re going to focus on ten Java security best practices for both open source maintainers and developers.

We’ve written about SQL Injection and ORMs in more detail in the past. In this post, we’ll focus on the recent SQL injection example that the Snyk team discovered in the popular npm library sequelize.

The Snyk Team is thrilled to announce we have raised $70 million investment, led by Accel and existing investors GV and Boldstart Ventures, to further boost our growth and leadership in the dev-first security market!

Hey I’m Luke, an engineer at Snyk based in Amsterdam. I wanted to share my story about making climate positive changes.

An underrated feature of Jest is customizing the way assertion errors that the console displays when tests fail are handled.


This post explores how to make it easier to switch between different Node.js versions and to switch between different npm registries while working in a development environment.

On August 19th, 2019 rest-client, a simple HTTP and REST client for Ruby, reported a new security threat. A maintainer’s RubyGem account was compromised and a malicious third party installed a code execution back door. The exploit affects versions greater than 1.6.10 and less than 1.7.0.rc1.

On July 29th, 2019 a high severityDeserialization of Untrusted Data vulnerability (CVE-2019-14379,CVE-2019-14439) affecting all versions of com.fasterxml.jackson.core:jackson-databind up to 2.9.9.2 was published.

On August 17, 2019, the Webmin team announced the release of Webmin 1.930 and Usermin 1.780. These releases address a newly discovered remote command execution vulnerability found in Webmin versions 1.890 through 1.920. This vulnerability has been present for more than a year and was introduced by a malicious third party.

We’re excited to share that starting today, you can make sure that vulnerable artifacts will not be used in your organization by using Snyk’s Artifactory plugin!

We’re excited to announce that Snyk has partnered with CircleCI to help you use open source and stay secure.

I examined Eclipse IDE plugins and then narrowed it down to the top 10 most helpful plugins that I have added to my own toolkit.

Kubernetes is an open source container orchestration engine for automating deployment, scaling, and management of containerized applications, and is the largest project in the CNCF ecosystem.

We are excited to share that starting today, developers can test and monitor their Go projects, which use modules, for open source vulnerabilities and get precise and accurate package-level alerts.

The first question many customers ask us after purchasing Snyk is—now how do we roll out the product throughout the company? In this post, we’ll outline some best practices for getting started with Snyk at your organization.

Snyk is excited to share that we’ve recently added new integrations with your container registries, including Amazon Elastic, Google and Microsoft Azure container registries (ECR, GCR, ACR).

This is a technical exploration of how the Capital One breach might have occurred, based on the evidence we have from the criminal complaint.

Snyk curates security patches for open source JavaScript projects in the npm ecosystem. By doing so, we help maintainers keep their packages safe and stay ahead of the security curve even when they aren’t free themselves to fix security issues immediately.

We are excited to share that developers can now test and monitor their projects for open source vulnerabilities, natively from within their Eclipse IDE (integrated development environment) instance.

Welcome to our new security report: .NET open source security insights.

Welcome to our new security report: .NET open source security insights.

Welcome to our new security report: .NET open source security insights.

Snyk has acquired DevSecCon, the leading conference focused on DevSecOps, which emphasizes collaboration between developers and security teams. Under the guidance of Francois Raynaud, Snyk and DevSecCon aim to create a vendor-neutral environment to enhance the DevSecOps community. They plan to provide more support and resources, hosting nine global conferences throughout the remainder of 2019 and into 2020.

The growth of open source alongside the lagging security standards has led many regulatory bodies and industry watchdogs to move toward stricter and clearer rules around how to protect applications that include open source code.

Snyk brings this dev-first, product-led approach to the security industry, on a mission to solve software security efficiently and at scale. To help us realise that vision, I’m excited to announce that Peter McKay - a Snyk board director, a top tier tech executive and my good friend of 15 years - is joining us as Snyk’s CEO!

Functions are often short-lived and deployed in large numbers and are invoked more and more frequently as you scale. For these reasons, it’s easy to lose track of the flow of events or to pinpoint the root cause for any given error.

In this post, we’ll look at how New10 has leveraged both AWS and Snyk to deliver value to their customers faster and with security always at the forefront.

On July 5th, 2019, the CVE-2019-13354 security advisory was published for a malicious version of the strong_password Ruby gem which allows for remote code execution in applications bundling the vulnerable dependency.

On July 2nd, 2019, Snyk published a high severity prototype pollution security vulnerability (CVE-2019-10744) affecting all versions of lodash, as the result of an on-going analysis lead by the Snyk security research team.

To emphasize the complexity of tracking a function’s dependencies, in a recent State of Open Source Security report 2019 Snyk showed that security vulnerabilities in indirect dependencies account for 78% of overall vulnerabilities.

Snyk has partnered with O’Reilly to offer a new book

Cryptocurrency wallet developer Komodo has been in the news recently as the most recent victim of an attempted cryptocurrency attack by malicious code injection via npm dependencies.


Fugue’s visualization feature enables DevOps teams, security engineers, and compliance analysts to auto-generate diagrams of their cloud environments.

Here’s the first installment of our bi-weekly updates on what’s new in Snyk.

June 4th is a historic date: it’s the date that the millionth package was indexed into the npm registry. npm is a package manager for JavaScript packages. The core component of npm is its public registry, hosting JavaScript packages that can be accessed by the npm client to build JavaScript applications.

10 serverless security best practices for securing your serverless and cloud functions, from managing secrets, to data security, function isolation, least privileges and many more!
![Java Top 10 Security Vulnerabilities Disclosed [2019 - List]](/article-images/d2d14ec2-e670-4c4a-b5bf-6d4aa2681bf7.webp)
In this post, we’ll take a look at the vulnerabilities that have been found in the top ten Java libraries picked by OverOps, and focus on three of them in more depth.

We are pretty excited to share that last week Snyk was recognized as a ‘Next European Unicorn’ at the 2019 Vivatech Awards.

Snyk’s goal is to help you use open source in a secure way. Vulnerabilities are one indicator that a dependency is unhealthy, but there are other risk factors at play as well. For that reason, we have a whole team working on making Snyk the go-to destination for information about your dependencies – from Security to License information, and now to Health.

One of FIRST’s initiatives is a Special Interest Group (SIG) that is responsible for developing and maintaining the Common Vulnerability Scoring System (CVSS) specification in an effort to help teams understand and prioritize the severity of a security vulnerability.

This post discusses the CRLF injection vulnerability recently discovered in a popular Python library and provides guidance on how you can protect your Python project.

We’re launching a new JVM Ecosystem Survey for 2019. The goal of this survey is to understand the lay of the land across the entire JVM ecosystem, and Java in particular.

Mismanaging the configuration of your Amazon S3 resources can lead to significant security and compliance incidents. Learn how to prevent these risks.

Affected versions of axios are vulnerable to Denial of Service (DoS) because content continues to be processed from requests even after maxContentLength is exceeded, causing increased I/O and CPU usage.

This post outlines Snyk’s 8 security best practices for working with Azure Repos.

Having team-wide rules that prevent credentials from being stored as code is a great way to police bad actions in your existing developer workflow.

If you find sensitive data in your Azure Repos repository, you need to do several things to recover, including invalidating the tokens and passwords that were once public.

Adding a SECURITY.md file to your Azure Repos helps your users find the information they need and encourages maintainers to consider general security practices.

By adding Snyk’s native integration with Azure Repos, each pull request will be tested to ensure new vulnerabilities aren’t introduced into the code base. Policies can be defined to configure the severity level of a vulnerability that fails the merge. The following image displays a failed PR due to new vulnerabilities that it would have added:


Following the rule of least privilege, ensure that contributors exist in the correct groups and therefore have the necessary permissions to work. Try to restrict administrative actions where possible.

Using two-factor authentication adds an additional level of security to your Azure Repos.

Azure Repos access is typically done using SSH keys or personal access tokens (in lieu of a password). But what happens if those tokens are stolen and you didn’t know? Be sure to refresh your keys and tokens periodically, mitigating any damage caused by keys that leaked out.

In this blog, we take a look at the libraries that, because they contain today’s most common vulnerabilities, also most frequently appear in Snyk project scans.

Starting today, developers can test, fix, and monitor their Azure Repos projects for open source vulnerabilities.

We’re continuing to extend our Container Vulnerability Management offering, now providing integration with your container image registries as well.

Docker Hub may have reset your account details if it detected that it was part of the breach. What could potentially happen? What should I do to protect my code?

How many packages on npm can be considered abandoned? How many packages are connected to each other? Let’s explore npm - today’s biggest open source package registry!

Welcome to the Docker security report “Shifting Docker security left.”

Welcome to the Docker security report: Shifting Docker security left.

Welcome to the Docker security report “Shifting Docker security left.”

Welcome to the Docker security report “Shifting Docker security left.”

On March 26th, 2019, almost three years after the last jQuery security vulnerability was disclosed, we recently learned about a new security vulnerability affecting the same popular jQuery frontend library.

In this cheat sheet we’ll cover how you can be more secure as a Bitbucket user or contributor. Some of it is specific to Bitbucket, but a lot of it is also useful for other Git and non-Git repositories as well.

Our publicly available Vulnerability DB is one such example, and has recently undergone some improvements — making it even more powerful as an aid to security.

We are excited to share that starting today, developers can import, test, fix and monitor their Bitbucket Cloud projects for open source vulnerabilities. Being developer-focused, Snyk is the only solution to provide native testing and fixing of open source dependencies for Bitbucket Cloud.

On March 26, 2019, a malicious version of the popular bootstrap-sass package, that has been downloaded a total of 28 million times to date, was published to the official RubyGems repository.

A recent experimental feature for introducing integrity policies landed in Node.js core 11.8.0. This capability, shipped in non LTS version yet, provides integrity checks for a Node.js runtime when modules are being loaded, in order to verify that the modules code haven’t been tampered with.

With our integrations and plugins for leading CI/CD platforms, Snyk enables a further, more DevOps-focused security gate through the pipeline.

In this article we will discuss both npm’s package lock file package-lock.json as well as Yarn’s _yarn.lock.

Welcome to another edition of our Snyking In exploit series! In this episode, we’ll be looking at the regular expression denial of service vulnerability, demonstrating how it can be exploited, as well as the potential risk they pose to your data and systems.

We’re delighted to announce a new partnership with the Linux Foundation to support the launch of CommunityBridge.

At QCon London this week, the Security Transformation track featured insightful presentations from speakers including Michael Brunton-Spall, Gareth Rushgrove, Shraya Ramani, and Kevin Gilpin. The strong turnout of at least 100 attendees at each session highlighted a growing interest among developers in enhancing their security knowledge and practices. The event showcased a commitment to advancing security awareness and transformation within the development community.

In the spirit of Interntional Women’s Day, Snyk wants to take a moment to celebrate the contributions of the women in our company and to invite our community in London to our International Women’s Day event.

n this post, we’ll look deeper into Docker images and the container ecosystems that were covered in our State of Open Source Security report, including our finding that the top ten Docker images contain over 8,000 vulnerable paths.

Snyk now integrates with Bitbucket Pipes, which allows Bitbucket users to secure their continuous integration/continuous delivery (CI/CD) workflow by finding, fixing and monitoring open-source vulnerabilities (vulns) in their application or docker image dependencies.

Only one in three developers can address a high or critical-severity vulnerability in a day or less. The more we use open source software, the more risk we accumulate as we’re including someone else’s code that could potentially contain vulnerabilities now or in the future.

A worrying 27% of respondents stated they do not have any proactive or automatic way to find out about newly discovered vulnerabilities in their applications. 37% of users of users don’t implement any sort of security testing during CI.

A good number of security vulnerabilities are discovered and fixed in non-official channels. We measured Snyk DB to uncover 67% more vulnerabilities than public databases. In 2018, new disclosures for npm grew by 47%, and Maven Central grew by 27%

Maintainers stated their security knowledge is improving but not high enough, averaging 6.6/10, and 1 in 4 open source maintainers do not audit their code bases.

Regex for for a single-threaded runtime could be devastating. We’ve also detected that the npm ecosystem has seen the most XSS vulnerabilities, Maven Central and PyPI follow next.

we found that 44% of docker image scans had known vulnerabilities, and for which there were newer and more secure base image available. Most vulnerabilities originate in the base image you selected. For that reason, remediation should focus on base image fixes.

Welcome to the first edition of a new exploit series we’re calling “Snyking In”! We’ll be looking at various security vulnerabilities, demonstrating how they can be exploited, as well as the potential risk they pose to your data and systems.


This post, co-written by Weaveworks and Snyk, explains how by using a GitOps continuous integration (CI)/continuous delivery (CD) pipeline combined with good security practices improves the overall security of your development workflow to Kubernetes.

Concerned about npm vulnerabilities? It is important to take npm security best practices into account for both frontend, and backend developers. Open source security auditing is a crucial part of shifting security to the left, and npm package security should be a top concern, as we see that even the official npm command line tool has been found to be vulnerable.

Today Snyk is happy to announce the launch of The Secure Developer, a community and educational resource for all things security. We’ll bring together the greatest security experts to share their experiences on building security into their workflows, discussing tools that can help, and reviewing good and bad practices seen in the real world.

A security flaw discovered by Adam Iwaniuk and Borys Popławski and found in open source software runC was disclosed on February 11th, 2019 and described in CVE-2019-5736.


We’re happy to share that we’ve just extended our Docker scans to now include scanning key binaries that were manually installed on the Docker image. Up until now, we only scanned OS packages that were installed by OS package managers such as dpkg, apk or rpm.

Infrastructure misconfiguration is the leading cause of data breaches in the cloud, and a big reason misconfiguration happens is infrastructure configuration “drift.” While some drift events can lead to data breaches, not all of it is bad. Understanding the distinctions is important if you’re responsible for cloud security and compliance.

A recently discovered vulnerability in NumPy, the widely used open source package for scientific computing in Python, allows for the execution of arbitrary, potentially malicious code.

As of today, Snyk enables importing, scanning and monitoring of .NET projects directly within GitHub, GitLab, and Bitbucket without having to move away to Snyk.

When I tried to fix the situation, I realized how little I actually knew about the event-loop behavior and gained some realizations that at first surprised me and some fellow developers I shared this with. I believe it’s important that as many Node developers will have this knowledge too - which led me to writing this article.

Earlier this month it was found that Bower, a popular web package manager, is vulnerable to archive extractions and currently, we can associate two security incidents with it, for which follow-up releases to address them are available:

Today we’re delighted to share that we’re launching our Open Source Security Runtime Monitoring solution, in beta, to all users, with no limitation on usage! While Snyk invests heavily in making fixing vulnerabilities ridiculously easy by baking it into the development workflow, handling a large backlog of issues can be time-consuming.

On 30th of April, 2018, Node.js 4 was officially marked as End of Life (EOL) and ceased to receive security updates. At Snyk, we have been committed to continued support for Node.js 4 in our CLI tool, but the time has finally come to wave goodbye.

Snyk was happy to implement code insights, a new functionality by Bitbucket, to allow Bitbucket Server users to view detailed results of Snyk’s vulnerability scan, all within Bitbucket itself.

Business Insider recently published its annual list of promising enterprise startups for 2019, where Snyk is recognized for its potential success. While the article emphasizes valuation and investment opportunities, Snyk is also eager to share additional insights about the company, particularly for those contemplating a career change this year. This could be a beneficial New Year’s resolution that remains relevant throughout the year.

Starting from January 2019, Snyk’s vulnerability database will no longer be integrated into the Xray platform. Snyk vulnerabilities observed through scans done prior to January 2019 or databases not updated since then will remain visible in Xray dashboard. New scans following January 2019 will not include any Snyk vulnerabilities.

Snyk’s Liran Tal looks back at the year 2018 in developer security.

An examination of the critical Kubernetes vulnerability identified as CVE-2018-1002105, which allows an attacker to gain remote access to backend services that reside in the Kubernetes cluster and execute arbitrary commands on them. We look at key takeaways and methods for protecting yourself from image vulnerabilities.


We take a look at the House Oversight and Government Reform Committee’s report on the Equifax breach, what their findings mean, and how good DevSecOps practices can help to prevent this kind of breach.


In this post, we take ten minutes to build an automated development pipeline with Codefresh, baking in security testing with Snyk. The goal is to keep the tests short and sweet, so we can get back to coding and shipping features.

For the past few months, we have been working hard to improve our lockfile support both in the CLI and web. The new functionality already exists in the CLI and it’s currently being gradually released on the web and it will be soon enabled by default for all of the organizations.

A look back at the chain of events that led to the use of the malicious npm package “flatmap-stream” and a reflection on what it means for the fragility of open source.

An overview of how the malicious flatmap-stream npm package operates, and remediation steps to follow if you’ve been affected.

Guy Podjarny gives an overview of his talk about Serverless Security from the Serverless Computing conference in London.

Snyk released its application security runtime monitoring solution, allowing developers to monitor the behavior of their open source components in runtime


Welcome to the largest survey ever of Java developers. The data presented in the following report was taken from more than 10,200 questionnaires, covering JDK vendors, versions, IDEs, build tools, CI servers, Java EE versions, web frameworks, JVM languages, binary repositories, source code repositories, source code management and much more!

Welcome to the largest survey ever of Java developers. The data presented in the following report was taken from more than 10,200 questionnaires, covering JDK vendors, versions, IDEs, build tools, CI servers, Java EE versions, web frameworks, JVM languages, binary repositories, source code repositories, source code management and much more!

Welcome to the largest survey ever of Java developers. The data presented in the following report was taken from more than 10,200 questionnaires, covering JDK vendors, versions, IDEs, build tools, CI servers, Java EE versions, web frameworks, JVM languages, binary repositories, source code repositories, source code management and much more!

Welcome to the largest survey ever of Java developers. The data presented in the following report was taken from more than 10,200 questionnaires, covering JDK vendors, versions, IDEs, build tools, CI servers, Java EE versions, web frameworks, JVM languages, binary repositories, source code repositories, source code management and much more!

We’ve been approached by many customers asking for help in creating hundreds of orgs, many times with identical configurations such as license policies that are shared throughout the company. Setting up integrations and license policies for each org can be time consuming, so we focused on how we could speed up that flow.

Today we’re delighted to share that we’re launching a free-tier version of our Container Vulnerability Management solution, in general availability. Our Container Vulnerability Management solution enables developers to test, fix and monitor open source


Our JVM ecosystem survey results, shows Maven’s dominance continues into 2018, and doesn’t look like it’s going anywhere with six in ten developers using the build tool in their main project. In this cheat sheet we provide 10 security best practices for how you can enhance your Maven-foo.

Snyk announces a $22M series B fundraise led by Accel! It’s a huge vote of confidence in Snyk’s unique developer-first approach, and in the belief that developers are ready to own and fix open source security

When installing random Python packages from PyPI, there’s a significant 13.5% chance that a package lacks licensing information. Given the typical Python application often includes numerous dependencies and sub-dependencies, this raises the risk of inadvertently using unlicensed code. The implications of utilizing unlicensed software can vary widely, from minimal consequences to severe repercussions. The article aims to explore this issue more thoroughly.

We’ve made some improvements to our Slack notifications to make them more useful and actionable.

We’ve just released a shiny new API endpoint that will let you import your repositories, projects, functions and apps so that they are monitored for vulnerabilities.

This month’s cheat sheet is about how you can secure your Spring Boot application. Spring Boot has dramatically simplified the development of Spring applications. Its autoconfiguration and starter dependencies reduce the amount of code and configuration you need to begin an app. If you were used to Spring and lots of XML in back in the day, Spring Boot is a breath of fresh air.

In June 2018, the Snyk research team discovered numerous exploitable instances of the Zip Slip vulnerability across various ecosystems, affecting thousands of applications. Recognizing the severity of this widespread issue, they emphasized the importance of a careful private disclosure process. This approach ensures that vulnerable libraries and projects are informed of their risks before any public announcements are made. The post details the team’s journey from the discovery of the vulnerability to the creation of fix pull requests and their subsequent steps.

It’s true you can crash an email server with a single email! This guest blog post talks about a vulnerability found in the top five Node mail parsers that will bring each of them down just by clicking send. Joran Greef explains how he found the vulnerability while he was writing his own mail parser and how he disclosed via Snyk’s security team.

The time has come for you to take responsibility of your application security. This may sound daunting to some of you, but don’t fret! There are many resources available to you, including The Secure Developer podcast, run by Snyk’s very own CEO, Guy Podjarny

This post covers some higher-level software engineering principles demonstrated in my experience with Python testing over the past year and half. In particular, I want to revisit the idea of patching mock objects in unit tests.

Zip Slip is a form of a Directory Traversal that can be exploited by extracting files from an archive. This cheat sheet informs you of vulnerable libraries and code snippets that are exploitable to a Zip Slip attack. Additionally it provides you with the information you need to upgrade to fixed library versions and offers tips on how to find and fix your own vulnerable code.

Containers are becoming the standard form in which applications are packaged and executed, so the need to protect not only the application itself but the entire container against open source vulnerabilities is growing.

In this post we’ll look at the most common types of vulnerabilities for two of the main ecosystems we track in our vulnerability database, namely Maven Central and npm. The Snyk Vulnerability database consists of vulnerabilities from over 1,000,000 open source packages we track that use Composer, Go, Maven Central, npm, NuGet, pip and Rubygems.

In recent months, Snyk has collaborated with customers to enhance the remediation process for vulnerabilities using various issue trackers, with a particular focus on integrating with Jira. Customers expressed a strong desire for this integration to effectively track the status of Snyk vulnerabilities and license issues through their lifecycle—from initial disclosure to assignment and remediation. The aim is to accelerate the workflow and simplify the process of creating Jira issues.

One of our most frequent feature requests recently has been for the ability to generate an API token that isn’t tied to a particular user. We’re excited to be able to now offer our pro and enterprise customers the ability to create service accounts – a special type of user that has an API token associated with it.

The Snyk Security team is today announcing the public disclosure of a critical arbitrary file overwrite vulnerability called Zip Slip. It is a widespread vulnerability which typically results in remote command execution. The vulnerability affects thousands of projects.

We’re extremely humbled and honored to have Gartner name Snyk as a May 2018 Cool Vendor in Application and Data Security!

We’re excited to launch the a brand new survey called the JVM Ecosystem Survey 2018 in partnership with the Java Magazine. Also, if we reach 2,500 responses, we’ll give $2000 to Devoxx4Kids!

Skyscanner today monitors nearly 500 separate projects with Snyk, and is able to understand the state of their security as well as address both their vulnerability and licensing issues. This case study shows why Skyscanner chose to use Snyk and the benefits they see every day.

Java 10 introduces Local Type Inference, enabling developers to use the ‘var’ keyword to replace explicit type declarations in their code. While this feature can enhance coding efficiency, understanding its proper application is crucial for its effective use. The provided cheat sheet and blog serve as a condensed guide, based on a more extensive post by Stuart Marks on the OpenJDK site, helping developers to grasp how and when to implement this new feature.

Guy Podjarny live hacks a Node.js application to exploit vulnerabilities in real world packages. In this edited down video from the JSKongress conference. Guy explains where some of the most common JS security pitfalls exist.

Snyk identified and responsibly disclosed a directory traversal vulnerability found in FTP clients that connect to malicious servers. This post contains the full details of the vulnerability and what you can do to avoid it.

We’re excited to announce that Snyk is now powering the brand-new vulnerable JavaScript audit in Google Chrome’s Lighthouse — the auditing tool built by the Google Chrome team that checks your site’s performance, accessibility, and security.

Snyk has recognized the importance of email alerts for users to stay informed about project issues. Previously, there was limited configuration for these alerts regarding the types of problems that would trigger them. As Snyk expands its language support and allows users to monitor more projects, the aim is to enhance user control over alert configurations. This will help users focus on relevant issues while reducing notifications about less significant problems.

DigitalOcean found and fixed a critical vulnerability within one day of disclosure using Snyk’s automated remediation system.

Comic Relief integrated Snyk into their Concourse CI Serverless deployment pipeline — allowing even the most junior of developers use open source securely by remediating any vulnerable libraries before they go to production.

We’re excited to announce our $7M Series A, and feel this is a great opportunity to say thanks!

We’re excited to announce a new feature for our Pro and Enterprise Plan customers that makes it possible to split your organization into teams, who can manage different projects.

Ignoring security issues shouldn’t be the default action, but sometimes it’s necessary — for example, if an issue doesn’t currently have a fix, you might want to snooze it until it does. Thankfully, Snyk makes it suppress issues that are currently irrelevant.

Welcome to a guide to the basics of mocking in Python!

A vulnerability is a vulnerability, whether known or not. The key difference between the two is the likelihood of an attacker to be aware of this vulnerability, and thus try to exploit it.

You can’t go to a security event nowadays without hearing at least a few speakers say the phrase “DevSecOps”. The term has turned into a rallying cry for an approach that automates security throughout the development process. But in order for DevSecOps to succeed, it will first have to die.

The best solution for known vulnerabilities is to upgrade your software. But sometimes there’s not a security update immediately available. The next best solution is to patch your software. In this post, we go through four ways to find security patches for open source software.

Open source maintainers give up their own time to create great pieces of free software, which we then use to create business value. In our State of Open Source Security Report, open source consumers and maintainers were asked about their security expertise, actions and sense of ownership — and the results were very mixed.

Locking or “pinning” dependencies is a widespread best practice in Ruby, Python, and other ecosystems. In Node.js locking was much less widespread, until recently, thanks to the improvements provided by package-lock.json and yarn.lock. This post discusses how each of these solutions works and why you may want to use them.

Stop building security tools that think about development, and start building development tools that handle security.

The Snyk API gives you access to all the issues associated with a given project. In this post, you’ll learn how to use the API to fetch the organisations you have access to, the projects for a given organisation, and all the issues for a given project.

Snyk has always been committed to making it easy to use open-source code without compromising security. Today, we’re taking another leap forward and launching support for .NET, Go and PHP!

Bower is no longer the dependency manager of choice for front-end projects. While the open source project is still maintained, its creators decided to deprecate it, and have advised how to migrate to other solutions. In this post, we explain why Bower used to be great, list six reasons why it isn’t necessary anymore, and explain how to move on to newer and better technologies.

Last week, we released our first annual State of Open Source Security report. One of the discoveries the report mentions is that an analysis of around 433,000 sites found that 77% of them use at least one front-end JavaScript library with a known security vulnerability. In this post, we take a deep dive into that problem space.

Today we’re excited to launch the 2017 State of Open Source Security Report! The full report is available as a free PDF, and the highlights are collected online.

Whether a vulnerability is currently exposed or not matters, but only in prioritization. Where its exploitable today or not, leaving it unaddressed is a unnecessarily risky decision.

One of the biggest bottlenecks in security is ’triaging’—the process of validating if a security alert is actually impacting your organization, sizing up the estimated impact, and figuring out how to resolve it. In this article, we’ll make the case that we should all be striving to skip triaging and focus on fixing vulnerabilities instead.

Earlier this year we ran a test on the top 5,000 URL’s on the web and found that 76.6% of them were running a JavaScript library with at least one known security vulnerability. It’s a frighteningly large number. That’s why we’re proud to announce that Snyk now powers the vulnerable JavaScript libraries linter in Microsoft’s Sonar—an open-source linting tool for developers.

Python 3 and Python 2 have various functional differences. On their own, they’re not necessarily better or worse (though arguably Python 3 should be an improvement), but any change may introduce risk. This post highlights and explains a few differences between the versions that have security implications.

Where just a few months ago we launched Snyk for Serverless, we are now taking it to the next level by launching the Snyk Heroku Add-On. The add-on is currently in beta, which means it’s free to try out! We’re looking for people to take it for a test drive and provide us with some feedback.

After years of preparation and debate, the General Data Protection Regulation (GDPR) was finally approved by the EU with enforcement starting as early as May 2018, at which time those organisations in non-compliance will face heavy fines. In this post we explain how that impacts companies using open-source and how they can protect themselves.





Today, we’re taking another leap forward and launching support for Python, Scala and Gradle!


Today we’re happy to announce that we’ve launched support for testing Cloud Foundry applications for vulnerable libraries with Snyk!

It’s been over 10 years since Cross Site Scripting (XSS) became big news, awareness has grown and defenses have become much more sophisticated. But, as we show in this post, recent data indicates XSS attacks are only increasing.

Snyk has launched our next integration with Bitbucket Server, Atlassian’s Git solution for professional teams.

Snyk Enterprise is now available on the UK government G-Cloud digital marketplace! Government services can now easily use Snyk to protect their applications against known vulnerabilities in their dependencies—an increasingly important consideration.

The OWASP Top 10 is a well known index of web app security vulnerabilities which is used every day by security professionals, but it doesn’t currently take into account how often those vulnerabilities are used by hackers. We dug through security breach records to see which vulnerabilities are exploited most frequently.

Today Guy Podjarny had the pleasure of presenting at the amazing ServerlessConf in Austin, Texas about security in a serverless world. Here are the slides from his talk, “Serverless Security: What’s Left to Secure?”

Today we’re excited to announce Snyk’s new solution for securing your serverless functions, designed to easily integrate and protect serverless-based applications!

By its very nature, Serverless (FaaS) addresses some of today’s biggest security concerns but it doesn’t fix it all. This post outlines the top areas where Serverless helps or hinders our security efforts, offering advice on how to address concerns and thoughts on what’s to come next.

Today we’re excited to announce Snyk’s support for Java and other Maven supporting languages!

We’re excited to announce we’re overhauling our pricing to make Snyk projects, and the ongoing protection they offer, free.

The other week a paper was released that reported that about 37% of sites included at least one JavaScript library with a known vulnerability. We ran our own test and discovered that the reality is much worse—76.6% of sites were using at least one vulnerable library.

In this post, we’ll focus on using type manipulation to circumvent template-frameworks sandboxes.

Peter Benjamin (@pmbenjamin) is a Senior Software Engineer on the Cyber Security Team at Intuit. Peter recently published a fantastic VS Code plugin that brings Snyk test results right into the editor. We decided to ask him a few questions about the plugin to learn more.

Last month, we added a high-severity Prototype Override Protection Bypass vulnerability in the qs package to our database. The fix was released in updated versions of the library about a week ago. This post explains the vulnerability and how to mitigate it.

An interesting whitepaper was released at the 2017 NDSS Symposium discussing a large-scale attempt at determining just how vulnerable client-side JavaScript libraries are. We wanted to share some of our thoughts on the report.

One thing we’ve learned from building complex software for the cloud is that a language is only as good as its debugging and profiling tools. Learn about how we diagnosed and fixed memory leaks in Python code.

We’re big fans of open-source development at Snyk. It’s why we built Snyk in the first place: so people could safely use open-source dependencies without compromising security in the process. That’s why we’re excited to announce our integration with JFrog’s Xray!

This is a guest post from Glenn Gillen. Glenn is one of the co-founders of Voltos, a service to help you securely manage your apps and service credentials, and is a co-contributor to the online course Tiny Security Wins: Quick steps to secure your dev environment. Previously he ran the add-ons ecosystem at Heroku and is an active investor in early-stage developer tools startups.

We recently added a pair of high-severity XML External Entities (XXE) vulnerabilities found in the Nokogiri library to our vulnerability database. This post explains how the vulnerability works and discusses how to fix the exploit in your application.

This post discusses the responsible disclosure of security vulnerabilities.

Doug Wade is a Senior Front-End Engineer at Indeed. Doug built the wonderful gulp-snyk plugin, which lets you seamlessly include Snyk in your Gulp build process. We were really excited to stumble upon the plugin, so we wanted to talk to Doug to hear a little more about it.

Meet pkgbot – the bot making security analyst lives easier at Snyk!

The level of danger when it comes to regular expressions and security is quite high. In this post we explain what a regular expression denial of service is and how to prevent them from happening.


There’s a widespread attack on insecure MongoDB installs that has resulted in over 28,000 databases being held ransom. This post explains the hack, how to protect yourself and what can we learn from it.

Jesse Houwing is a Lead Consultant at Xpirit. Recently he published a really helpful Visual Studio Team Services (VSTS) task making it easier to get Snyk incorporated into your VSTS workflow. We interviewed him to learn more about how he did it.

Since we launched Ruby last month, we’ve been working away on improvements. Today we’re excited to let you know about our extended support for Ruby.


This week we added a high-severity Remote Code Execution vulnerability in the EJS package to our vulnerability database.

Just over a week ago, we were sponsors at the Brighton conference, ffconf. It was a day full of brilliant talks, both thought provoking and useful. Ashley Williams of npm gave a talk titled “A brief history of modularity”, which we felt was particularly relevant to Snyk, and so we thought we’d share a summary of the talk here.

Today, we’re announcing Snyk’s support for Ruby

Today we’re releasing the Serverless Snyk plugin—a plugin for the Serverless framework that helps you to prevent vulnerable packages in your application, using Snyk!

In the latest episode of “The Secure Developer”, I had the pleasure of interviewing Sabin Thomas, VP Engineering at Codiscope.

In 2016, Facebook announced the open-source release of Yarn: an alternative client for the npm registry. While it’s true that Yarn is often much faster than other clients, and that the new lockfile ensures more consistency when your application is installed, the security claims around it are a little over-optimistic.

Well over 80% of successful exploits today occur due to unpatched servers. Approaches such as Serverless & PaaS should dramatically reduce the risk of outdated binaries. Unfortunately, this transition does nothing to secure open source code packages.

We’re excited to announce Snyk for Bitbucket Pipelines, which makes it easy to stay secure if you’re managing your work with the Atlassian product stack.


You can now receive Snyk security alerts via Slack! This blog provides an overview of how to implement Snyk’s Slack integration.

What should I defend my application against? Should I deal with Cross-Site Scripting (XSS) attacks? How about SQL injection? Should I protect myself against cross-site request forgery? The short answer is yes. But as always, it’s not that simple.

A discussion for JS developers about how to have some fun with the useful ECMAScript 2015 “Proxy” feature, which enables you to create a proxy for another object.

Snyk founder Guy Podjarny joins Courtney Nash on the new O’Reilly Security podcast, discussing key topics such as: - Why developers should own security, and why they haven’t done so yet - How can we bring the DevOps revolution into the world of security - What are each of our roles in improving Open Source Security - More tactically, handling vulnerabilities in open source components

A focus on the engineering team goal of getting things shipped, and what helps us achieve this at Snyk. There are several practices we observe in our development cycle that bind well and keep us shipping all the time; this post outlines the philosophy behind our approach and the continuous delivery practices we use.

Dependencies are extremely powerful, but also open up a world of complexity. To successfully secure these packages in your application, you need to consider security as a natural aspect of quality. This means embedding it into your suite of quality tools and practices, making handling security the default.

Despite having been around for over 20 years, HTTPS always remained very lightly adopted – until 2016. Data from two independent sources shows that HTTPS adoption more than doubled from 2015 to 2016. Snyk CEO Guy Podjarny digs into this data.

Creating Snyk’s GitHub integration, released in late June, helped clarify the different steps to truly address vulnerable dependencies, both immediately and in a continuous fashion. These steps are consistent across packaging systems, from npm to Maven to Chef cookbooks. This post explains each step, why they are needed, and how to apply them with Snyk.

We’re removing the Beta tag fromSnyk and adding two long-awaited features: tight GitHub integration and organization support.

We often talk about the growing number of npm dependencies, and how they make us productive and fast or fragile and insecure. But what exactly is an npm dependency? This post defines the ways to look at an npm dependency.

Using a programmable SQL interface such as an ORM (Object Relational Mapping) is a good way to reduce risk of SQL Injection, which is a very bad vulnerability to have. However, ORM packages are not bullet proof. This post explains why you shouldn’t put all your SQL Injection protection eggs in the ORM basket, and what more can you do.

A quick look at the different options for getting Node.js vulnerability alerts, based on the based on the RSS feed of Snyk’s Vulnerability DB.

A recently published vulnerability in the npm marked package shows how attackers can use the flexibility of the Markdown format to introduce Cross-Site Scripting vulnerabilities. This post explains the issue and the fix, and discusses the difficulty of sanitizing complex user input.

With AWS Lambda, your code is automatically scaled to meet requests. This kind of direct computing is on a trajectory of voracious expansion.


Snyk now provides a free service that lets anyone test for vulnerabilities in – and then monitor – any public Node.js GitHub repository.

In this post, we explain how the “Buffer” class works, and why it behaves the way it does. We’ll run an exploit against a vulnerable application, to better demonstrate the ramifications.

Last week, CERT alerted users to the risk of publishing or consuming a malicious npm package. This important risk is not unique to npm, but it is more likely to happen in this ecosystem. This post explains the risk and how you can protect yourself.


A little over 3 years ago, a few friends and I started a group called pasten to participate in the Chaos Computer Club’s Capture The Flag (CTF) competition. It is a jeopardy style CTF, where the participating teams need to solve security related challenges in various categories such as exploitation, reverse engineering, web, forensic & crypto.

Leaking credentials means exposing secrets that provide access to different accounts. The most common types of leaked credentials are passwords, API keys and SSH private keys. In this post, we discuss best practices you can establish as part of your flow to introduce multiple layers of defense that help prevent mistakes.

I’m excited to announce Snyk is now live! Snyk helps you find and fix known vulnerabilities in your Node.js dependencies. These are publicly documented security holes, making them easy for attackers to track and exploit.

For those who haven’t used Emacs, it’s something you’ll likely hate, but may love. It’s sort of a Rube Goldberg machine the size of a house that, at first glance, performs all the functions of a toaster.

HTTPS, HTTP over TLS, has been around since 1994, and has been well adopted by the security sensitive web — online banking, shopping, taxes and more. However, the vast majority of websites (est. 81% to 97%) continue to communicate using clear (unencrypted) HTTP — no matter how insecure that is.

If you work with network infrastructure, you know that it has a tendency to grow warts, that is, it drifts from its original configuration. One of our goals is to prevent this drift from occurring by maintaining your infrastructure’s known good status.