Apache Tomcat: Vulnerable versions downloaded nearly 100K times since PoC

Apache Tomcat: Vulnerable versions downloaded nearly 100K times since PoC

A rapidly exploited vulnerability with a major blast radius A recently disclosed vulnerability in Apache Tomcat, CVE-2025-24813, is drawing significant attention due to its ease of exploitation, rapid adoption by attackers, and ...
Bypassing picklescan: Sonatype discovers four vulnerabilities

Bypassing picklescan: Sonatype discovers four vulnerabilities

Sonatype has discovered and disclosed four vulnerabilities in picklescan, a tool designed to help developers scan Python pickle files for malicious content. Pickle files, used for serializing and deserializing Python AI/ML models, ...
The hidden threat: Tackling malware in your software supply chain

The hidden threat: Tackling malware in your software supply chain

The value of open source is undeniable — 90% of all modern software development depends on it. According to Harvard Business School, in 2024 alone, more than 6 trillion open source software ...
Securing software development with Sonatype Air-Gapped Environment (SAGE)

Securing software development with Sonatype Air-Gapped Environment (SAGE)

Developers everywhere build modern applications from reusable pieces of code downloaded from repositories such as Maven Central ...

New Glibc Flaw Allows Full Root Access on Major Linux Distros

As a fundamental element of nearly every Linux-based system, the GNU C Library, or glibc, acts as a core library connecting applications with the Linux kernel. It provides essential functions for system ...
'everything' matters — why the npm package sparked controversy

‘everything’ matters — why the npm package sparked controversy

The npm package 'everything' sparked some controversy slowly after its publication over the holidays this year ...
Unraveling the Struts2 security vulnerability: A deep dive

Unraveling the Struts2 security vulnerability: A deep dive

In a recent webinar hosted by Sonatype, Chief Technology Officer (CTO) and co-founder Brian Fox and Field CTO Ilkka Turunen discussed the critical security vulnerability affecting Apache Struts2 ...

Coping with Python 3.7 End of Life: A Guide for Developers

Python 3.7 reached end of life on June 27, 2023   The current stable Python release is Python 3.12   Running end-of-life software poses compliance risks   Python is one of the ...