The Sonatype Newsroom | Sonatype Press Releases

The Sonatype Newsroom

Explore Sonatype's latest announcements, media coverage, threat research, brand assets, and more.

Featured News and Stories

June 18, 2026

Sonatype Named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security

Recognized for Completeness of Vision and Ability to Execute

Read More

Miasma campaign poisons 20-plus npm packages, hunts for developer secrets

June 29, 2026

2026: The Year of AI-Assisted Attacks

May 4, 2026

Press Releases

Sonatype Research Labs Marks 15 Years of Software Supply Chain Intelligence

July 14, 2026

Read More

Sonatype Named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security

June 18, 2026

Read More

Sonatype Names Three Industry Veterans to Executive Team to Lead the Next Chapter of Agentic Development

June 9, 2026

Read More

Sonatype Firewall Extends Malicious Package Protection to Any Repository

May 27, 2026

Read More

Sonatype and Package Registry Leaders Unite to Address Open Source Sustainability Crisis

May 6, 2026

Read More

Sonatype Releases Q1 2026 Open Source Malware Index: Trust Abuse Most Successful Attack Vector

April 14, 2026

Read More

Sonatype Threat Research

Powering unmatched visibility and insights

Sonatype’s world-class Security Research team leads the market in identifying and analyzing threats within the open source ecosystem. With a combination of automated intelligence, expert analysis, and secondary expansion, the team uncovers new forms of open source malware, software supply chain attacks, and emerging vulnerabilities. From in-depth reports to real-time threat detection, Sonatype Security Research powers the insights that keep our customers ahead of adversaries and sets the standard for trust in software development.

Learn more

[Sonatype Releases Q1 2026 Open Source Malware Index](/content/press-releases/sonatype-q1-2026-open-source-malware-index "Internal link to Sonatype Releases Q1 2026 Open Source Malware Index blog post"/index.html)

Read More

[Unnecessary Risk: The Persistence of Open Source Vulnerabilities](/content/whitepapers/the-persistence-of-open-source-vulnerabilities "Internal link to Unnecessary Risk: The Persistence of Open Source Vulnerabilities blog post"/index.html)

Read Report

In the News

OSS security finally gets a Magic Quadrant

June 29, 2026

Continue

Malicious apps got into the Arch User Repository - how to protect yourself

June 29, 2026

Continue

Miasma campaign poisons 20-plus npm packages, hunts for developer secrets

June 29, 2026

Continue

Linux Foundation Unveils New Open Source Security Project Akrites

June 29, 2026

Continue

Sonatype appoints new CRO, CMO and CHRO as it scales agentic software development platform

June 29, 2026

Continue

After Fable 5 ban, Anthropic and 19 organizations launch open source security body

June 29, 2026

Continue

2026 State of the Software Supply Chain Report

Sonatype was the first to share year-over-year analyses of open source consumption and threat data. For over a decade, the State of the Software Supply Chain® Report has provided developers and security teams with insights into trends, risks, and threats related to open source software — ultimately helping them better understand and manage their software supply chains.

Learn more

Press Kit

Access some basic statistics, descriptions, and brand assets you may find helpful when writing about Sonatype.