The Sonatype Newsroom | Sonatype Press Releases
The Sonatype Newsroom
Explore Sonatype's latest announcements, media coverage, threat research, brand assets, and more.
Featured News and Stories
June 18, 2026
Sonatype Named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security
Recognized for Completeness of Vision and Ability to Execute
Read More
Miasma campaign poisons 20-plus npm packages, hunts for developer secrets
June 29, 2026
2026: The Year of AI-Assisted Attacks
May 4, 2026
Press Releases
Sonatype Research Labs Marks 15 Years of Software Supply Chain Intelligence
July 14, 2026
Sonatype Named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security
June 18, 2026
Sonatype Names Three Industry Veterans to Executive Team to Lead the Next Chapter of Agentic Development
June 9, 2026
Sonatype Firewall Extends Malicious Package Protection to Any Repository
May 27, 2026
Sonatype and Package Registry Leaders Unite to Address Open Source Sustainability Crisis
May 6, 2026
Sonatype Releases Q1 2026 Open Source Malware Index: Trust Abuse Most Successful Attack Vector
April 14, 2026
Sonatype Threat Research
Powering unmatched visibility and insights
Sonatype’s world-class Security Research team leads the market in identifying and analyzing threats within the open source ecosystem. With a combination of automated intelligence, expert analysis, and secondary expansion, the team uncovers new forms of open source malware, software supply chain attacks, and emerging vulnerabilities. From in-depth reports to real-time threat detection, Sonatype Security Research powers the insights that keep our customers ahead of adversaries and sets the standard for trust in software development.
[Sonatype Releases Q1 2026 Open Source Malware Index](/content/press-releases/sonatype-q1-2026-open-source-malware-index "Internal link to Sonatype Releases Q1 2026 Open Source Malware Index blog post"/index.html)
Read More
[Unnecessary Risk: The Persistence of Open Source Vulnerabilities](/content/whitepapers/the-persistence-of-open-source-vulnerabilities "Internal link to Unnecessary Risk: The Persistence of Open Source Vulnerabilities blog post"/index.html)
Read Report
In the News
OSS security finally gets a Magic Quadrant
June 29, 2026
Malicious apps got into the Arch User Repository - how to protect yourself
June 29, 2026
Miasma campaign poisons 20-plus npm packages, hunts for developer secrets
June 29, 2026
Linux Foundation Unveils New Open Source Security Project Akrites
June 29, 2026
Sonatype appoints new CRO, CMO and CHRO as it scales agentic software development platform
June 29, 2026
After Fable 5 ban, Anthropic and 19 organizations launch open source security body
June 29, 2026
2026 State of the Software Supply Chain Report
Sonatype was the first to share year-over-year analyses of open source consumption and threat data. For over a decade, the State of the Software Supply Chain® Report has provided developers and security teams with insights into trends, risks, and threats related to open source software — ultimately helping them better understand and manage their software supply chains.
Press Kit
Access some basic statistics, descriptions, and brand assets you may find helpful when writing about Sonatype.