Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Coding Agents Just Reopened Your Software Supply Chain Blind Spot

Most organizations spent years hardening their software supply chain. The model is familiar: dependencies flow through a controlled repository, policies determine what is allowed, scanning catches what slips through, and every action is logged for auditability. It works because human developers operate within environments that enforce these rules. AI coding agents break that assumption entirely.

Why Self-Healing Is the Only Way to Secure at Frontier AI Speed

For twenty years, the software security playbook has worked the same way. You find the vulnerability, score it, open a ticket, assign it to a human, wait for the fix, ship the patch, and prove it happened. Every step in that sequence assumes humans can review each fix individually and still keep up. Frontier AI broke that assumption. The exploit window has collapsed from weeks to hours. Attackers reason across your codebase, chain their findings, and ship exploits before a CVE is even published.

Agent Immunization: A New Model for Building Trusted AI Agents

The riskiest thing an AI agent does all day isn’t writing code. It’s shopping. Every few minutes, it reaches out for a package, an AI asset, or a tool, and pulls it in with no real way to check what’s inside. We think the fix is agent immunization: security that lives inside what an agent consumes, builds, and ships, not a wall built around it.

Propagating User Identity From AI Agents to Your Tools: Amazon Bedrock AgentCore Gateway and JFrog Artifactory

Join us at swampUP New York, September 1-3, for our joint session Trusted AI Delivery at Scale: Securing Every Artifact from Curation to Cloud, where we walk the full chain of custody from the moment a package enters your organization to the moment your agent runs on Amazon Bedrock AgentCore. Register here. AI agents are becoming real users of internal systems. They open pull requests, run queries, and pull and publish artifacts in repositories like JFrog Artifactory.

Frontier AI Application Security: Every Second Counts

Somewhere in the last few months, the math of application security quietly broke. Anthropic’s Claude Mythos Preview didn’t just analyze code, it found a 27-year-old vulnerability in OpenBSD, a 16-year-old bug in FFmpeg, and a 17-year-old remote code execution flaw in FreeBSD, entirely on its own. Then it went further: it built working exploits for them. No human guidance. No months of manual research. And by Anthropic’s own account, this is only a preview of what’s coming.

Scale Your Engineering Organization Without Losing Control

Growing engineering organizations all hit the same wall. More teams shipping software means more repositories, more permission requests, more onboarding cycles, and eventually one platform admin fielding every change. The platform that was supposed to accelerate delivery has now become the bottleneck. JFrog Projects is built to break that pattern.

Inside the ECB's AI Cyber Directive: What EU Banks Need to Know

A bank isn’t just a vault holding money. It is an engine powered by implicit public trust, sustained by the continuous confidence that funds remain secure and accessible on demand. When operational risks fail, whether through cyber breaches, system outages, or third-party vulnerabilities, that trust shatters, threatening not just an individual institution, but the stability of the entire financial network. This is why regulatory oversight goes beyond standard compliance.

Agentic Development Security is a Discipline that Starts Before the First Line of Code

Ask most security tools what an AI coding agent just built, and they can tell you. Ask what it was allowed to consume before it started, and far fewer have an answer. That gap, between watching agentic development and controlling it, is what securing it actually comes down to. Securing agentic development means stopping risk before it enters a build, not flagging it after. And risk prevention has a prerequisite most approaches skip: you can only account for the assets you actually hold and manage.

How to Control AI Assets Before They Become Shadow AI

A developer on your team just told Claude Code to connect to a new MCP server, the protocol coding agents use to reach organizational tools and data. Nobody in security reviewed it. Nobody in security even knows it happened. For two-thirds of enterprises, the primary obstacle to scaling agentic development isn’t budget or headcount — it’s security risk.

Fast Remediation Is the New Trust Model: JFrog and OpenAI Collaboration on Zero-Day Security Findings

Just last week, OpenAI and Hugging Face jointly disclosed what may be the first incident of its kind: during an internal evaluation of frontier cyber capabilities, OpenAI’s models, running deliberately without production safeguards in an isolated research environment, autonomously discovered and employed chained vulnerabilities to escape its sandbox, reach the open internet, and extract evaluation answers from Hugging Face’s infrastructure.