Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

JFrog Named a Leader in the Inaugural Gartner Magic Quadrant for Software Supply Chain Security

It’s official. Gartner just published the very first Gartner Magic Quadrant for Software Supply Chain Security, and JFrog has been recognized as a Leader, placing highest for Ability to Execute among all the vendors included. For an inaugural report in a category this important, that placement means a great deal to us, and we don’t take it lightly.

Protecting Applications Through Secure Development Practices

Modern software rarely gets built from scratch. Instead, it's put together using a complex mix of proprietary code, open-source libraries, third-party APIs, and various development tools. This network of dependencies and components makes up the software supply chain. While this approach speeds up development, it also brings significant security risks that attackers can exploit, making it more crucial than ever to protect this chain.

The Month the AI Supply Chain Broke: Six Cybersecurity Incidents That Shook May 2026

May 2026 will be remembered as the month the AI developer toolchain itself became the primary attack surface. A single threat actor — TeamPCP — ran a nine-day campaign that started as a worm in open-source packages, escalated through a poisoned code-editor extension, and ended inside GitHub’s own infrastructure.

Supply Chain Whiplash: Why Your Orders Keep Slipping

Quick answer: Today’s supply chain disruptions stem from surging demand for components, especially server CPUs feeding the AI build-out, rather than the pandemic-era shutdowns of 2020 and 2021. Companies can protect themselves by diversifying suppliers, locking in pricing terms early, holding strategic inventory, and investing in real-time visibility tools. Think of your supply chain like the plumbing in an old building. When everything flows, you never think about it.

Boosting Data Center Security Through Hardware Integrity

When people talk about data center security, they often focus on firewalls, encryption, and intrusion detection systems. These software defenses are crucial, but they rely on a basic level of trust in the physical hardware. If that foundation is weak, the whole system is at risk. Real system security starts from the ground up, with the integrity of the processors, memory, and other core components of your infrastructure.

The Governance Gap: What IDC's 2026 Data Reveals About AI and the Software Supply Chain

In a landscape where executive teams demand immediate AI integration, engineering and security leaders find themselves navigating a complex operational balancing act. To explore how organizations can accelerate delivery pipelines without introducing fatal security risks, JFrog recently hosted a virtual panel discussion titled “Agentic Software Delivery in 2026.

The new supply chain blast radius

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

What Is 'Business Identity Theft'? Corporate Security and Vendor Risk Management

Business identity theft occurs when criminals hijack a company's commercial credentials-such as its tax ID or registration details-to open fraudulent lines of credit, intercept vendor payments, or execute supply chain attacks. You do not just lose money. You lose your operational integrity.

NVIDIA NIM Models Are Now Governed Assets in Your Supply Chain

NVIDIA NIM (NVIDIA Inference Microservices) packages production-ready AI models into optimized containers for enterprise deployment. Your developers need them. Your coding agents pull them. And until now, they pulled them directly from NVIDIA’s NGC registry, bypassing the supply chain controls you’ve spent years building. JFrog AI Catalog now brings NVIDIA NIM models under the same governance as every other artifact in your organization, with no separate registry and no governance gap.