Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Coding Agents Just Reopened Your Software Supply Chain Blind Spot

Most organizations spent years hardening their software supply chain. The model is familiar: dependencies flow through a controlled repository, policies determine what is allowed, scanning catches what slips through, and every action is logged for auditability. It works because human developers operate within environments that enforce these rules. AI coding agents break that assumption entirely.

Why Self-Healing Is the Only Way to Secure at Frontier AI Speed

For twenty years, the software security playbook has worked the same way. You find the vulnerability, score it, open a ticket, assign it to a human, wait for the fix, ship the patch, and prove it happened. Every step in that sequence assumes humans can review each fix individually and still keep up. Frontier AI broke that assumption. The exploit window has collapsed from weeks to hours. Attackers reason across your codebase, chain their findings, and ship exploits before a CVE is even published.

Agent Immunization: A New Model for Building Trusted AI Agents

The riskiest thing an AI agent does all day isn’t writing code. It’s shopping. Every few minutes, it reaches out for a package, an AI asset, or a tool, and pulls it in with no real way to check what’s inside. We think the fix is agent immunization: security that lives inside what an agent consumes, builds, and ships, not a wall built around it.

Introducing JFrog Platform Federation: One Control Plane for Synchronizing Every Site in Your Software Supply Chain

It’s 2 p.m. on a Tuesday. Your primary region goes down. Your software artifacts have been syncing to your Disaster Recovery site the way they were designed to, but your projects, permissions, and security policies were never part of the package. Instead of flipping the lights back on, your platform team is scrambling to manually reconstruct governance while builds grind to a halt across every other region.

Propagating User Identity From AI Agents to Your Tools: Amazon Bedrock AgentCore Gateway and JFrog Artifactory

Join us at swampUP New York, September 1-3, for our joint session Trusted AI Delivery at Scale: Securing Every Artifact from Curation to Cloud, where we walk the full chain of custody from the moment a package enters your organization to the moment your agent runs on Amazon Bedrock AgentCore. Register here. AI agents are becoming real users of internal systems. They open pull requests, run queries, and pull and publish artifacts in repositories like JFrog Artifactory.

Frontier AI Application Security: Every Second Counts

Somewhere in the last few months, the math of application security quietly broke. Anthropic’s Claude Mythos Preview didn’t just analyze code, it found a 27-year-old vulnerability in OpenBSD, a 16-year-old bug in FFmpeg, and a 17-year-old remote code execution flaw in FreeBSD, entirely on its own. Then it went further: it built working exploits for them. No human guidance. No months of manual research. And by Anthropic’s own account, this is only a preview of what’s coming.

Scale Your Engineering Organization Without Losing Control

Growing engineering organizations all hit the same wall. More teams shipping software means more repositories, more permission requests, more onboarding cycles, and eventually one platform admin fielding every change. The platform that was supposed to accelerate delivery has now become the bottleneck. JFrog Projects is built to break that pattern.

Inside the ECB's AI Cyber Directive: What EU Banks Need to Know

A bank isn’t just a vault holding money. It is an engine powered by implicit public trust, sustained by the continuous confidence that funds remain secure and accessible on demand. When operational risks fail, whether through cyber breaches, system outages, or third-party vulnerabilities, that trust shatters, threatening not just an individual institution, but the stability of the entire financial network. This is why regulatory oversight goes beyond standard compliance.

Agentic Development Security is a Discipline that Starts Before the First Line of Code

Ask most security tools what an AI coding agent just built, and they can tell you. Ask what it was allowed to consume before it started, and far fewer have an answer. That gap, between watching agentic development and controlling it, is what securing it actually comes down to. Securing agentic development means stopping risk before it enters a build, not flagging it after. And risk prevention has a prerequisite most approaches skip: you can only account for the assets you actually hold and manage.