Sonatype Selected by Equifax to Support OS Governance Press Release

blog-logo Sonatype Blog

Struts2 Breach at Equifax was 100% Preventable. Here's how.

By Ilkka Turunen on September 20, 2017 Nexus Lifecycle
The breach at Equifax is a siren call for organizations to approach the problem of managing open source software by using automated technology.
Read More...

Security Processes at the Apache Software Foundation (video and podcast)

By Mark Miller on September 15, 2017 Struts
In our continuing series on the Struts2 vulnerability announcement and the breach at Equifax, we spoke with Mark Thomas, Director, Apache Software Foundation
Read More...

A Struts2 Vulnerability Hurricane: Deserialization

By Derek Weeks on September 06, 2017 Struts
Attackers are widely exploiting a new vulnerability in Apache Struts2 that allows them to remotely execute malicious code on web servers.
Read More...

The 2014 Survey: Marked by an Industry Shock Wave

Wow! What an amazing turnout we had for our 4th annual survey: 3,353 participants this year brings us to over 11,000 participants in the four years we’ve run this survey. I would like to extend a BIG

Read More...

Walking in the Open Source Component Garden

Its not everyday I can stop to enjoy my afternoon tea outside on my deck, overlooking my garden. But today I did and while admiring my beautiful blooming flowers, I started to draw some parallels

Read More...

5 Things You Need to Know About Open Source Components

You can't get away from it. Thousands of open source components are being used in every industry, every day, to quickly build and deploy applications. For those not in the security industry, it's

Read More...

4 Open Source Components You Need to Update Right Now

Heartbleed has put the security community on notice: it is time to take a harder look at the security status of open source components and frameworks. After doing a little industry research on

Read More...

Important: Apache Struts Framework Security Alert

By Derek Weeks on August 13, 2013 Sonatype Says
Important: Apache Struts Framework Security Alert
Read More...