Struts2 Breach at Equifax was 100% Preventable. Here's how.

By Ilkka Turunen on September 20, 2017 Nexus Lifecycle

25 second read time

The breach at Equifax is a siren call for organizations to approach the problem of managing open source software by using automated technology.
Read More...

Security Processes at the Apache Software Foundation (video and podcast)

By Mark Miller on September 15, 2017 Struts

1 minute read time

In our continuing series on the Struts2 vulnerability announcement and the breach at Equifax, we spoke with Mark Thomas, Director, Apache Software Foundation
Read More...

A Struts2 Vulnerability Hurricane: Deserialization

By Derek Weeks on September 06, 2017 Struts

3 minute read time

Attackers are widely exploiting a new vulnerability in Apache Struts2 that allows them to remotely execute malicious code on web servers.
Read More...

The 2014 Survey: Marked by an Industry Shock Wave

2 minute read time

Wow! What an amazing turnout we had for our 4th annual survey: 3,353 participants this year brings us to over 11,000 participants in the four years we’ve.
Read More...

Walking in the Open Source Component Garden

3 minute read time

Its not everyday I can stop to enjoy my afternoon tea outside on my deck, overlooking my garden.
Read More...

5 Things You Need to Know About Open Source Components

5 minute read time

You can't get away from it. Thousands of open source components are being used in every industry, every day, to quickly build and deploy applications.
Read More...

4 Open Source Components You Need to Update Right Now

8 minute read time

Heartbleed has put the security community on notice: it is time to take a harder look at the security status of open source components and frameworks.
Read More...

Important: Apache Struts Framework Security Alert

By Derek Weeks on August 13, 2013 Sonatype Says

2 minute read time

Important: Apache Struts Framework Security Alert
Read More...