Mend.io Blog

You can’t rely on open source for security — not even when ai is involved

You can’t rely on open source for security — not even when AI is involved

LATEST
Learn more

Filter & Search

Cvss 4. 0 — what’s new? - cvss 4. 0 whats new e1687453756567

CVSS 4.0 — What’s New?

Learn about the new features and improvements in CVSS 4.0, the Common Vulnerability Scoring System. Understand how to use it.

Read More Read More
Cvss 4. 0 — what’s new? - smart merge control release

How to Boost Confidence in Your Open Source Security with Mend Smart Merge Control

Learn how to boost confidence in your open source security. Automate updates and reduce risks with confidence scores for seamless integration.

Read More Read More
Cvss 4. 0 — what’s new? - blog 7

Mend.io Launches AppSec Risk Assessment Program

Mend.io launches AppSec Risk Assessment Program to help organizations visualize and remediate application security risks.

Read More Read More
Cvss 4. 0 — what’s new? - understanding the anatomy of a malicious package attack

Understanding the Anatomy of a Malicious Package Attack

Learn to protect your applications from malicious packages with our guide. Understand the anatomy of attacks and how to prevent them.

Read More Read More
Cvss 4. 0 — what’s new? - whats driving the adoption of sboms and whats

What’s Driving the Adoption of SBOMs? What’s Next for Them?

Discover what's driving the adoption of SBOMs and what's next for them in terms of malicious packages and supply chain security.

Read More Read More
Cvss 4. 0 — what’s new? - unseen risks of open source dependencies case of an abandoned name e1685538190274

The Unseen Risks of Open Source Dependencies: The Case of an Abandoned Name

Mend.io research discovered a threat actor takeover of the name ‘gemnasium-gitlab-service', a retired Ruby gem with two million+ downloads.

Read More Read More
Cvss 4. 0 — what’s new? - blog pic

Mend.io + Jira Security: Doing DevSecOps Better Together

Discover how Mend.io & Jira Security are revolutionizing DevSecOps, improving application security, & streamlining workflows for dev teams.

Read More Read More
Cvss 4. 0 — what’s new? - gartner mq blog image

Magic Quadrant™ for Application Security Testing, 2023 Gartner® report

Mend.io is recognized as a Visionary in the 2023 Gartner Magic Quadrant for Application Security Testing. Learn about their approach.

Read More Read More
Cvss 4. 0 — what’s new? - what you should know about open source license compliance

What You Should Know About Open Source License Compliance

Learn about open source license compliance for M&A activity, the risks of copyleft licenses like GPL, and how to ensure compliance with SCA.

Read More Read More
Cvss 4. 0 — what’s new? - what are malicious packages blog post

What are Malicious Packages? How Do They Work?

Learn about malicious packages and the growing threat they pose to software supply chains.

Read More Read More
Cvss 4. 0 — what’s new? - blog a guide to standard sbom formats

SBOM Standard Formats: Guide

Discover the importance of Software Bill of Materials (SBOM) and compare the three main formats - SPDX, CycloneDX, and SWID.

Read More Read More
Cvss 4. 0 — what’s new? - rsa view from the floor

RSA Conference 2023: Key Takeaways From Our Five Favorite Sessions

RSA 2023 takeaways, including sessions on supply chain security, translating security for the board, & the psychology of DevSecOps.

Read More Read More
Cvss 4. 0 — what’s new? - why is cybersecurity now a global governmental concern blog

Why is Cybersecurity Now a Global Governmental Concern?

What do Australia’s cybersecurity plans teach us all about the need for advanced application security?

Read More Read More
Cvss 4. 0 — what’s new? - atlassian mend enhanced integration blog

Optimizing AppSec by Enhancing Integration with Jira

Enhance your AppSec by integrating with Jira. Learn how Mend's new Jira Security integration can streamline your security processes.

Read More Read More
Cvss 4. 0 — what’s new? - aws security partner competency accreditation

Mend.io Achieves AWS Security Competency Status

Mend.io achieves AWS Security Competency status, demonstrating expertise in cloud security. Trusted partner with specialized software for AWS

Read More Read More
Cvss 4. 0 — what’s new? - blog 2 1

Deceptive ‘Vibranced’ npm Package Discovered Masquerading as Popular ‘Colors’ Package

Discover the threat of the 'Vibranced' npm package masquerading as 'Colors'. Learn about its stages of execution, obfuscation techniques.

Read More Read More

Subscribe to our Blog

Never miss a post. Opt-out at any time.

Thank you

You’re all set to receive our latest posts.

AI Security & Compliance Assessment

Map your maturity against the global standards. Receive a personalized readiness report in under 5 minutes.