-
Tweets16K
-
Followers11K
-
Following900
-
Likes8K
New React2Shell RCE vulnerabilities highlight a growing challenge for every modern software organization: the expanding risk surface created by generative and agentic AI-accelerated development. Even widely trusted frameworks like React and Next.js can introduce pathways for remote code execution — sometimes without developers realizing the server-side behaviors involved. Our latest blog breaks down the incident and detailed remediation guidelines. Take a look to learn more: lnkd.in/gkVBC-YK #OpenSourceSecurity #DevSecOps #React #SoftwareSupplyChain
Application security is moving fast. Is your team keeping up? Gartner’s new “Hype Cycle for Application Security, 2025” reveals the strategies leading organizations use to cut security incidents by up to 70%—without slowing their release cycles. Ready to stay ahead of emerging threats, streamline DevSecOps, and enable secure innovation? Get the insights your team needs to compete and win. Download the Gartner Application Security Hype Cycle lnkd.in/giiUBr_2 #ApplicationSecurity #DevSecOps #Cybersecurity
Nexus Repository Cloud helps you stay one step ahead by detecting malware in both open source components and AI/ML models — directly in your proxy repository. Add Sonatype Repository Firewall to block and remove risky packages before they ever hit your pipeline. 🛡️ Built for teams shipping faster in the AI era Try it free with 6-month, 500GB promo lnkd.in/gxCszKkV?utm_c… #RepoCloud #SoftwareSupplyChain #AIModelSecurity #DevSecOps #MalwarePrevention
Introducing Nexus One — a cloud-first, developer-centric, and AI-native platform. Built on 15+ years of research and the world’s most comprehensive OSS data, Nexus One helps teams build faster, safer, and smarter. Explore Nexus One: lnkd.in/gmN79dVw?utm_c…
The Latest on npm Supply Chain Attack x.com/i/broadcasts/1…
🚨 Another active attack targeting npm developers — and this one spreads itself. We break down the evolving #ShaiHulud campaign, a new wave of self-propagating malware targeting #npm publishers: ➡️ Over 180+ compromised packages tracked so far ➡️ Multi-stage payloads exfiltrate credentials, poison repos, and auto-spread ➡️ A wake-up call: open source developers are the new frontline Get the latest updates here: bit.ly/41WlxPY #SoftwareSupplyChain #npmSecurity #OpenSourceSecurity #Malware #DevSecOps #CyberSecurity #SupplyChainAttack
Thanks for reaching out — the OWASP In Ten ZAP videos aren’t currently hosted, but we’ve got some updated OWASP-related resources you might find helpful: The OWASP LLM Top 10 + Supply Chain Security: sonatype.com/blog/the-owasp… Data & Model Poisoning in the AI Era: sonatype.com/blog/the-owasp… AI + OWASP topics in our recent webinar (starts ~6min in): webinars.sonatype.com/wcc/eh/5011667…
🚨 New research: Lazarus Group targets developers through open source malware Since January, Sonatype has uncovered 234 malicious packages tied to the North Korea-backed group — deployed via npm and PyPI to exfiltrate secrets, drop payloads, and surveil developers. 📦 120+ used multi-stage droppers 🔐 90+ focused on secrets exfiltration 🎯 36,000 potential victims Our latest whitepaper breaks down the tactics, payloads, and what security teams can do to stay protected. Get the report: bit.ly/3HaoR2I #OpenSourceSecurity #MalwareCampaign #DevSecOps #CyberThreats #SoftwareSupplyChain #ThreatIntel
In finance, trust is everything, and that extends to your #softwaresupplychain. 🔐 Sonatype is trusted by over 70% of the Fortune 100, including leading global banks and insurers, to secure their open source components and reduce software risk at scale. Explore how Sonatype supports the financial services industry: bit.ly/4ezBcK2 #FinancialServices #Cybersecurity #Sonatype #DevSecOps
LLMs are powerful, but their outputs aren’t always safe. Improper output handling can lead to code injection, outages & compliance failures. Learn how Sonatype helps teams validate LLM responses before they reach production: bit.ly/46ooU5c #AIsecurity #OWASP #DevSecOps #LLM
Security and speed don’t have to compete. Discover how Sonatype enables teams to streamline software composition analysis (#SCA) with automated solutions that scale, reducing manual effort while enhancing their risk posture. 🔐 Read the blog: bit.ly/4kjvf6h #DevSecOps #AppSec #SoftwareSecurity #Automation #Sonatype
Java changed everything — igniting the open source revolution and redefining modern software development. In this deep dive from @thenewstack, Sonatype CTO and co-founder Brian Fox reflects on the early days of open source and the movement that followed, in conversation with Darryl Taft. 📖 Read the full story: bit.ly/3Hw5nFs #OpenSource #Java30 #SoftwareInnovation #Sonatype #DevHistory
Streamline security without slowing innovation. Discover how one financial enterprise used Sonatype Lifecycle to scale security, boost efficiency, and reduce risk: 📈 3x faster onboarding 🔍 335% more scans 🛡️ 25% fewer critical risks Read the full story: bit.ly/43ISDTH #AppSec #DevSecOps #OpenSourceSecurity #FinancialServices #CustomerStory #SonatypeSuccess
Data and model poisoning attacks are on the rise — and they threaten the integrity of AI at its core. In part two of our OWASP LLM Top 10 blog series, we break down how Sonatype helps organizations detect and prevent poisoning attacks before they compromise your models. 🔍 Identify poisoned packages ⚠️ Enforce policies that block tainted data 📦 Track AI/ML components with SBOMs 📊 Learn what our research uncovered in top AI ecosystems Read the blog: bit.ly/44K8XWj #AI #SoftwareSupplyChain #ModelPoisoning #DevSecOps #Sonatype #OWASP
Are your AI models compliant and secure? Sonatype’s discovery of four picklescan bypasses is a wake-up call for any team using open source AI. Insecure models can silently introduce risk into your environment—long before they reach production. Read the whitepaper to strengthen your defenses and ensure the integrity of your AI supply chain: bit.ly/43BXxmh #AI #PyTorch #OpenSourceSecurity #SoftwareSupplyChain #DevSecOps #AICompliance
Software supply chain security isn’t just an IT issue anymore — it’s a boardroom priority. With attacks on open source rising 156% in 2024 and new regulations taking effect, executives must lead with proactive strategies that balance innovation, risk, and compliance. Explore our latest executive brief with The Futurum Group to understand the evolving landscape and how to align software security with business outcomes. 📖 Read the brief: bit.ly/3YVZ3Nn #SoftwareSecurity #CISO #BoardroomSecurity #SupplyChainSecurity #CyberResilience #ExecutiveLeadership #Sonatype
🚨 Software attacks are on the rise — and regulators are responding. bit.ly/4iac7FT Our latest executive brief with The Futurum Group explains why 2025 is a defining year for software security, compliance, and board-level accountability. Learn what every executive needs to know: ✔️ Key risks driving regulation ✔️ Questions boards should be asking ✔️ How to align software security with business outcomes #SBOM #DevSecOps #CISO #CIO #OpenSourceSecurity #Compliance
A new Apache Tomcat vulnerability (CVE-2025-24813) was exploited within hours of disclosure, and the threat is real and growing. Learn why this flaw is so dangerous, and what teams must do to stay protected. bit.ly/42apLEl #ApacheTomcat #CyberSecurity #SoftwareSupplyChain #OpenSourceSecurity #DevSecOps #ApplicationSecurity
Open source malware isn’t slowing down. It’s getting smarter. Sonatype’s Open Source Malware Index Q1 2025 reveals a sharp rise in data exfiltration attacks targeting developers — and the stakes are only getting higher. 📈 17,954 new malicious packages identified 📤 56% of them focused on stealing sensitive data 🏦 Financial services, government, and energy sectors were hit hardest 🧠 Open source malware is evolving — less noise, more real threats Sonatype blocked over 22,000 attacks this quarter alone with Repository Firewall. Get the full report and see what your team needs to know to stay ahead: bit.ly/4luWjk3 #OpenSourceSecurity #SoftwareSupplyChain #CyberSecurity #DevSecOps #OpenSourceMalwareIndex
🚨 A data exfiltration campaign was discovered with 10 popular npm crypto packages hijacked — now repurposed to steal sensitive environment variables from unsuspecting developers. bit.ly/422frNa Some of these components have been trusted for nearly a decade and downloaded hundreds of thousands of times. Now, their latest versions are laced with obfuscated info-stealing code. Sonatype researchers uncovered the threat and our tools are already blocking it. Read the full blog here: bit.ly/422frNa #OpenSourceMalware #SoftwareSupplyChain #npm #Malware #InfoStealer #CryptoSecurity #DevSecOps
Maciej Walkowiak 🍃 @maciejwalkowiak
41K Followers 947 Following Freelance Java Consultant - Java, Spring Boot, AWS 👉 https://t.co/5hDONs8nrh 📺 https://t.co/xtk152k8qm
Josh Long @starbuxman
85K Followers 4K Following Spring Developer Advocate (@Java_Champions & @Kotlin @GoogleDevExpert) @VMwareTanzu 🍃🐲 📽️ https://t.co/A2wBUe0b0A
javinpaul @javinpaul
106K Followers 7K Following Blogger - https://t.co/Cxgp9zzN3y Creator - https://t.co/GYls4Lx9DW newsletter - https://t.co/P8jiQ5GW16 youtube - https://t.co/vs4WjwaEQ6
Dan Lorenc @lorenc_dan
11K Followers 2K Following OSS Supply Chain Security. Founder/CEO/Primary Ariba Admin at https://t.co/sGmuUU9JbG Sigstore: https://t.co/dWKlyYu6kv
Karl Heinz Marbaise @khmarbaise
3K Followers 5K Following Apache Maven Project PMC @ASFMavenProject, Apache Software Foundation Member @TheASF, @Java_Champions, Java Developer,CI/CD Fan,Freelancer
Arnaud Héritier @aheritier
7K Followers 3K Following #lescastcodeurs #devoxxfr #AI #ci #cd #devops #platformengineering #oss #jenkinsci #maven #asf
Luke Hinds @decodebytes
3K Followers 750 Following Creator of https://t.co/T8htHI7vHB , now building https://t.co/OBABqFvHE2 - the agent security platform.
Baeldung @baeldung
77K Followers 851 Following Passionate about everything Java. Teaching Spring on https://t.co/vh3oOY6ka6. Java Champion.
Agatino Caruso @agatinocaruso_
13 Followers 213 Following
Amit Geynis @geynis48380
0 Followers 12 Following
Christopher DiMarco @ImChrisDiMarco
69 Followers 82 Following R&D Aerospace PM, obsessed with AI and autonomy. Stuck in the nexus of Constitutional Conservative & Libertarian. Proud dad & husband.
RavenTek @RavenTek_IT
52 Followers 132 Following We deliver leading-edge IT solutions to mission critical organizations worldwide.
Kim Fletcher (She/Her... @kc_fletcher
712 Followers 1K Following Event Operations & Community Leader | Organising Devoxx UK | Volunteer Manager: AI Native DevCon & StateOfOpenCon | Leader of the Virtual Java User Group
Eug @eug2027
7 Followers 145 Following
SHR @SHR_Hasija
0 Followers 65 Following
_overksam @_overksam
0 Followers 80 Following
shivakrishna @Addik0102
11 Followers 58 Following Jenkins |GIT | docker | Kubernetes | Prometheus | AWS | Linux | Terraform | Ansible |
julian.toribio @jtoribioc
4 Followers 731 Following
You mean Joner @JonerYou72638
0 Followers 18 Following
Adam Daum @adamweststack
8 Followers 93 Following Former SWE turned agentic engineer, specializing in agent-driven development and intelligent, cloud-native solutions for finance. I run weststack ai and build.
ail @ai13000
0 Followers 8 Following
Owen Huang @owenhuang777
23 Followers 258 Following
Phavya Jayakumar @phavyajai
8 Followers 32 Following
Lil Bindle @YungBindlestiff
99 Followers 5K Following
Mark Pape @mark_pape
529 Followers 2K Following Founder @deep_current… focused on learning the art of architecting AI empowered niche products.
Aptori @AptoriDev
6 Followers 21 Following Developer-First Application Security for the Shift-Left Revolution!
Aleksandr @Aleksandr_Rib
0 Followers 43 Following
sai manideep allu @AlluManideep
64 Followers 2K Following
@sinclaw @sinclaw
25 Followers 714 Following
Andrew Cmetx @AndrewCmetx
0 Followers 15 Following
Pradheep @pradheep_s1
24 Followers 231 Following
zechdz 🇺🇲🇬�... @zechdz
701 Followers 524 Following All-Japan Superbike ST1000 🇯🇵 2019 Tsukuba ST600 Champion🥇 Tokyo🇯🇵🏡Ghanaian-American🇬🇭🇺🇸🇨🇿🇫🇮 Pro Racer🏍️Software Engineer👨💻
alejandro gómez @alejand02868110
25 Followers 753 Following
LeAnn Hodges @HodgesLean90016
52 Followers 356 Following I’m a proud mother of an amazing person! I’m completely in love forever and always with my babygirl!
MK @HEALTHWEALTHWI2
34 Followers 1K Following
Damian von Pappeln @niotcs
6 Followers 3K Following IST BI CloudComputing IoT BigData DevSecOps ISSP DFIR ISO ISM SIH OffensiveSecurity SigInt SatCom CTI CTH SpaceSafety
Mohsen Rajabi @mohsen_rajabi72
363 Followers 3K Following Tech Lead at Mofid Securities .NET / Architect - Consultant
Paul Litzbarski @Nanduhirion
44 Followers 585 Following
Muhammad Waseem @wgujjer11
4K Followers 1K Following Cybersecurity Analyst | Ethical Hacker | Secure @nasa | #CyberSecurity #
Alade Gazaliy @GazaliyAlade
218 Followers 4K Following
Mahraz Ali @MahrazAli91391
10 Followers 254 Following
DevoxxFR @DevoxxFR
16K Followers 224 Following 🤖 Devoxx France 🤖 Conférence pour les développeurs & développeuses 📍 Paris Palais des Congrès 📆 RDV du 7 au 9 avril 2027 pour la 15ème édition !
Mannymosdef | Ceiba.e... @mannymosdef
1K Followers 6K Following 🗽🇵🇷 Marketing @Bitdefender | MBA | Privacy & Digital Sovereignty fwd | Building @capiculabs | Prof Art by @goodvibesclub | Views are my own
Sawitri Saengchan @SawitriSae68767
1 Followers 245 Following
[email protected] @Irespewebde1
0 Followers 623 Following
Desta Zerihun @DestaZerihun
119 Followers 764 Following Engineering Manager | Platform Engineering | Building High-Scale Distributed Systems | Agentic AI | Leading High-Performing Teams | Java, Go, Python
P1cK@_ @blackbi25979798
15 Followers 1K Following 👶 CyberKid & Noob Explorer 🌐 | Passionate young mind diving into the realm of cybersecurity & hacking. 🚀 Constantly learning, breaking, and fixing
srinivas @srinivas_s19
1 Followers 207 Following
Raphael @GalacticRaph
21 Followers 210 Following "Nothing is evolved as a consequent that is not involved as an antecedent"
Dave Farley @davefarley77
36K Followers 142 Following Software Engineer, Consultant & Author. Latest YouTube Video: https://t.co/dOwUgqnFlV Support Me On Patreon: https://t.co/7VzLHbRT4A
Patrick Debois @patrickdebois
30K Followers 8K Following Generative AI and DevOps specialist - co-author Devops Handbook - https://t.co/PZlox9jwoq
Arnaud Héritier @aheritier
7K Followers 3K Following #lescastcodeurs #devoxxfr #AI #ci #cd #devops #platformengineering #oss #jenkinsci #maven #asf
Theresa Mammarella @t_mammarella
764 Followers 618 Following JVM engineer @IBM. Toronto JUG Co-organizer. I love to be outside with my foster dog.
WSJ Business News @WSJbusiness
1.8M Followers 378 Following The Wall Street Journal's Business editors share the latest breaking news and their insights on what matters most in business and finance.
Steve Morgan @CybersecuritySF
21K Followers 11K Following Founder of Cybersecurity Ventures, Editor-in-Chief at Cybercrime Magazine, Executive Producer at Cybercrime Radio. Researcher, Publisher, Journalist, Author.
Amazon Web Services @awscloud
2.2M Followers 434 Following AWS is the world's most comprehensive cloud, enabling organizations to accelerate innovation, reduce costs, and scale more efficiently.
CVE @CVEnew
58K Followers 3 Following Official account maintained by the CVE™ Program to notify the community of new CVE IDs. Posts contain abbreviated details. Full CVE Records on https://t.co/ALn4YvUtom
InfoWorld @InfoWorld
88K Followers 224 Following We're your destination for #softwaredevelopment, #machinelearning, and #cloud news. Follow along for expert analysis of these #enterprise technologies.
NYT Business @nytimesbusiness
881K Followers 458 Following Financial, tech, media and other business news from The New York Times.
Entrepreneur @Entrepreneur
3.5M Followers 1K Following Inspiring, informing and celebrating entrepreneurs.
AWS Events @AWSEvents
106K Followers 15 Following We bring the cloud computing community together to connect, collaborate, and learn from #AWS experts. #AWSSummit #AWSreInvent
VentureBeat @VentureBeat
686K Followers 2K Following Obsessed with covering transformative technology.
AWS re:Invent @AWSreInvent
4K Followers 35 Following @awsevents hosts events, both online and in-person, bringing the cloud computing community together to connect, collaborate, and learn from AWS experts.
Megan Lueders @MeganLueders
683 Followers 866 Following Passionate #CMO #.advisor #boards #brand #SaaS #revenue #B2B #footballmom
Rashida @RashidaHodge
884 Followers 874 Following CVP, Azure Data & AI @microsoft, Previously @ibm. board member @sonatype, @girls_inc, @mistyrobotics US Virgin Islander, *Tweets are my own*
OpenSSF @openssf
6K Followers 29 Following Open Source Security Foundation (OpenSSF) Together, we're securing the #opensource ecosystem #OSSSecurity https://t.co/uUpbn44G4Q https://t.co/adjLU8dbk0
Techstrong TV @TechstrongTV
880 Followers 276 Following Serving you the latest news in the world of digital transformation. Powered by @TechstrongGroup
Harvard Business Revi... @HarvardBiz
5.6M Followers 197 Following The best ideas in business and management to help people, organizations, and economies work better.
ARCHIVED: Jen Easterl... @CISAJen
61K Followers 48 Following Archived: Director, CISA—America’s Cyber Defense Agency. Combat Veteran. Proud Mom. Rubik’s Cuber. Aspiring Electric 🎸. ❤️/RT ≠ endorsement
Fast Company @FastCompany
2.0M Followers 4K Following Inspiring readers to think beyond traditional boundaries & create the future of business. Subscribe to our daily newsletter: https://t.co/BpH3KmBae9
NordicITSecurity @nordicitsec
792 Followers 1K Following The Most recognized and influential cyber security business forum in Scandinavia May 25th 2023! Get your tickets below. #NordicITSec
IDC @IDC
140K Followers 234 Following The premier global provider of market intelligence, advisory services, and events for the IT, telecommunications, and consumer technology markets
Forrester @forrester
345K Followers 13K Following Forrester helps business and technology leaders use customer obsession to accelerate growth. With us, you can be bold at work.
HackerNoon | Learn An... @hackernoon
92K Followers 5K Following how hackers start their afternoons. where 50k+ technologists publish blog posts for 4M+ monthly readers. write your story 👉https://t.co/PGmtSCSd5V
TechRadar @techradar
329K Followers 481 Following A 🌏 team of gadget obsessives here to help you make informed decisions on tech. What to use, what to cancel. What to buy, what to skip. Part of @futureplc
Forbes @Forbes
20.3M Followers 5K Following Sign up now for Forbes' free daily newsletter for unmatched insights and exclusive reporting: https://t.co/v3UAa9BzAT
Dark Reading @DarkReading
351K Followers 49 Following One of the most widely read and trusted cybersecurity news sites, providing IT security professionals informed insights into the latest news and trends.
Inc. @Inc
2.6M Followers 2K Following Everything you need to know to start and grow your business now. Sign up for our daily newsletters: https://t.co/XAE0ET9Cq2
Fairygodboss @fairygodboss
18K Followers 6K Following 🧚♀️ An authentic career space for *all* women to feel supported & empowered✨ 💬 Community advice 💡 Expert insights 🤝 Job opportunities ➡️ #fairygodboss
Courtney Arnoldy @sonatype_court
5 Followers 17 Following
IT Revolution @ITRevBooks
7K Followers 658 Following Helping technology leaders succeed through books (The Phoenix Project, Team Topologies), events (@ITRevSummit), research, podcasts (#TheIdealcast), and more.
W-JAX @jaxcon
5K Followers 471 Following Globale Community und Events für Java, Architektur & Software-Innovation. 📍 Mainz: 4. - 8. Mai 2025 📍 München: 2. - 6. November 2026
NightDragon @nightdragon
954 Followers 274 Following NightDragon is a venture capital firm investing in innovative growth and late stage SecureTech companies, including cyber, national security, and defense.
Wayne Jackson @WayneJacksonIII
29 Followers 79 Following Family man, tech entrepreneur, & serial hobbyist
SiliconANGLE @SiliconANGLE
20K Followers 2K Following Extracting the Signal from the Noise. Where social science meets computer science. The ANGLE on technology. Also the home of @theCUBE #theCUBEresearch
ISMG Network News @ISMG_News
4K Followers 1K Following ISMG is a global leader in cybersecurity education, intelligence and research with 38 media properties focused on #cybersecurity news.
theCUBE @theCUBE
19K Followers 6K Following Unparalleled insights from the smartest people in #EnterpriseTech. Extracting the signal from the noise since 2010. Get our podcast at https://t.co/3M4ykPrtzb
DevopsDays Medellín @DevopsdaysMed
571 Followers 1K Following ¡La conferencia de referencia mundial sobre DevOps llega a Medellín ! #DevOpsDaysMDE
Channel Dive @ChannelDiveNews
25K Followers 7K Following Channel Dive is an independent B2B digital media platform providing daily news, analysis and insights for IT service providers in North America.
Informa TechTarget @InformaTTGT
26K Followers 3K Following We inform, influence and connect the world’s technology buyers and sellers, accelerating growth from R&D to ROI.
Computerworld @Computerworld
241K Followers 2K Following The Voice of Business #Technology. We help #ITleaders create business advantage.
CRN @CRN
46K Followers 7K Following CRN, a media brand of The Channel Company, is the #1 trusted source for IT channel news, analysis and insight online and in print.
Tech Transforms Podca... @TechTransforms
126 Followers 398 Following Tech Transforms talks to some of the most prominent influencers shaping government technology. Proudly sponsored by @Dynatrace
Maury Cupitt @maurycupitt
127 Followers 248 Following















