Sonatype Uncovers Millions of Previously Hidden Open Source Vulnerabilities Through Unique Shaded Vulnerability Detection System
By:
Sonatype via
GlobeNewswire
May 02, 2024 at 12:00 PM EDT
Fulton, Md., May 02, 2024 (GLOBE NEWSWIRE) -- Sonatype, the software supply chain optimization company, today announced it has identified 336,000 previously undetectable, “Critical” open source vulnerabilities through a new, first-of-its-kind shaded vulnerability detection capability in the Sonatype platform, that revolutionizes the identification of hidden security threats within open source code. This industry-first data enhancement comes from a novel, Sonatype-created algorithm capable of detecting vulnerabilities in "shaded" open source files—a technique in which original code is repackaged, often making detection by traditional means impossible. Through this technique, Sonatype uncovered a previously hidden layer of risk within the software supply chain, resulting in 4.5 million additional open source vulnerabilities being found, 1.85 million with a “High” risk classification, and 336,000 having a CVSS score of 9.7+, categorized as Critical by the National Vulnerability Database (NVD) and comparable to Log4Shell in severity. The pace of software innovation is paramount to remaining competitive, but for development teams to work efficiently, they must prioritize where to spend their time. Comprehensive intelligence on vulnerable components provides a holistic picture, improving risk management while eliminating developer waste so teams can focus on innovating at scale. Speaking on the announcement, Wayne Jackson, CEO of Sonatype said, "The reality is, 'good enough' is not enough when it comes to securing the open source software that underpins much of the digital world. Bad actors are constantly evolving their methods, and to help our customers stay ahead of them, we must evolve as well. Our commitment is to provide the deepest, most comprehensive insights into open source vulnerabilities, coupled with the tools and automation necessary to boost developer productivity while minimizing security risks." Unlike other tools, the Sonatype platform's design emphasizes comprehensiveness and precision in findings, while virtually eliminating false positives and illuminating false negatives. This ensures that teams focus only on genuine threats at the right time, thereby reducing unnecessary workload and strain on development teams. Equally important, the platform also empowers developers with automated remediation tools, enabling far more efficient and productive vulnerability resolution. "While no one wants to see more vulnerabilities discovered in open source, sunshine is, as they say, the best disinfectant. The key here is to prioritize the most critical, exploitable defects and to provide developers with reliable fixes that do not get in the way of innovation,” said Jackson. “We know the pressures on both developers and security teams, which is why our solutions streamline and even automate the remediation process; helping developers resolve the most critical issues while maintaining high levels of efficiency and productivity. This balance is key for driving innovation while safeguarding software integrity." Amid the growing complexity of software supply chains, Sonatype's innovations offer optimism that developers can continue to develop innovative software, while avoiding additional security-related stress. By merging security with productivity, Sonatype dispels the notion that companies must compromise between the two. This progress highlights the potential for businesses to enhance efficiency and security, making a new era in software development and cybersecurity truly possible. About Sonatype Attachment ![]() Elissa Walters Sonatype ewalters@sonatype.com More NewsView MoreVia MarketBeat
Why Palantir Slide May Be a Setup for a Long-Term Opportunity ↗
Today 10:36 EST
Via MarketBeat
Attention Income Investors: This REIT Is on Sale ↗
Today 9:01 EST
Via MarketBeat
Tickers
RKLB
MarketBeat Week in Review – 11/17 - 11/21 ↗
Today 7:00 EST
Recent QuotesView More
Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes. By accessing this page, you agree to the Privacy Policy and Terms Of Service.
© 2025 FinancialContent. All rights reserved.
|
