February 2026 Summaries
3 posts from Arnica
Filter
Month:
Year:
Post Summaries
Back to Blog
A new software supply chain attack, dubbed SANDWORM_MODE, is targeting the npm ecosystem by compromising at least 19 packages, including popular Node.js utilities and AI coding tools, and exfiltrating data using sophisticated methods like GitHub API and DNS tunneling. Organizations are challenged by the lack of enterprise-wide visibility into software dependencies, making it difficult to assess exposure quickly. In response, Arnica has introduced a feature allowing customers to filter their Software Bill of Materials (SBOM) based on active zero-day campaigns, enabling real-time identification of affected repositories and applications. This feature, available to all Arnica customers, underscores the importance of continuous visibility in software supply chains to swiftly address threats.
Feb 21, 2026
842 words in the original blog post.
The latest Application Security Market Report by Latio Tech highlights significant shifts in the application security landscape, emphasizing the critical importance of developer experience and the challenges posed by AI-generated code. Arnica is recognized as a leader in this field, earning the titles of Developer Experience Innovator and AI Code Innovator for its efforts to integrate security into AI coding workflows. This approach aims to ensure secure code generation by providing AI agents with necessary security context, thus addressing the shortcomings of traditional security tools that were designed for human-written code. The report underscores the necessity of evolving security practices to align with rapid advancements in AI-assisted development, advocating for a proactive "shift left" approach that prevents vulnerabilities during code generation rather than identifying them post-factum. As developer workflows evolve with AI, application security tools must adapt to support speed and seamless integration, ensuring that security becomes an enabler rather than a hindrance in the development process.
Feb 17, 2026
654 words in the original blog post.
The evolution of application security tools is being driven by the rapid advancements in software development and AI integration, requiring modern tools to go beyond traditional static source code security. These tools now need to provide comprehensive coverage that includes AI-assisted development, open-source dependencies, infrastructure as code, and cloud-native architectures, all while integrating seamlessly into developer workflows to deliver timely security feedback. In 2026, the emphasis has shifted towards real-time, developer-native security platforms that engage developers earlier in the process, reducing backlog and preventing risks from reaching production. New-generation tools such as Aikido, Apiiro, Arnica, Checkmarx, Cycode, Ox Security, Snyk, and Veracode each offer unique capabilities and trade-offs, catering to different organizational needs. Effective AppSec tools are now measured by their ability to help teams address the most critical vulnerabilities promptly and efficiently, supporting modern development practices and minimizing the need for multiple point solutions.
Feb 13, 2026
1,427 words in the original blog post.