Home / Companies / JFrog / Blog / September 2025

September 2025 Summaries

17 posts from JFrog

Filter
Month: Year:
Post Summaries Back to Blog
Software organizations face the challenge of balancing speed and trust in their development processes, as moving too fast can lead to security issues while being too slow allows competitors to gain an edge. This dilemma often stems from the complex and misaligned software pipeline, characterized by manual handoffs and fragmented data. To address these issues, JFrog and ServiceNow have partnered to integrate their platforms, creating DevGovOps by automating governance, risk, and compliance (GRC) processes in software development. The integration between JFrog AppTrust and ServiceNow DevOps Change Velocity aims to eliminate friction by automating evidence collection and providing a unified view of software development lifecycle (SDLC) evidence, facilitating faster and more informed change management decisions. This partnership ensures that once a change is approved, it is securely promoted to production, enabling seamless and secure software delivery. With this integration, development workflows become more efficient and aligned, offering a fast and trusted approach to software development in the AI-driven era.
Sep 30, 2025 565 words in the original blog post.
As the AI revolution progresses, developers are introduced to a surge of innovative tools, enhancing productivity but simultaneously increasing cybersecurity risks due to the rapid adoption outpacing security measures. The developer security landscape has improved in securing open-source software dependencies, yet software supply chain security risks are escalating, particularly with the advent of sophisticated supply chain attacks like the one affecting npm packages in 2025. This attack, which compromised 20 packages with over 2 billion downloads, highlighted the growing threat of vulnerabilities in developer tools and extensions. To address these challenges, JFrog introduces a solution called Curation, designed to block risky or malicious components from entering the development lifecycle by only allowing vetted dependencies and packages. Curation acts as a firewall, maintaining security without hindering developer productivity by enforcing policies that prevent the use of immature packages while providing compliant alternatives, thus creating a balance between security needs and development efficiency.
Sep 19, 2025 639 words in the original blog post.
Frogward Innovation Days, hosted by JFrog India in Bangalore, is an annual week-long festival that fosters collaboration and creativity among cross-functional teams from engineering, IT, marketing, sales ops, and support, alongside start-ups and customers, to address real-world challenges in software delivery. This year's theme of 'productivity' inspired various activities, including hackathons and prototype showcases, where employees explored bold ideas and turned them into practical solutions that directly benefit customers, emphasizing the philosophy that customer success drives their own success. The event highlighted JFrog India's role as a global growth hub in software supply chain management by encouraging risk-taking, challenging the status quo, and fostering a culture of collaboration and customer-centric innovation. Insights from customers like Myntra and Schneider-Electric, and interactions with start-ups, provided valuable perspectives that ensured the innovations were aligned with industry needs and trends. Frogward Innovation Days underscored the importance of empathy, creativity, and technical experimentation, serving as a catalyst for embedding these principles into JFrog's daily operations, while planning future community meetups and hackathons to further engage with the broader software development community.
Sep 18, 2025 1,155 words in the original blog post.
Held in Napa Valley, swampUP 2025 was JFrog's annual customer conference, bringing together leaders from various fields to address the challenges of AI-driven software delivery. The event emphasized the necessity of a unified Software Supply Chain platform to navigate the complexities introduced by AI and quantum shifts in development. JFrog introduced six innovative products, including JFrog AppTrust for application risk governance and JFrog AI Catalog as a unified system of record for AI/ML models. The JFrog Platform was highlighted as the foundational system of record for modern software supply chains, addressing security threats and evolving regulatory landscapes. Industry leaders such as NVIDIA, ServiceNow, Sonar, and GitHub joined JFrog to showcase a vision for integrated ecosystems that streamline development workflows. The conference also focused on emerging practices like DevGovOps, integrating governance, risk, and compliance into development processes to ensure secure and compliant software releases. With announcements of new integrations and products like JFrog Fly, an agentic repository, and features like Agentic Remediation and Developer Extensions Security, JFrog aims to enhance productivity and security in the AI-driven era. The event concluded with plans to hold the next swampUP conference in Berlin, further expanding its international reach.
Sep 17, 2025 2,226 words in the original blog post.
The npm ecosystem recently experienced its third major attack, involving the compromise of numerous packages, including the @ctrl/[email protected] package, initially reported by Daniel Pereira. JFrog’s malware scanners later identified 164 malicious packages across 338 versions, all containing variations of a data-stealing payload disguised as system optimization software. This payload, known as the Shai-Hulud Data Stealer, collects sensitive information from platforms like GitHub, NPM, AWS, and GCP, and uses TruffleHog to search for secrets, subsequently storing the stolen data in a GitHub repository called Shai-Hulud. The attack's iterations suggest the attacker’s ongoing adjustments, with some versions extending to steal Azure credentials and others making repositories private. Users impacted by these compromised packages are advised to rotate access tokens for the affected services and consider using JFrog Curation for proactive defense against malicious packages. While the attack's resemblance to a previous NX CLI compromise implies a potential link, the exact attribution remains uncertain.
Sep 16, 2025 1,133 words in the original blog post.
JFrog Security Research has disclosed several critical vulnerabilities, collectively called "Chaotic Deputy," in the popular Chaos engineering platform Chaos-Mesh. These vulnerabilities, identified as CVE-2025-59358, CVE-2025-59359, CVE-2025-59360, and CVE-2025-59361, allow in-cluster attackers to execute arbitrary code on any pod within a Kubernetes cluster, posing a risk of cluster-wide denial-of-service attacks and unauthorized access to privileged information. Users of Chaos-Mesh are advised to upgrade to version 2.7.3 or apply recommended workarounds to mitigate these risks. The vulnerabilities stem from issues such as missing authentication and OS command injection, which enable attackers to exploit the Chaos Controller Manager's exposed GraphQL server. JFrog has worked with the Chaos-Mesh maintainers to address these issues, emphasizing the need for vigilance in maintaining secure systems in the face of evolving threats.
Sep 16, 2025 1,923 words in the original blog post.
AI and machine learning (AI/ML) are revolutionizing technology but face increasing scrutiny from global regulators demanding rigorous transparency and accountability. The rapid development pace and significant power of AI/ML technologies have widened the scope of risk assessment, with regulators concerned about data privacy, intellectual property, and potential negative impacts like algorithmic bias or misinformation. Europe's comprehensive regulations, such as the European Union Artificial Intelligence Act, impose strict compliance requirements, with potential penalties for non-compliance, while the US and other countries are developing their own legislative frameworks. To address these challenges, an integrated approach like Continuous Compliance Automation (CCA), exemplified by JFrog's Evidence Collection, can help ensure compliance by automating security and regulatory processes throughout the AI/ML model lifecycle. This approach supports developers, security teams, and stakeholders in maintaining a trusted environment, offering a reliable path to production that aligns with compliance obligations.
Sep 11, 2025 779 words in the original blog post.
Managing and securing developer tools such as IDE extensions and plugins is crucial for maintaining an efficient and secure software development environment, as highlighted by the challenges of inconsistency, security risks, and operational overhead associated with unregulated use of these tools. The proposed solution involves leveraging JFrog's platform to implement a two-step approach: first, by creating a managed repository for extensions, which reduces redundant downloads, standardizes the developer experience, and centralizes control and visibility; and second, by using JFrog Curation to proactively scan and apply automated security policies to prevent the installation of malicious or vulnerable extensions. This approach ensures a secure, consistent, and cost-effective development process, emphasizing the importance of securing the software supply chain starting from the developer's IDE.
Sep 10, 2025 684 words in the original blog post.
At swampUP 2025, JFrog and GitHub announced a new integration that unifies source code and binary security into a single DevSecOps workflow, addressing the traditional separation that causes blind spots and increased risks. This integration delivers end-to-end security and visibility across the software supply chain, enhancing automation, unification, and intelligence. Key features include a simplified setup with secure authentication, bulk deployment of the Frogbot for automated scanning, unified security results in GitHub's dashboard, and the merging of source and binary Software Bill of Materials (SBOMs). Additionally, GitHub Copilot now accesses JFrog’s security knowledge for agentic remediation, ensuring secure coding. The integration also streamlines audits and provides compliance through evidence-backed attestations, offering significant benefits to developers, DevOps, platform, and security teams by reducing context switching and enhancing security practices across multiple repositories.
Sep 10, 2025 954 words in the original blog post.
JFrog's annual user conference, swampUP 2025, highlighted the transformative impact of AI on DevOps, DevSecOps, and MLOps, emphasizing the importance of integration, agency, and trust in the evolving software landscape. Keynotes from industry leaders explored the challenges and opportunities presented by AI, such as the need for new integration models, the rise of AI agents as critical users, and the significance of trust and security in software development. The conference also showcased JFrog's innovations, including the Agentic Remediation, AppTrust, and AI Catalog, designed to enhance software supply chain security and management. Attendees were urged to embrace the quantum shift in technology, leveraging AI to improve productivity while maintaining compliance and governance across platforms. Collaborative efforts with partners like NVIDIA, GitHub, and ServiceNow were highlighted as essential for advancing a secure and efficient AI-driven software future.
Sep 09, 2025 6,080 words in the original blog post.
AI innovation is advancing rapidly, offering new opportunities for organizations, yet challenges such as model proliferation, security issues, and governance gaps hinder the journey to production-ready AI applications. In response, JFrog has introduced the JFrog AI Catalog, a comprehensive hub for discovering, governing, and serving AI and ML models, developed in collaboration with partners like NVIDIA. This catalog aims to centralize control, enhance security, and maintain compliance by integrating AI models into the trusted software supply chain, providing visibility and control over model usage with security policies to block unapproved models. It also simplifies access and deployment of models, reducing friction in discovery and enhancing productivity and collaboration by offering a centralized repository for various model types, including those from external providers. The catalog not only addresses current challenges but also lays the groundwork for future AI strategies, enabling a streamlined model development lifecycle and a secure, efficient path to production.
Sep 09, 2025 791 words in the original blog post.
The pressure to rapidly deliver applications has created vulnerabilities in the software supply chain, prompting new regulations that shift liability to developers, requiring auditable security proof throughout the product lifecycle. Organizations often struggle with fragmented approaches, relying on individual security scanners and Application Security Posture Management (ASPM) tools that lack application context, leading to weak prioritization and a dependence on manual governance that cannot keep pace with compliance demands. JFrog AppTrust addresses this issue by offering a comprehensive solution for application risk governance, consolidating security, governance, and compliance to ensure reliability and operational efficiency. AppTrust allows organizations to set evidence-based policies as control gates at each stage of the software development lifecycle, providing a "Trusted Release" badge to applications that meet all policy requirements. It facilitates collaboration between security, DevOps, and GRC teams by providing a unified view of application context, including a complete Software Bill of Materials (SBOM) and a timeline of all versions. AppTrust integrates with tools like GitHub and ServiceNow to trigger alerts and ensure compliance without slowing release cadence, while maintaining post-deployment monitoring to address new vulnerabilities. As part of the JFrog Platform, AppTrust supports AI-era advancements by offering a single, transparent record of application actions, promoting effective collaboration and balancing speed with safety.
Sep 09, 2025 1,205 words in the original blog post.
As software supply chains grow increasingly complex, governance, risk, and compliance (GRC) initiatives gain importance, especially as new software and AI regulations emerge. The fragmented nature of the Software Development Life Cycle (SDLC) audit trail poses challenges for organizations needing to prove compliance, often requiring manual processes to collect evidence. In response, JFrog has launched its third-party Evidence Collection service to streamline this process by allowing teams to capture and store evidence linked to binaries within the JFrog Platform, thus enhancing auditability. With an aim to simplify and accelerate evidence collection, JFrog has partnered with leading SDLC vendors to natively integrate with their tools, automating the collection of attestations and fostering DevGovOps practices. JFrog introduces its Founding Evidence Collection Integrations, starting with 12 partners, to support comprehensive ecosystem evidence and ensure fast, trusted software releases. This initiative is part of JFrog's broader commitment to providing a unified and verifiable system of record for SDLC proof, which allows users to automate application risk governance and set evidence-based policies.
Sep 09, 2025 1,227 words in the original blog post.
JFrog has introduced Agentic Software Supply Chain Security to address the increasing complexity of software supply chains, which are a major target for cybercriminals. By integrating AI-driven automation with JFrog's platform, this solution enables development teams to proactively curate safer software packages, remediate vulnerabilities, and enhance compliance, effectively shifting from reactive to proactive security measures. It incorporates tools such as JFrog Catalog, Curation, SAST, GitHub Copilot, and VSCode, offering features like AI-powered package selection and contextual source code remediation within developers' IDEs. The platform facilitates seamless and efficient CVE remediation, reducing risks and operational costs while improving productivity by allowing developers to focus on innovation rather than manual security tasks. JFrog's approach emphasizes agentic, autonomous remediation to transform DevSecOps practices, providing end-to-end visibility and integrating security intelligence across development workflows, ultimately resulting in faster, more secure software delivery.
Sep 09, 2025 1,174 words in the original blog post.
A recent phishing campaign compromised the npm registry by publishing trojanized versions of 18 popular packages, including "debug," "chalk," and "ansi-styles," after obtaining developers’ tokens. The malicious code, obfuscated with the "javascript-obfuscator" library, contained a cryptocurrency stealer that intercepted web3 transactions, redirecting funds to the attacker's wallet. Despite its widespread reach, affecting packages with over two billion total downloads, the attack caused minimal practical damage, with only about $500 in cryptocurrency stolen due to the quick detection of the poorly obfuscated malware. This incident, the largest supply chain attack in npm’s history, underscores the fragility of the JavaScript ecosystem, where many utilities depend on single developers. Further compromised accounts, such as "duckdb," suggest the campaign is ongoing, and continuous monitoring is underway to update any new developments.
Sep 09, 2025 514 words in the original blog post.
AI agents, evolving rapidly from simple text generators to complex autonomous assistants, are now capable of tasks such as web browsing and travel booking, but their increasing autonomy exposes them to new security threats. A novel attack vector highlighted by JFrog Security Research exploits this vulnerability by using website cloaking and browser fingerprinting techniques to target AI agents specifically. This stealthy approach serves benign content to human users while delivering malicious prompts to AI agents, which remain unaware of the deception due to their predictable digital fingerprints. The attack effectively hijacks AI agents, leading to unauthorized data access and manipulation. This strategy represents a new form of the "living off the land" attack, where the AI itself becomes a tool for malicious activity. As AI agents become more integrated into digital interactions, the need for enhanced security measures to protect against such sophisticated threats grows increasingly urgent.
Sep 04, 2025 1,137 words in the original blog post.
In today's fast-paced software development landscape, organizations are driven by the need to rapidly release software to stay competitive, leading to trends like increased developer accountability, platform engineering, and cloud computing. However, this rush can risk compromising trust, a crucial factor akin to brand reputation. The balance between speed and trust is vital, as demonstrated by incidents where cutting corners led to significant financial losses and reputational damage. The concept of a "trusted software factory" involves key elements like Ownership, Control, and Compliance, which require orchestration and collaboration to ensure a seamless, trustworthy development pipeline. Challenges such as managing ownership at scale, embedding security throughout the lifecycle, and ensuring compliance through evidence are critical in achieving trust. Best practices for building trust into development processes include unifying software operations, integrating security, and fostering collaboration. Ultimately, a unified approach where all stakeholders align and share information is essential for managing risks and ensuring the delivery of reliable and secure software.
Sep 03, 2025 2,089 words in the original blog post.