Welcome to the JFrog Blog

All Blogs

Fast Remediation Is the New Trust Model: JFrog and OpenAI Collaboration on Zero-Day Security Findings

Fast Remediation Is the New Trust Model: JFrog and OpenAI Collaboration on Zero-Day Security Findings

UPDATE August 5, 2026: This week at Black Hat USA, the OpenAI team presented a detailed reconstruction of the chain of events behind the Hugging Face incident. I was glad to watch OpenAI speaking openly about it. This kind of transparency reflects the same spirit of collaboration we experienced working with their team behind the…
The Perfect Heist: NuGet Typosquat Targets Betting Platform to Rig Results

The Perfect Heist: NuGet Typosquat Targets Betting Platform to Rig Results

The JFrog Security Research team has discovered and disclosed a typosquatted NuGet package named Newtonsoftt.Json.Net. Note the double t and the .Net suffix.  This package has been masquerading as the popular Newtonsoft.Json library while quietly shipping a trojanized fork. The trojan rigs Digitain, an online betting platform, and in later generations, exfiltrates rigged round results…
Secure AI Workflows: The Identity and Access Management (IAM) Checklist

Secure AI Workflows: The Identity and Access Management (IAM) Checklist

AI agents and LLMs are already building, analyzing, and deploying code across your software development lifecycle. As software supply chains become increasingly AI-driven, proactive security and access controls are your only path to success. To effectively govern authentication and permissions without sacrificing development speed, you must update your access management strategies. By securing the AI…
Beyond Tokens SF: Best Ideas of the Evening

Beyond Tokens SF: Best Ideas of the Evening

AI agents are changing how software gets built, but the infrastructure around them hasn't caught up. Agents burn through tokens on noise. They take actions they shouldn't. Context evaporates between releases. And most delivery pipelines were never designed for the pace and volume of agentic development. On June 11th we brought together developers in San…
Where Severity Scores Go Wrong: “Just Add Prototype Pollution”

Where Severity Scores Go Wrong: “Just Add Prototype Pollution”

At JFrog, our Security Research team continuously monitors and analyzes newly disclosed CVEs across the open-source ecosystem. Throughout our research, we have repeatedly observed cases where the assigned severity score does not accurately reflect a vulnerability's real-world impact or exploitability. In fact, during 2025, JFrog researchers reassessed NVD critical-severity vulnerabilities and concluded that 96% warranted…
JFrog Named a Leader in the Inaugural Gartner<sup>®</sup> Magic Quadrant™ for Software Supply Chain Security

JFrog Named a Leader in the Inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security

The recognition is new; the commitment behind it isn't. It's official. Gartner just published the very first Gartner® Magic Quadrant™ for Software Supply Chain Security, and JFrog has been recognized as a Leader, placing highest for Ability to Execute among all the vendors included. For an inaugural report in a category this important, that placement…
How JFrog and NanoClaw are Bringing Software Supply Chain Security to the Age of Autonomous AI

How JFrog and NanoClaw are Bringing Software Supply Chain Security to the Age of Autonomous AI

There's a category of security risk that most organizations aren't ready for. It doesn't live in your code repository, your CI pipeline, or your developer laptops. It lives in your runtime, in the autonomous AI agents already running in your environment, extending their own capabilities, and making decisions that no human explicitly approved. This is…