Welcome to the JFrog Blog

All Blogs

The New Rules of Patching: When a Fix Becomes a Blueprint for Attackers

The New Rules of Patching: When a Fix Becomes a Blueprint for Attackers

TL;DR: Frontier AI has collapsed the vulnerability exploit window from weeks to mere hours. Attackers now use advanced AI models to reverse-engineer published fixes and generate working exploits faster than human security teams can deploy updates. In the AI era, publishing a patch creates a blueprint for attackers. Surviving this threat requires vendors to tier sensitive…
ParaShells: Parallels Desktop Turns Appliance Install Into a Root Shell

ParaShells: Parallels Desktop Turns Appliance Install Into a Root Shell

Your Mac runs a vulnerable version of Parallels Desktop. A malicious package, compromised CI job, or other unprivileged process is already running on it. No admin access. No Parallels-signed client. One appliance-install request later, attacker-controlled code runs as root. While testing Desktop 26.4.0 (build 57513) on Apple silicon, we found that an unprivileged local user…
Extending the Single Source of Truth to the Agentic Software Supply Chain

Extending the Single Source of Truth to the Agentic Software Supply Chain

Every developer on your team now runs multiple agents. None of them are waiting for human sign-off to act. That's exactly the gap we discussed and closed at swampUP 2026. JFrog unveiled new capabilities that extend the JFrog Platform as not only the Single Source of Truth for OSS and heritage software, but now the…
Live From the Show Floor: swampUP 2026

Live From the Show Floor: swampUP 2026

Live updates from this event have concluded. swampUP 2026 is officially LIVE in New York City! Three days, one stage, one mission: rebuild trust for a software supply chain that increasingly ships itself. Keynote updates land here as they happen, September 1–3, 2026. Let’s go! Conference Day 2, September 3rd [11:00 a.m.] The Great Model…
DevGovOps: How the AI Era Dictates That Governance Lives Inside the Pipeline

DevGovOps: How the AI Era Dictates That Governance Lives Inside the Pipeline

For decades, proving compliance meant having a person behind every decision - an engineer who remembered the approval, an auditor who could call someone and get an answer. That model worked because humans wrote, reviewed, and shipped every line of code. When agents do it instead, that dependency breaks. And so does your ability to…
The Evolution of JFrog AI Catalog: Your AI Control Plane for Agentic Development

The Evolution of JFrog AI Catalog: Your AI Control Plane for Agentic Development

In a single morning, a coding agent can pull an open-source model, connect to an unvetted MCP server, and execute a code-optimizing skill from the web. In the rush toward agentic automation, these AI assets quietly bypass traditional security reviews, creating new attack vectors across the software supply chain. Closing this blind spot has been…
Securing the Australian Government Software Supply Chain: JFrog Completes Protected Level IRAP Assessment

Securing the Australian Government Software Supply Chain: JFrog Completes Protected Level IRAP Assessment

JFrog has reached a major milestone: An IRAP assessment at the Protected level, across the full JFrog Platform. Conducted by CyberCX, an Australian Signals Directorate (ASD)-endorsed assessor, against the ISM, it independently validates that the platform managing an agency’s software supply chain meets the bar for Australia’s most sensitive workloads. It reasserts a commitment that…