Welcome to the JFrog Blog

All Blogs

Dissecting and Exploiting CVE-2025-62507: Remote Code Execution in Redis

Dissecting and Exploiting CVE-2025-62507: Remote Code Execution in Redis

A recent stack buffer overflow vulnerability in Redis, assigned CVE-2025-62507, was fixed in version 8.3.2. The issue was published with a high severity rating and assigned a CVSS v3 score of 8.8. According to the official advisory, “a user can run the XACKDEL command with multiple IDs and trigger a stack buffer overflow, which may…
Beyond the Hype: Building a Future-Proof Foundation for the AI-Native Enterprise

Beyond the Hype: Building a Future-Proof Foundation for the AI-Native Enterprise

We are witnessing a fundamental transformation in how software is built. The industry has moved beyond the experimental phase of Machine Learning Operations and entered a complex new reality: the era of the AI Software Supply Chain. The adoption metrics confirm this shift is irreversible. Google reports that 90% of tech workers are now using…
JFrog Achieves AWS Security Competency

JFrog Achieves AWS Security Competency

At JFrog, our mission has long been to power the future of software, and we believe that future is undeniably cloud-native. This is why we’ve architected our platform as a container-first, Kubernetes-native SaaS—built for performance at scale on the world's leading cloud infrastructure. Our deep commitment to cloud excellence has reached a major milestone in…
2026: Trust Is the Currency, Platforms Are the Standard, and Vendors Must Justify Their Seat at the Table

2026: Trust Is the Currency, Platforms Are the Standard, and Vendors Must Justify Their Seat at the Table

Listen to a NotebookLM podcast version of the blog: Your browser does not support the audio element. First things first Those who know me know that I don’t publish predictions just because the calendar flips, and for a few years, I’ve avoided posting blogs, forecasts, and year-end summaries. But 2025 was different. Not because of…
Why Enterprise and Fortune 500 Companies are Leaving Snyk and Checkmarx for JFrog

Why Enterprise and Fortune 500 Companies are Leaving Snyk and Checkmarx for JFrog

Effectively protecting your software supply chain has reached a critical turning point where the traditional strategy of integrating "best of breed" or point AppSec solutions is no longer sustainable. While tools like Snyk and Checkmarx served a purpose in the era of siloed development and security, today we’re seeing how leading companies are moving away…
JFrog vs Checkmarx: An AppSec Solution Comparison

JFrog vs Checkmarx: An AppSec Solution Comparison

Application Security (AppSec) can’t stop at source code. Today’s software is assembled, not written, from open-source packages, containers, binaries, and increasingly - AI models. While traditional AppSec tools like Checkmarx focus primarily on source code scanning, that approach leaves critical security and compliance gaps across the software supply chain. JFrog takes AppSec to the next…
JFrog vs Snyk: Why Effective AppSec Must Move Beyond Source Code

JFrog vs Snyk: Why Effective AppSec Must Move Beyond Source Code

The tech world is abuzz with the potential of AI and automated development, but this rapid advance is fueling a massive increase in regulatory scrutiny and supply chain risk. While many teams rely on source code scanning, focusing on code alone leaves a critical "malware blind spot" in the software supply chain. Today’s applications are…
Docker Hardened Images are Free: Scale Their Adoption with JFrog

Docker Hardened Images are Free: Scale Their Adoption with JFrog

Securing your Docker containers just got a lot easier. On December 17, Docker announced that their catalog of over 1,000 Docker Hardened Images (DHI)—previously a premium-only feature—is now free and open source. This big change means every developer can now start their Dockerfile with a minimalist, near-zero CVE, SLSA Level 3 compliant foundation. If you’re…
swampUP Europe 2025 Recap

swampUP Europe 2025 Recap

The energy was electrifying as the inaugural swampUP Europe 2025 kicked off at the JW Marriott this past November! For three days Berlin became the epicenter of the DevOps, DevSecOps, and MLOps universe, buzzing with a sense of intrigue and excitement. This wasn’t just another tech conference; it was a convergence of innovation and regulation,…