56,966 blogs · [ { "id": "01a0deea-8d37-716d-b2cf-5d039f12a9c3", "title": "Polaris release update: Bringing AI security findings, scan governance, and remediation together", "url": "https://www.blackduck.com/blog/polaris-september-2026-update.html", "published_at": "2026-09-23T13:28:40+00:00" }, { "id": "01a0deea-8d37-716d-b2cf-5d039f305188", "title": "Top 10 free penetration testing tools", "url": "https://www.blackduck.com/blog/top-10-free-hacking-tools-for-penetration-testers.html", "published_at": "2026-09-23T00:35:33+00:00" }, { "id": "01a0deea-8d37-716d-b2cf-5d03a028df14", "title": "The real and hidden costs of AI security programs", "url": "https://www.blackduck.com/blog/hidden-costs-ai-security-programs.html", "published_at": "2026-09-21T19:39:23+00:00" }, { "id": "01a0deea-8d37-716d-b2cf-5d03a09dd7e9", "title": "Agentic AppSec on your infrastructure with Black Duck Signal", "url": "https://www.blackduck.com/blog/black-duck-signal-byo-llm.html", "published_at": "2026-09-10T17:30:14+00:00" }, { "id": "01a0deea-8d37-716d-b2cf-5d03a1942c0a", "title": "The vulnerability you didn’t write", "url": "https://www.blackduck.com/blog/the-vulnerability-you-didnt-write.html", "published_at": "2026-09-08T20:07:17+00:00" }, { "id": "01a0deea-8d37-716d-b2cf-5d03a21e3076", "title": "Stories from the field, part 2: When vulnerability scores don’t tell the whole story", "url": "https://www.blackduck.com/blog/stories-from-the-field-vulnerability-scores.html", "published_at": "2026-09-02T01:51:08+00:00" }, { "id": "01a0deea-8d37-716d-b2cf-5d03a2473ae0", "title": "OSSRA 2026: Open source vulnerability counts doubled year-over-year", "url": "https://www.blackduck.com/blog/ossra-2026-open-source-vulnerability-counts-doubled-year-over-year.html", "published_at": "2026-08-27T06:19:48+00:00" }, { "id": "01a0deea-8d37-716d-b2cf-5d03a2df0fa6", "title": "Polaris release update: Two-way bug tracker sync, AI-assisted fixes, scanning you can govern", "url": "https://www.blackduck.com/blog/polaris-august-2026-update-bug-tracker-sync-governed-scanning.html", "published_at": "2026-08-19T06:00:00+00:00" }, { "id": "01a0deea-8d37-716d-b2cf-5d03a2fd1f63", "title": "Polestar’s U.S. market exit is a warning for automakers", "url": "https://www.blackduck.com/blog/polestar-connected-vehicle-rule-denial-automaker-software-compliance.html", "published_at": "2026-08-18T23:02:05+00:00" }, { "id": "01a0deea-8d37-716d-b2cf-5d03a35a94d7", "title": "The AI coding security gap: Why faster development demands stronger guardrails", "url": "https://www.blackduck.com/blog/ai-coding-assistants-cybersecurity-defense-in-depth.html", "published_at": "2026-08-14T20:16:08+00:00" }, { "id": "01a0df01-eae7-72f7-a073-1a8f6a0adaa2", "title": "AI application security needs both reasoning and assurance", "url": "https://www.blackduck.com/blog/ai-application-security-reasoning-and-assurance.html", "published_at": "2026-08-13T19:37:40+00:00" }, { "id": "01a0df01-eae7-72f7-a073-1a8f6af4bd77", "title": "The hidden liabilities in open source AI model adoption", "url": "https://www.blackduck.com/blog/open-source-ai-model-licensing-risk.html", "published_at": "2026-08-07T18:30:43+00:00" }, { "id": "01a0df01-eae7-72f7-a073-1a8f6b8ebe59", "title": "Countdown to the next EU CRA milestone", "url": "https://www.blackduck.com/blog/eu-cyber-resilience-act-cra-article-14-deadline.html", "published_at": "2026-07-21T18:46:10+00:00" }, { "id": "01a0df01-eae7-72f7-a073-1a8f6c4b51b4", "title": "Polaris achieves TX-RAMP certification: A milestone in our public sector commitment", "url": "https://www.blackduck.com/blog/black-duck-polaris-tx-ramp-fedramp-government-appsec.html", "published_at": "2026-07-15T15:15:13+00:00" }, { "id": "01a0df01-eae7-72f7-a073-1a8f6d1a69f1", "title": "Polaris release update: Smarter risk scoring, AI-assisted triage, and complete container coverage", "url": "https://www.blackduck.com/blog/black-duck-polaris-july-2026-release.html", "published_at": "2026-07-14T00:06:19+00:00" }, { "id": "01a0df01-eae7-72f7-a073-1a8f6da36da8", "title": "What your scanner can’t see: Deep visibility into hardened container images with Black Duck", "url": "https://www.blackduck.com/blog/hardened-container-image-scanning-vulnerability-scanner.html", "published_at": "2026-06-29T23:14:26+00:00" }, { "id": "01a0df01-eae7-72f7-a073-1a8f6e4eedb4", "title": "What open source scans don’t see in M&A due diligence: stories from the field", "url": "https://www.blackduck.com/blog/open-source-audit-software-ma-due-diligence.html", "published_at": "2026-06-25T19:47:22+00:00" }, { "id": "01a0df01-eae7-72f7-a073-1a8f6f3c88de", "title": "Black Duck named a Leader in the first-ever Gartner Magic Quadrant for Software Supply Chain Security", "url": "https://www.blackduck.com/blog/gartner-magic-quadrant-software-supply-chain-security-leader.html", "published_at": "2026-06-22T19:58:11+00:00" }, { "id": "01a0df01-eae7-72f7-a073-1a8f6fb2ecfd", "title": "From commit to confidence: Black Duck for Bitbucket", "url": "https://www.blackduck.com/blog/black-duck-for-bitbucket.html", "published_at": "2026-06-19T23:07:13+00:00" }, { "id": "01a0df01-eae7-72f7-a073-1a8f6fe5c63c", "title": "Why the future of application security isn’t AI or SAST—it’s both", "url": "https://www.blackduck.com/blog/hybrid-ai-sast-application-security-model.html", "published_at": "2026-06-18T22:25:33+00:00" }, { "id": "01a0df17-4cec-7009-830d-aa3f2a0e2453", "title": "Key deadlines and reporting requirements for the EU Cyber Resilience Act (CRA)", "url": "https://www.blackduck.com/blog/eu-cyber-resilience-act-cra-compliance-deadlines.html", "published_at": "2026-06-17T22:00:09+00:00" }, { "id": "01a0df17-4cec-7009-830d-aa3f2a295245", "title": "Polaris release update: Automated remediation, reachability-driven prioritization, and deeper scanning coverage", "url": "https://www.blackduck.com/blog/black-duck-polaris-june-2026-platform-updates.html", "published_at": "2026-06-15T21:27:47+00:00" }, { "id": "01a0df17-4cec-7009-830d-aa3f2a7502c8", "title": "Why LLM API keys should be treated like tier‑zero secrets", "url": "https://www.blackduck.com/blog/llm-api-key-security-hardcoded-secrets-detection.html", "published_at": "2026-06-03T18:43:52+00:00" }, { "id": "01a0df17-4cef-718a-bdb8-626ec9b2ff0b", "title": "Beyond the noise: Better risk prioritization with Polaris reachability analysis", "url": "https://www.blackduck.com/blog/beyond-the-noise-better-risk-prioritization-with-polaris-reacha.html", "published_at": "2026-05-22T20:18:54+00:00" }, { "id": "01a0df17-4cef-718a-bdb8-626eca7651e9", "title": "Polaris release update: Expanded integrations, deeper detection, complete license governance", "url": "https://www.blackduck.com/blog/black-duck-polaris-may-2026-platform-updates.html", "published_at": "2026-05-18T00:00:00+00:00" }, { "id": "01a0df17-4cef-718a-bdb8-626ecb166215", "title": "Prompt injection: Can a fifth grader steal your data?", "url": "https://www.blackduck.com/blog/prompt-injection-ai-security-tech-acquisition-due-diligence.html", "published_at": "2026-05-15T00:00:00+00:00" }, { "id": "01a0df17-4cef-718a-bdb8-626ecb8d570a", "title": "Leading organizations address growing regulatory pressures with automation", "url": "https://www.blackduck.com/blog/software-security-compliance-automation-bsimm16.html", "published_at": "2026-05-04T00:00:00+00:00" }, { "id": "01a0df17-4cef-718a-bdb8-626ecbaca91c", "title": "NVD Changes 2026: Why public vulnerability data is no longer enough", "url": "https://www.blackduck.com/blog/nist-nvd-policy-shift-2026.html", "published_at": "2026-04-24T00:00:00+00:00" }, { "id": "01a0df17-4cef-718a-bdb8-626ecc78f579", "title": "Catch critical defects before embedded software ships", "url": "https://www.blackduck.com/blog/catch-defects-embedded-software.html", "published_at": "2026-04-21T00:00:00+00:00" }, { "id": "01a0df17-4cef-718a-bdb8-626eccd2f8f2", "title": "Polaris release update: Streamlined workflows, stronger governance, smarter detection", "url": "https://www.blackduck.com/blog/polaris-ai-security-updates-april-2026.html", "published_at": "2026-04-14T00:00:00+00:00" }, { "id": "01a0df2b-b031-71e3-8eab-cb5037914c70", "title": "What Anthropic’s Project Glasswing means for software builders", "url": "https://www.blackduck.com/blog/ai-security-glasswing-mythos.html", "published_at": "2026-04-13T00:00:00+00:00" }, { "id": "01a0df2b-b031-71e3-8eab-cb5037d69179", "title": "The third wave of application security: How AI is reshaping AppSec at scale", "url": "https://www.blackduck.com/blog/ai-transforming-appsec-black-duck-ceo-rsa-2026.html", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a0df2b-b031-71e3-8eab-cb50381a630f", "title": "Strange but true software licenses: No foolin’", "url": "https://www.blackduck.com/blog/quirky-open-source-licenses-guide.html", "published_at": "2026-04-01T00:00:00+00:00" }, { "id": "01a0df2b-b031-71e3-8eab-cb503832a04b", "title": "Decoding AI-enabled dev: Top concerns, hidden benefits, and smart investment strategies", "url": "https://www.blackduck.com/blog/ai-devsecops-investment-strategies.html", "published_at": "2026-03-31T00:00:00+00:00" }, { "id": "01a0df2b-b031-71e3-8eab-cb5038a9acb8", "title": "Coverity Connect Vulnerability Notification", "url": "https://www.blackduck.com/blog/coverity-connect-cve-2026-1496-security-advisory.html", "published_at": "2026-03-26T00:00:00+00:00" }, { "id": "01a0df2b-b031-71e3-8eab-cb503913b039", "title": "Black Duck Signal: Security that moves at the speed of AI", "url": "https://www.blackduck.com/blog/black-duck-signal-security-that-moves-at-the-speed-of-ai.html", "published_at": "2026-03-23T00:00:00+00:00" }, { "id": "01a0df2b-b031-71e3-8eab-cb50394e6b1a", "title": "AI is rewriting the rules of application security—and most organizations aren’t ready", "url": "https://www.blackduck.com/blog/ai-application-security-bsimm16-insights.html", "published_at": "2026-03-17T00:00:00+00:00" }, { "id": "01a0df2b-b031-71e3-8eab-cb5039e01994", "title": "The importance of software quality audits during M&A due diligence: Stories from the field", "url": "https://www.blackduck.com/blog/software-quality-audits-ma-due-diligence.html", "published_at": "2026-03-16T00:00:00+00:00" }, { "id": "01a0df2b-b031-71e3-8eab-cb503aa7a0ca", "title": "Feedback through agents: Moving beyond verdict‑only instrumentation", "url": "https://www.blackduck.com/blog/feedback-through-agents-moving-beyond-verdictonly-instrumentati.html", "published_at": "2026-03-09T00:00:00+00:00" }, { "id": "01a0df2b-b031-71e3-8eab-cb503b6636de", "title": "Unlimited test cases: The power of generative fuzzing", "url": "https://www.blackduck.com/blog/unlimited-test-cases-the-power-of-generative-fuzzing.html", "published_at": "2026-03-09T00:00:00+00:00" }, { "id": "01a0df42-50f2-717f-8bc9-baa839624849", "title": "Guided by feedback: Smarter fuzzing with Defensics", "url": "https://www.blackduck.com/blog/guided-by-feedback-smarter-fuzzing-with-defensics.html", "published_at": "2026-03-06T00:00:00+00:00" }, { "id": "01a0df42-50f2-717f-8bc9-baa839ca4656", "title": "Beyond Confidence: Grounding Your AI Security Strategy in Reality", "url": "https://www.blackduck.com/blog/ai-security-confidence-vs-reality-devsecops.html", "published_at": "2026-03-03T00:00:00+00:00" }, { "id": "01a0df42-50f2-717f-8bc9-baa839f000d0", "title": "Software governance in the AI era: Key findings from the 2026 OSSRA report", "url": "https://www.blackduck.com/blog/open-source-trends-ossra-report.html", "published_at": "2026-02-25T00:00:00+00:00" }, { "id": "01a0df42-50f2-717f-8bc9-baa83a623a63", "title": "Evaluating AI powered applications: A new frontier for M&A software due diligence", "url": "https://www.blackduck.com/blog/ai-due-diligence-framework-software-investment.html", "published_at": "2026-02-17T00:00:00+00:00" }, { "id": "01a0df42-50f2-717f-8bc9-baa83a8afebf", "title": "The Olympics: A digital battleground where prevention is the best defense", "url": "https://www.blackduck.com/blog/winter-olympics-cybersecurity-threats-prevention-2026.html", "published_at": "2026-02-12T00:00:00+00:00" }, { "id": "01a0df42-50f2-717f-8bc9-baa83adcfa36", "title": "Event-driven AppSec is here: Thoughtful automation finds risk earlier", "url": "https://www.blackduck.com/blog/event-driven-application-security-automation.html", "published_at": "2026-02-05T00:00:00+00:00" }, { "id": "01a0df42-50f2-717f-8bc9-baa83b6a6aec", "title": "The BSIMM16 report: What today’s software security programs are really doing—and why it matters", "url": "https://www.blackduck.com/blog/bsimm16-benchmark-enterprise-programs.html", "published_at": "2026-02-04T00:00:00+00:00" }, { "id": "01a0df42-50f2-717f-8bc9-baa83c2f16a6", "title": "Navigating the AI frontier: Risks, benefits, and uncharted territory in code development", "url": "https://www.blackduck.com/blog/ai-coding-assistant-security-risks-benefits-devsecops-2025.html", "published_at": "2026-01-22T00:00:00+00:00" }, { "id": "01a0df42-50f2-717f-8bc9-baa83c5483ed", "title": "Navigating the AI security era: Key trends for software leaders in 2026", "url": "https://www.blackduck.com/blog/2026-ai-security-appsec-predictions.html", "published_at": "2026-01-21T00:00:00+00:00" }, { "id": "01a0df42-50f2-717f-8bc9-baa83c5de2f5", "title": "Understanding generative AI risks in software development", "url": "https://www.blackduck.com/blog/generative-ai-risks-in-software.html", "published_at": "2026-01-14T00:00:00+00:00" }, { "id": "01a0df5a-8b3b-722c-829f-38b5c74bedbd", "title": "CyRC Advisory: High-severity vulnerability in TP-Link Archer BE400", "url": "https://www.blackduck.com/blog/black-duck-cyrc-tp-link-be400-cve-2025-14631.html", "published_at": "2026-01-13T00:00:00+00:00" }, { "id": "01a0df5a-8b3b-722c-829f-38b5c7a1d223", "title": "Key learnings from the latest CyRC Wi-Fi vulnerabilities", "url": "https://www.blackduck.com/blog/broadcom-wifi-chipset-vulnerability-router-security.html", "published_at": "2026-01-13T00:00:00+00:00" }, { "id": "01a0df5a-8b3b-722c-829f-38b5c807537e", "title": "CyRC advisory: Vulnerability in Broadcom chipset causes network disruption and client disconnection on wireless routers", "url": "https://www.blackduck.com/blog/cyrc-discovers-asus-tplink-wlan-vulnerabilities.html", "published_at": "2026-01-13T00:00:00+00:00" }, { "id": "01a0df5a-8b3b-722c-829f-38b5c86dd384", "title": "Vibe coding and its implications", "url": "https://www.blackduck.com/blog/vibe-coding-and-its-implications.html", "published_at": "2026-01-06T00:00:00+00:00" }, { "id": "01a0df5a-8b3b-722c-829f-38b5c8b6f884", "title": "AI coding security gap: 76% of orgs expose software supply chain to risk", "url": "https://www.blackduck.com/blog/ai-coding-security-gap-software-supply-chain-risk.html", "published_at": "2025-12-16T00:00:00+00:00" }, { "id": "01a0df5a-8b3b-722c-829f-38b5c9735afb", "title": "Bridging the divide: Why friction between dev and security persists (and how to fix it)", "url": "https://www.blackduck.com/blog/devsecops-automation-reduces-appsec-friction-2025.html", "published_at": "2025-12-16T00:00:00+00:00" }, { "id": "01a0df5a-8b3b-722c-829f-38b5ca572069", "title": "The hidden costs of technical debt in M&A due diligence", "url": "https://www.blackduck.com/blog/business-risk-of-technical-debt.html", "published_at": "2025-12-11T00:00:00+00:00" }, { "id": "01a0df5a-8b3b-722c-829f-38b5ca739652", "title": "Introducing Black Duck Signal: Agentic AI that solves the noise crisis in application security", "url": "https://www.blackduck.com/blog/black-duck-signal-ai-application-security.html", "published_at": "2025-12-10T00:00:00+00:00" }, { "id": "01a0df5a-8b3b-722c-829f-38b5cac1366c", "title": "Embracing AI in embedded software development: A balanced approach", "url": "https://www.blackduck.com/blog/embedded-software-survey-ai-adoption-code-quality.html", "published_at": "2025-12-01T00:00:00+00:00" }, { "id": "01a0df5a-8b3b-722c-829f-38b5cacb5e10", "title": "Vibe coding with a conscience: Why security must be in the mix", "url": "https://www.blackduck.com/blog/secure-vibe-coding-ai-development-cybersecurity.html", "published_at": "2025-11-18T00:00:00+00:00" }, { "id": "01a0df85-cfe0-7068-954a-0fb0dc2a7768", "title": "Black Duck SCA takes on AI: Securing the future of software with model scanning", "url": "https://www.blackduck.com/blog/black-duck-ai-model-scanning.html", "published_at": "2025-11-12T00:00:00+00:00" }, { "id": "01a0df85-cfe0-7068-954a-0fb0dcfae769", "title": "Black Duck’s product release round-up: faster fixes, smarter security", "url": "https://www.blackduck.com/blog/black-duck-product-updates-faster-fixes-smarter-security.html", "published_at": "2025-10-27T00:00:00+00:00" }, { "id": "01a0df85-cfe0-7068-954a-0fb0dd0568f3", "title": "Making intelligent tradeoffs in software due diligence", "url": "https://www.blackduck.com/blog/making-intelligent-tradeoffs-software-due-diligence.html", "published_at": "2025-10-16T00:00:00+00:00" }, { "id": "01a0df85-cfe0-7068-954a-0fb0dd6632f7", "title": "Scaling authenticated DAST with multimodal LLMs and vault-backed credentials", "url": "https://www.blackduck.com/blog/scaling-authenticated-dast-generative-llms-vault-backed-credentials.html", "published_at": "2025-10-15T00:00:00+00:00" }, { "id": "01a0df85-cfe0-7068-954a-0fb0de5b8559", "title": "Black Duck named a Leader in the 2025 Gartner Magic Quadrant for Application Security Testing for the eighth time", "url": "https://www.blackduck.com/blog/black-duck-leader-2025-gartner-magic-quadrant-application-security-testing.html", "published_at": "2025-10-14T00:00:00+00:00" }, { "id": "01a0df85-cfe0-7068-954a-0fb0de6d585f", "title": "AI in DevSecOps: A critical crossroads for security and risk management", "url": "https://www.blackduck.com/blog/ai-in-devsecops-balancing-innovation-and-security.html", "published_at": "2025-10-08T00:00:00+00:00" }, { "id": "01a0df85-cfe0-7068-954a-0fb0ded28d51", "title": "Polaris redefines application security: New release brings unmatched visibility, automation, and compliance", "url": "https://www.blackduck.com/blog/polaris-september-2025-release-enhancements.html", "published_at": "2025-09-30T00:00:00+00:00" }, { "id": "01a0df85-cfe0-7068-954a-0fb0df1cfbac", "title": "What’s new in Polaris fAST Dynamic: AI-assisted authentication with expanded coverage and faster onboarding", "url": "https://www.blackduck.com/blog/polaris-fast-dynamic-ai-assisted-authentication.html", "published_at": "2025-09-29T00:00:00+00:00" }, { "id": "01a0df85-cfe0-7068-954a-0fb0dfc18adb", "title": "The next frontier in AppSec: Context-aware risk scoring", "url": "https://www.blackduck.com/blog/application-security-risk-scoring-ai-age.html", "published_at": "2025-09-19T00:00:00+00:00" }, { "id": "01a0df85-cfe0-7068-954a-0fb0e05e87a4", "title": "The Shai-Hulud npm malware attack: A wake-up call for supply chain security", "url": "https://www.blackduck.com/blog/npm-malware-attack-shai-hulud-threat.html", "published_at": "2025-09-18T00:00:00+00:00" }, { "id": "01a0df91-51a0-71d9-aa95-59db0f847835", "title": "From diligence to integration: How software audits inform post-close M&A strategies", "url": "https://www.blackduck.com/blog/software-audits-inform-post-close-ma-strategies.html", "published_at": "2025-09-17T00:00:00+00:00" }, { "id": "01a0df91-51a0-71d9-aa95-59db10171f45", "title": "Get the best from AI in software development without risking the worst", "url": "https://www.blackduck.com/blog/mitigating-ai-risks-in-software-development0.html", "published_at": "2025-09-15T00:00:00+00:00" }, { "id": "01a0df91-51a0-71d9-aa95-59db10632b47", "title": "The recent npm supply chain attack: Lessons in securing your software dependencies", "url": "https://www.blackduck.com/blog/recent-npm-software-supply-chain-attack-security-lessons.html", "published_at": "2025-09-11T00:00:00+00:00" }, { "id": "01a0df91-51a0-71d9-aa95-59db1067f49a", "title": "Contextualizing risk in the AI era", "url": "https://www.blackduck.com/blog/mitigating-ai-risks-in-software-development.html", "published_at": "2025-09-05T00:00:00+00:00" }, { "id": "01a0df91-51a0-71d9-aa95-59db10b75d00", "title": "Key findings from “The State of Embedded Software Quality and Safety 2025” report", "url": "https://www.blackduck.com/blog/embedded-software-quality-safety-challenges.html", "published_at": "2025-08-26T00:00:00+00:00" }, { "id": "01a0df91-51a0-71d9-aa95-59db11b4de49", "title": "Accelerate onboarding and testing of GitHub repos with the Black Duck Security app", "url": "https://www.blackduck.com/blog/black-duck-security-github-app.html", "published_at": "2025-08-19T00:00:00+00:00" }, { "id": "01a0df91-51a0-71d9-aa95-59db12539dcc", "title": "Addressing the hidden risks of AI coding tools", "url": "https://www.blackduck.com/blog/mitigating-ai-coding-risks.html", "published_at": "2025-08-18T00:00:00+00:00" }, { "id": "01a0df91-51a0-71d9-aa95-59db12f94e8b", "title": "Software due diligence: The home inspection of tech M&A", "url": "https://www.blackduck.com/blog/manage-risks-with-software-due-diligence.html", "published_at": "2025-08-12T00:00:00+00:00" }, { "id": "01a0df91-51a0-71d9-aa95-59db133442f4", "title": "Once and future code snippets: How AI reignites risk", "url": "https://www.blackduck.com/blog/generative-ai-tools-appsec-risk.html", "published_at": "2025-08-12T00:00:00+00:00" }, { "id": "01a0df91-51a0-71d9-aa95-59db14183129", "title": "What you need to know about the NIST Secure Software Development Framework", "url": "https://www.blackduck.com/blog/nist-ssdf-secure-software-development.html", "published_at": "2025-08-12T00:00:00+00:00" }, { "id": "01a0df98-ff99-719e-8511-2be456123580", "title": "Black Duck Assist: AI code security assistance in your IDE", "url": "https://www.blackduck.com/blog/black-duck-assist-ai-code-security.html", "published_at": "2025-08-05T00:00:00+00:00" }, { "id": "01a0df98-ff99-719e-8511-2be456de8883", "title": "The Importance of a Third-Party Due Diligence Perspective on Code Risk", "url": "https://www.blackduck.com/blog/third-party-due-diligence-code-risk-assessment.html", "published_at": "2025-08-04T00:00:00+00:00" }, { "id": "01a0df98-ff99-719e-8511-2be456ec4103", "title": "Faster, Smarter Vulnerability Alerts: AI in Black Duck Security Advisories", "url": "https://www.blackduck.com/blog/bdsa-ai-vulnerability-research.html", "published_at": "2025-07-31T00:00:00+00:00" }, { "id": "01a0df98-ff99-719e-8511-2be4578fed65", "title": "Unlocking the full potential of application security: Key findings from the Black Duck customer value study", "url": "https://www.blackduck.com/blog/userevidence-appsec-study-findings.html", "published_at": "2025-07-24T00:00:00+00:00" }, { "id": "01a0df98-ff99-719e-8511-2be4582b63da", "title": "Key takeaways from the “2024 Software Vulnerability Snapshot” report", "url": "https://www.blackduck.com/blog/software-vulnerability-snapshot-2024.html", "published_at": "2025-07-21T00:00:00+00:00" }, { "id": "01a0df98-ff99-719e-8511-2be459142dfa", "title": "Navigating the EU Cyber Resilience Act", "url": "https://www.blackduck.com/blog/eu-cyber-resilience-act-compliance.html", "published_at": "2025-07-17T00:00:00+00:00" }, { "id": "01a0df98-ff99-719e-8511-2be459b76ce8", "title": "The Black Duck Way: Strong culture drives leadership", "url": "https://www.blackduck.com/blog/the-black-duck-way-strong-culture-drives-leadership.html", "published_at": "2025-07-15T00:00:00+00:00" }, { "id": "01a0df98-ff99-719e-8511-2be459fc5332", "title": "Understanding Section 524B of the FD&C Act", "url": "https://www.blackduck.com/blog/understanding-fda-section-524b-medical-device-cybersecurity.html", "published_at": "2025-07-08T00:00:00+00:00" }, { "id": "01a0df98-ff99-719e-8511-2be45ae92465", "title": "Scaling application security across borders: Black Duck Polaris Platform empowers Saudi Arabian enterprises with in-region SaaS hosting", "url": "https://www.blackduck.com/blog/black-duck-polaris-application-security-saudi-arabia-gulf-cooperation-council-gcc.html", "published_at": "2025-07-06T00:00:00+00:00" }, { "id": "01a0df98-ff99-719e-8511-2be45b32df7c", "title": "Beyond detection: Understanding vulnerability reachability in SCA", "url": "https://www.blackduck.com/blog/vulnerability-reachability-in-sca.html", "published_at": "2025-06-30T00:00:00+00:00" }, { "id": "01a0dfa1-b34c-72d4-8a55-1cf50e6b4148", "title": "Remain code-compliant in a regulated, AI-powered world", "url": "https://www.blackduck.com/blog/ai-powered-code-compliance-strategies.html", "published_at": "2025-06-23T00:00:00+00:00" }, { "id": "01a0dfa1-b34c-72d4-8a55-1cf50ee53f05", "title": "Detecting compromised source code using Rapid Scan Static’s Malicious URLs feature", "url": "https://www.blackduck.com/blog/rapid-scan-static-malicious-urls-detect-compromised-code.html", "published_at": "2025-06-16T00:00:00+00:00" }, { "id": "01a0dfa1-b34c-72d4-8a55-1cf50f81e064", "title": "Black Duck named a 2025 Intellyx Digital Innovator Award winner", "url": "https://www.blackduck.com/blog/black-duck-named-2025-intellyx-digital-innovator-award-winner.html", "published_at": "2025-06-11T00:00:00+00:00" }, { "id": "01a0dfa1-b34c-72d4-8a55-1cf50f8f68e7", "title": "Transitive dependencies are exponentially increasing open source software risk", "url": "https://www.blackduck.com/blog/managing-transitive-dependencies-open-source-software.html", "published_at": "2025-06-09T00:00:00+00:00" }, { "id": "01a0dfa1-b34c-72d4-8a55-1cf51086eae7", "title": "Three steps to ensuring the reliability and security of your C++ projects", "url": "https://www.blackduck.com/blog/secure-cpp-software-reliability.html", "published_at": "2025-06-03T00:00:00+00:00" }, { "id": "01a0dfa1-b34c-72d4-8a55-1cf5114d8e0b", "title": "Q&A: What You Need to Know About Open Source Software Risk in 2025", "url": "https://www.blackduck.com/blog/qa-open-source-software-risk-2025.html", "published_at": "2025-05-22T00:00:00+00:00" }, { "id": "01a0dfa1-b34c-72d4-8a55-1cf511bbe7e7", "title": "How to build reliability into developer workflows without slowing down", "url": "https://www.blackduck.com/blog/build-reliability-into-developer-workflow.html", "published_at": "2025-05-19T00:00:00+00:00" }, { "id": "01a0dfa1-b34c-72d4-8a55-1cf512a43ad0", "title": "A decade of open source risk: Reflecting on 10 years of OSSRA report insights", "url": "https://www.blackduck.com/blog/10-years-of-ossra-report-insights.html", "published_at": "2025-05-16T00:00:00+00:00" }, { "id": "01a0dfa1-b34c-72d4-8a55-1cf513974692", "title": "How to secure AI-generated code with DevSecOps best practices", "url": "https://www.blackduck.com/blog/secure-ai-generated-code-with-devsecops.html", "published_at": "2025-05-08T00:00:00+00:00" }, { "id": "01a0dfa1-b34c-72d4-8a55-1cf514778290", "title": "AI avalanche: Taming software risk with True Scale Application Security", "url": "https://www.blackduck.com/blog/true-scale-application-security.html", "published_at": "2025-04-28T00:00:00+00:00" } ] posts Claim your blog
Back to blackduck.com
Blog · corpus.blog/blogs/blackduck.com/posts

blackduck.com

blackduck.com

2026

2025