Blog

From the Kusari team.

Research, product launches, and field notes on software supply-chain security from the Kusari team.

What CrowdStrike, Travelex and Synapse tell us about blast radius in financial services.

What CrowdStrike, Travelex and Synapse tell us about blast radius in financial services.

CrowdStrike cost banking $1.149bn with no attacker involved. What Travelex and Synapse add, and why DORA now requires concentration risk assessment.

DORA, PCI DSS and NYDFS all now require a software inventory. Most banks cannot produce one.

DORA, PCI DSS and NYDFS all now require a software inventory. Most banks cannot produce one.

DORA Article 28, PCI DSS 6.3.2 and NYDFS 500.13 all require a software inventory. Here is what each asks for, and why scanner-built inventories fall short.

Introducing Waybill: the most comprehensive SBOM generation tool

Introducing Waybill: the most comprehensive SBOM generation tool

Existing SBOM generators have gaps in ecosystem coverage, transitive dependency analysis, and data quality. Waybill gives you the depth and accuracy modern software supply chains actually need.

For the first time in 19 years, vulnerabilities are the DBIR's top attack vector

For the first time in 19 years, vulnerabilities are the DBIR's top attack vector

Stolen credentials used to be an attacker's main path into your systems. Now it's exploiting a vulnerability in your software.

Kusari Score now includes active vulnerability exploits

Kusari Score now includes active vulnerability exploits

Kusari Score prioritizes vulnerabilities based on your specific software environment. Now with active exploit intelligence built in.

A yellow sign that says 'caution: avalanche danger' in front of snow-covered mountains.

Surviving the vulnpocalypse with Kusari

The coming avalanche of AI-assisted vulnerability discovery can overwhelm teams, but not if they’re prepared.

A screen shot of the vulnerability table in Kusari Console showing vulnerabilities that don't affect the software

Kusari Platform now tells you which vulnerabilities can actually be exploited — and writes the VEX

Most CVEs can't actually be reached by your code. Kusari's new AI Analysis Agent reads your codebase and traces each vulnerability so you can fix what matters and prove what doesn't.

kusari-cli gives you Kusari’s power wherever you go

kusari-cli gives you Kusari’s power wherever you go

The kusari-cli 1.0 release means you can connect to Kusari Inspector and Kusari Platform no matter what platform you use.

From Provenance to Enforcement:  SLSA, in-toto, and Kubernetes Admission Control

From Provenance to Enforcement: SLSA, in-toto, and Kubernetes Admission Control

If provenance is not evaluated, it is merely metadata. Enforcement is what transforms integrity into control.

Identity, Signing, and Transparency: The Foundation of Verifiable Builds

Identity, Signing, and Transparency: The Foundation of Verifiable Builds

Signing artifacts is not new. Making that signing keyless, auditable, and transparently verifiable is.

Software Is a Supply Chain — Start Treating It Like One

Software Is a Supply Chain — Start Treating It Like One

Modern software delivery now resembles global manufacturing. If we demand traceability for physical components, we must demand the same for code.

A statue of a three-headed monster

Facts and Mythos: understanding the future of AI security analysis

Mythos undoubtedly represents an advancement in the capability of frontier models. It’s also not the apocalypse.

Why 72% of Organizations Can't See Their Real Attack Surface: Solving the Transitive Dependency Visibility Gap

Why 72% of Organizations Can't See Their Real Attack Surface: Solving the Transitive Dependency Visibility Gap

Most security leaders think they have a handle on their attack surface, using SCA, SBOMs, tracking libraries. But there's a problem with that confidence.

How Kusari Protects Against Recent Supply Chain Attacks

How Kusari Protects Against Recent Supply Chain Attacks

Recent attacks against projects like Trivy, LiteLLM, and Axios show the need for automated supply chain checks.

Vibe Coding & Vulnerabilities: A Security Team's Guide to AI-Generated Code Risks

Vibe Coding & Vulnerabilities: A Security Team's Guide to AI-Generated Code Risks

Kusari Partners with OpenSSF to Strengthen Open Source Software Supply Chain Security

Kusari Partners with OpenSSF to Strengthen Open Source Software Supply Chain Security

Open source software powers the modern world; securing it remains a shared responsibility.

Kusari and CNCF: Advancing Software Supply Chain Security for Cloud Native Projects

Kusari and CNCF: Advancing Software Supply Chain Security for Cloud Native Projects

AI Coding Assistants in 2026: 4× Faster, 10× Riskier and The Hidden Security Cost

AI Coding Assistants in 2026: 4× Faster, 10× Riskier and The Hidden Security Cost

AI coding assistants (LLMs) dramatically increase developer velocity, but introduce critical new AppSec risks. AI-generated code is consistently less secure.

The 95% Problem: Why Transitive Dependencies Are Your Biggest Software Supply Chain Blind Spot in 2026

The 95% Problem: Why Transitive Dependencies Are Your Biggest Software Supply Chain Blind Spot in 2026

Your security team just finished a vulnerability scan. The dashboard looks clean, but there's a catch: that scan only covered about 5% of your actual risk surface.

Why the EU Cyber Resilience Act Will Catch US Software Companies Off Guard

Why the EU Cyber Resilience Act Will Catch US Software Companies Off Guard

Most US software regulations are built around intent. The EU Cyber Resilience Act (CRA) is built around outcomes. That difference is why 2026 will feel like a shock for many US companies selling softw

The Hidden Cost of Reactive AppSec

The Hidden Cost of Reactive AppSec

Security leaders often talk about risk reduction. Developers talk about velocity. The tension between the two has defined AppSec for over a decade.

Compliance Is Getting Real

Compliance Is Getting Real

Why software integrity is becoming the defining security challenge of the next decade

2026 Predictions: Open Source Accountability, AI Security, and Standardization Will Define the Next Era of Software

2026 Predictions: Open Source Accountability, AI Security, and Standardization Will Define the Next Era of Software

For years, software security has lived in the realm of best practices. In 2026, software security stops being theoretical and moves firmly into the realm of requirements.

Integrating GitLab and Kusari

Integrating GitLab and Kusari

Use Kusari’s tools directly in GitLab workflows to improve your supply chain security.