Research, product launches, and field notes on software supply-chain security from the Kusari team.
CrowdStrike cost banking $1.149bn with no attacker involved. What Travelex and Synapse add, and why DORA now requires concentration risk assessment.
DORA Article 28, PCI DSS 6.3.2 and NYDFS 500.13 all require a software inventory. Here is what each asks for, and why scanner-built inventories fall short.
Existing SBOM generators have gaps in ecosystem coverage, transitive dependency analysis, and data quality. Waybill gives you the depth and accuracy modern software supply chains actually need.
Stolen credentials used to be an attacker's main path into your systems. Now it's exploiting a vulnerability in your software.
Kusari Score prioritizes vulnerabilities based on your specific software environment. Now with active exploit intelligence built in.
The coming avalanche of AI-assisted vulnerability discovery can overwhelm teams, but not if they’re prepared.
Most CVEs can't actually be reached by your code. Kusari's new AI Analysis Agent reads your codebase and traces each vulnerability so you can fix what matters and prove what doesn't.
The kusari-cli 1.0 release means you can connect to Kusari Inspector and Kusari Platform no matter what platform you use.
If provenance is not evaluated, it is merely metadata. Enforcement is what transforms integrity into control.
Signing artifacts is not new. Making that signing keyless, auditable, and transparently verifiable is.
Modern software delivery now resembles global manufacturing. If we demand traceability for physical components, we must demand the same for code.
Mythos undoubtedly represents an advancement in the capability of frontier models. It’s also not the apocalypse.
Most security leaders think they have a handle on their attack surface, using SCA, SBOMs, tracking libraries. But there's a problem with that confidence.
Recent attacks against projects like Trivy, LiteLLM, and Axios show the need for automated supply chain checks.
Open source software powers the modern world; securing it remains a shared responsibility.
AI coding assistants (LLMs) dramatically increase developer velocity, but introduce critical new AppSec risks. AI-generated code is consistently less secure.
Your security team just finished a vulnerability scan. The dashboard looks clean, but there's a catch: that scan only covered about 5% of your actual risk surface.
Most US software regulations are built around intent. The EU Cyber Resilience Act (CRA) is built around outcomes. That difference is why 2026 will feel like a shock for many US companies selling softw
Security leaders often talk about risk reduction. Developers talk about velocity. The tension between the two has defined AppSec for over a decade.
Why software integrity is becoming the defining security challenge of the next decade
For years, software security has lived in the realm of best practices. In 2026, software security stops being theoretical and moves firmly into the realm of requirements.
Use Kusari’s tools directly in GitLab workflows to improve your supply chain security.