Blog

From the Kusari team.

Research, product launches, and field notes on software supply-chain security from the Kusari team.

OpenSSF Tech Talk Recap: Using the OSPS Baseline to Navigate Standards and Regulations

OpenSSF Tech Talk Recap: Using the OSPS Baseline to Navigate Standards and Regulations

Open source projects are in the spotlight as regulated industries, governments and those that sell to them ramp cybersecurity expectations. Enter Open Source Project Security (OSPS) Baseline!

Endpoint Security is Supply Chain Security

Endpoint Security is Supply Chain Security

Endpoint security is a key part of many IT security efforts, but it’s not always thought about in the specific context of software supply chain security.

Identifying Threats in the Implementation Phase

Identifying Threats in the Implementation Phase

Many threats present themselves while implementing software. Here's how to find and address them.

The Future of CVEs

The Future of CVEs

Recent funding concerns have highlighted the need for a more resilient system of vulnerability identification.

VulnCon 2025 Recap

VulnCon 2025 Recap

Kusari CTO Mike Lieberman shares his thoughts after attending the second-annual VulnCon conference.

The Hidden Risk in Your Software: Managing Transitive Dependencies

The Hidden Risk in Your Software: Managing Transitive Dependencies

Beyond knowing why transitive dependencies are important, you have to know how to manage them.

Codifying the SDLC with in-toto

Codifying the SDLC with in-toto

in-toto helps ensure product integrity by making transparent what steps were performed, by whom, and in what order.

The Hidden Risk in Your Software: Understanding Transitive Dependencies

The Hidden Risk in Your Software: Understanding Transitive Dependencies

Transitive dependencies are the invisible majority of your applications. Failure to properly understand them increases your risk.

Providing Secure Updates with TUF

Providing Secure Updates with TUF

A secure and resilient method for distributing software updates is a key part of keeping your supply chain trustworthy.

Securing the Software Supply Chain book now available!

Securing the Software Supply Chain book now available!

This new book from Michael Liberman and Brandon Lum guides you from the basics of supply chain security through to being a security expert.

GUAC Now Supports Runtime Kubernetes SBOMs using Kubescape

GUAC Now Supports Runtime Kubernetes SBOMs using Kubescape

GUAC v0.14.0 includes a Kubescape collector that can be run inside your Kubernetes cluster to watch for new scan results from Kubescape and ingest those results into GUAC

Securing Your AI Models

Securing Your AI Models

The abilities of generative and agentic AI models require a proactive approach to protecting the AI supply chain.

The Last Step on the Security Journey: Kusari Platform

The Last Step on the Security Journey: Kusari Platform

When you need a solution for managing your software supply chain, the Kusari Platform provides enterprise-ready features backed by security expertise.

Another Step on the Security Journey: A Constellation of SBOMs

Another Step on the Security Journey: A Constellation of SBOMs

Comparing two SBOMs is useful, but as your portfolio grows, you need to take a holistic approach.

The Next Step in the Security Journey: Comparing SBOMs

The Next Step in the Security Journey: Comparing SBOMs

Once you have multiple releases, you have multiple SBOMs. What can you learn from comparing them?

Starting the Security Journey: Producing an SBOM

Starting the Security Journey: Producing an SBOM

A hypothetical organization takes the first step on their software supply chain security journey by creating an SBOM for their application.

Unpacking Kusari Platform Views

Unpacking Kusari Platform Views

Kusari Platform gives you the information you need to secure your software supply chain.

Raising the Bar for Open Source Security: Introducing the OSPS Baseline

Raising the Bar for Open Source Security: Introducing the OSPS Baseline

Kusari is proud to contribute to the Open Source Project Security Baseline, an OpenSSF project to help open source maintainers improve their security posture.

Addressing Third-Party Risk in Open Source Software

Addressing Third-Party Risk in Open Source Software

Once you've discovered the third-party risks in the open source projects you consume, how do you address those risks without having a vendor relationship with the projects?

Analyzing Third-Party Risk in Open Source Software

Analyzing Third-Party Risk in Open Source Software

Third-party risk management is an important part of protecting your organization. But how do you manage the risks of open source software when you have no vendor relationship?

Building a Foundation of Trust for a Stronger Software Supply Chain

Building a Foundation of Trust for a Stronger Software Supply Chain

Creating a secure foundation of trust enables organizations to safely delegate specific actions in the software development life cycle.

Unpacking the Kusari “Effort to Fix” Capability

Unpacking the Kusari “Effort to Fix” Capability

Get a clear understanding of the work involved in remediating a vulnerability so you can schedule it in your sprint without blocking feature work.

Unpacking the Kusari Score

Unpacking the Kusari Score

Cut through the noise to prioritize which vulnerability gets fixed next

Alarms Raised by Critical Reverse Backdoor Vulnerability in Medical Devices

Alarms Raised by Critical Reverse Backdoor Vulnerability in Medical Devices

Medical monitors have critical security flaws, allowing unauthorized code execution and patient data leaks.