• Live Feeds
    • Press Releases
    • Insider Trading
    • FDA Approvals
    • Analyst Ratings
    • Insider Trading
    • SEC filings
    • Market insights
  • Analyst Ratings
  • Alerts
  • Subscriptions
  • Settings
  • RSS Feeds
Quantisnow Logo
  • Live Feeds
    • Press Releases
    • Insider Trading
    • FDA Approvals
    • Analyst Ratings
    • Insider Trading
    • SEC filings
    • Market insights
  • Analyst Ratings
  • Alerts
  • Subscriptions
  • Settings
  • RSS Feeds
PublishDashboard
    Quantisnow Logo

    © 2025 quantisnow.com
    Democratizing insights since 2022

    Services
    Live news feedsRSS FeedsAlertsPublish with Us
    Company
    AboutQuantisnow PlusContactJobsAI employees
    Legal
    Terms of usePrivacy policyCookie policy

    JFrog Enables Trusted AI - Uncovers Critical Security Threats Emerging from AI's Expansion in the Software Supply Chain

    4/1/25 5:00:00 AM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology
    Get the next $FROG alert in real time by email

    The Software Supply Chain State of the Union 2025 Report Reveals "Quad-fecta" of Security Exploits, Mis-scored CVEs, Poor ML Model Governance, & more are Jeopardizing Trust in Newly Created Software

    (KubeCon + CloudNativeCon Europe) — JFrog Ltd (NASDAQ:FROG), the Liquid Software company and creators of the JFrog Software Supply Chain Platform, today released the Software Supply Chain State of the Union 2025 report, which highlights emerging software security threats, evolving DevOps risks and best practices, and potentially explosive security concerns in the AI era.

    This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250401200753/en/

    "Many organizations are enthusiastically embracing public ML models to drive rapid innovation, demonstrating a strong commitment to leveraging AI for growth. However, over a third still rely on manual efforts to manage access to secure, approved models, which can lead to potential oversights," said Yoav Landman, CTO and Co-Founder, JFrog. "AI adoption will only grow more rapidly. Thus, in order for organizations to thrive in today's AI era they should automate their toolchains and governance processes with AI-ready solutions, ensuring they remain both secure and agile while maximizing their innovative potential."

    Managing and securing the software supply chain end-to-end is an imperative for delivering trusted software releases. By combining insights from over 1,400 development, security and operations professionals across the U.S., U.K., France, Germany, India and Israel, with developer usage data from JFrog's 7K+ customers, alongside original CVE analysis by the JFrog Security Research team, the JFrog Software Supply Chain State of the Union 2025 report reveals why this task is often challenging for companies amidst the expanding and frenzied threat landscape faced in today's AI era.

    Key Report Findings Include:

    • A "Quad-fecta" of Security Vulnerabilities are Threatening the Software Supply Chain: The top security factors impacting the integrity and safety of the software supply chain include: CVEs, malicious packages, secrets' exposures, and misconfigurations/human errors. As an example, the JFrog Security Research Team detected 25,229 exposed secrets/tokens in public registries (up 64% YoY). The increasing complexity of software security threats are making it harder to maintain consistent software supply chain security.
    • AI/ML Model Proliferation and Attacks are Growing: In 2024, more than 1 million new ML models were added to Hugging Face, with an accompanying 6.5x increase in malicious models, indicating AI and ML models are increasingly becoming a preferred attack vector for bad actors.
    • Manual Governance of ML Models is Increasing Risk: Most companies (94%) are using certified lists to govern ML artifact usage, however over one-third (37%) of those rely on manual efforts to curate and maintain their lists of approved ML models. This overreliance on manual validation creates uncertainty around the accuracy and consistency of ML model security.
    • Limited Security Scanning Leaving Blind Spots: Alarmingly, only 43% of IT professionals say their organization applies security scans at both the code and binary levels, leaving many organizations vulnerable to security threats only detectable at the binary level. This is down from 56% last year - a sign that teams still have huge blind spots when it comes to identifying and preventing software risk as early as possible.
    • Critical Vulnerabilities Continue to Rise and be Mis-scored: In 2024, security researchers disclosed over 33K new CVEs, a 27% increase from 2023, surpassing the 24.5% growth rate of new software packages. This trend raises concerns as the growing number of CVEs increases complexity and pressure on developers and security teams, potentially hindering innovation. Meanwhile, JFrog Security found that only 12% of high-profile CVEs rated "critical" (CVSS 9.0-10.0) by government organizations justify the critical severity level they were assigned because they are likely to be exploited by attackers.1 This pattern is troubling due to a centralized and unchanged scoring methodology over time, which heightens the risk of false positives in assessments and contributes to developers experiencing "vulnerability fatigue."

    "We uncovered a clear pattern by CVE scoring organizations to inflate scores and cause an unnecessary level of panic in the industry, sending developers scrambling on remediation efforts that often results in wasted cognitive and professional time," said Shachar Menashe, Vice President of Security Research. "When DevSecOps teams are forced to remediate vulnerabilities that aren't ultimately harmful, their everyday workflows are disrupted, which can lead to developer burnout and costly mistakes."

    The JFrog Software Supply Chain State of the Union 2025 report also outlines concerns around lack of code provenance visibility across the software supply chain, developers downloading open source software packages directly from public registries without filtering for vulnerabilities, the detriments of "security tool sprawl", and more. To explore the full findings of this year's report visit https://jfrog.com/software-supply-chain-state-of-union/ or read this blog.

    You can also register to join JFrog security and developer experts on Thursday, April 24, 2025 at 9 AM PT for a webinar, "JFrog's Software Supply Chain Report 2025: Trends, Threats & Actions," detailing the challenges and complexities of managing and securing the software supply chain.

    Like this Story? Share this on X (a.k.a. Twitter): @JFrog shares research findings in their Software Supply Chain State of the Union 2025 report. Discover the emerging #DevSecOps trends, risks & best practices to securing enterprise #SoftwareSupplyChain. Learn more: https://jfrog.co/43vkg3Y #SoftwareSupplyChain #DevOps #DevSecOps #cybersecurity #containers #CVE

    About JFrog

    JFrog Ltd. (NASDAQ:FROG) is on a mission to power the world with liquid software. We are replacing endless software updates with a single system of record that seamlessly delivers secure applications from developer to device. The JFrog Software Supply Chain Platform helps organizations build, manage, and distribute software quickly and securely, making applications available, traceable, and tamper-proof. Its integrated security features also help identify, protect, and remediate against threats and vulnerabilities. The Platform also brings ML models in line with all other software development processes, providing a single source of truth for all software components across Engineering, MLOps, DevOps, and DevSecOps teams so they can build and release AI applications faster, with minimal risk and less cost. JFrog's hybrid, universal, multi-cloud platform is available as both self-hosted and SaaS services across major cloud service providers. Millions of users and 7K+ customers worldwide, including a majority of the Fortune 100, depend on JFrog solutions to securely embrace digital transformation. Once you leap forward, you won't go back! Learn more at jfrog.com and follow us on X: @jfrog.

    ____________________

    1 The JFrog Severity Rating methodology considers the likelihood of vulnerability exploitability, unlike CVSS ratings, which focus only on exploitation severity, often overestimating risks.

    View source version on businesswire.com: https://www.businesswire.com/news/home/20250401200753/en/

    Media Contact:

    Siobhan Lyons, Sr. Manager, Global Communications, [email protected]

    Investor Contact:

    Jeff Schreiner, VP of Investor Relations, [email protected]

    Get the next $FROG alert in real time by email

    Chat with this insight

    Save time and jump to the most important pieces.

    Recent Analyst Ratings for
    $FROG

    DatePrice TargetRatingAnalyst
    4/11/2025$40.00Outperform
    Raymond James
    9/5/2024$30.00 → $33.00Buy
    Needham
    8/27/2024$32.00Outperform
    Robert W. Baird
    8/8/2024Outperform → Perform
    Oppenheimer
    7/24/2024$50.00Buy
    TD Cowen
    6/26/2024$50.00Overweight
    Barclays
    5/22/2024$45.00Outperform
    FBN Securities
    5/22/2024$41.00Buy
    UBS
    More analyst ratings

    $FROG
    SEC Filings

    See more
    • JFrog Ltd. filed SEC Form 8-K: Submission of Matters to a Vote of Security Holders

      8-K - JFrog Ltd (0001800667) (Filer)

      5/22/25 4:14:16 PM ET
      $FROG
      Computer Software: Prepackaged Software
      Technology
    • SEC Form 144 filed by JFrog Ltd.

      144 - JFrog Ltd (0001800667) (Subject)

      5/13/25 4:20:12 PM ET
      $FROG
      Computer Software: Prepackaged Software
      Technology
    • SEC Form 10-Q filed by JFrog Ltd.

      10-Q - JFrog Ltd (0001800667) (Filer)

      5/9/25 4:11:50 PM ET
      $FROG
      Computer Software: Prepackaged Software
      Technology

    $FROG
    Press Releases

    Fastest customizable press release news feed in the world

    See more
    • JFrog Appoints Sunny Rao as Senior Vice President of Asia Pacific to Drive Next Phase of Growth and Innovation Across the Region

      JFrog Ltd. ("JFrog") (NASDAQ:FROG), the Liquid Software company and creators of the award-winning JFrog Software Supply Chain Platform, today announced Sunny Rao has joined the company as Senior Vice President (SVP) of Asia Pacific (APAC) sales. Reporting directly to JFrog's Chief Revenue Officer (CRO), Tali Notman, Rao will spearhead the company's growth initiatives across APAC, helping customers achieve their business transformation goals utilizing the JFrog Platform. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250529286347/en/JFrog Appoints Sunny Rao as Senior Vice President of Asia Pacific to Drive Next Phase of Growth an

      5/29/25 9:15:00 AM ET
      $FROG
      Computer Software: Prepackaged Software
      Technology
    • JFrog Partners with NVIDIA to Accelerate Agentic AI, Integrating the JFrog Platform with NVIDIA Enterprise AI Factory

      New Full-Stack, Validated Design Aims to Accelerate AI/ML Model Engineering, Security, Operations and Delivery for the AI-powered Enterprise COMPUTEX 2025 – JFrog Ltd (NASDAQ:FROG), the Liquid Software company and creators of the award-winning JFrog Software Supply Chain Platform, today announced the integration of its foundational DevSecOps tools with the NVIDIA Enterprise AI Factory validated design. JFrog will serve as the cornerstone software artifact repository and secure model registry for the landmark agentic AI architecture. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250518384005/en/The JFrog Platform will serve as t

      5/19/25 2:00:00 AM ET
      $FROG
      Computer Software: Prepackaged Software
      Technology
    • JFrog Announces First Quarter 2025 Results

      Total Revenues of $122.4 million; up 22% Year-over-Year Cloud Revenues of $52.6 million; up 42% Year-over-Year Customers with ARR greater than $1 million equaled 54, up 35% Year-over-Year Released JFrog ML, delivering a unified DevOps, DevSecOps and MLOps Platform JFrog Ltd. ("JFrog") (NASDAQ:FROG), the Liquid Software company and creators of the JFrog Software Supply Chain Platform, today announced financial results for its first quarter ended March 31, 2025. "The JFrog Platform has become the software system of record for organizations, transforming how software is created and delivered by unifying DevOps, DevSecOps, and AI/MLOps in one platform," said Shlomi Ben Haim, CEO and C

      5/8/25 4:05:00 PM ET
      $FROG
      Computer Software: Prepackaged Software
      Technology

    $FROG
    Analyst Ratings

    Analyst ratings in real time. Analyst ratings have a very high impact on the underlying stock. See them live in this feed.

    See more
    • Raymond James initiated coverage on JFrog with a new price target

      Raymond James initiated coverage of JFrog with a rating of Outperform and set a new price target of $40.00

      4/11/25 9:07:40 AM ET
      $FROG
      Computer Software: Prepackaged Software
      Technology
    • Needham reiterated coverage on JFrog with a new price target

      Needham reiterated coverage of JFrog with a rating of Buy and set a new price target of $33.00 from $30.00 previously

      9/5/24 10:49:05 AM ET
      $FROG
      Computer Software: Prepackaged Software
      Technology
    • Robert W. Baird initiated coverage on JFrog with a new price target

      Robert W. Baird initiated coverage of JFrog with a rating of Outperform and set a new price target of $32.00

      8/27/24 7:29:31 AM ET
      $FROG
      Computer Software: Prepackaged Software
      Technology

    $FROG
    Insider Trading

    Insider transactions reveal critical sentiment about the company from key stakeholders. See them live in this feed.

    See more
    • Director Simon Frederic sold $1,489,791 worth of Ordinary Shares (35,000 units at $42.57), decreasing direct ownership by 0.81% to 4,274,903 units (SEC Form 4)

      4 - JFrog Ltd (0001800667) (Issuer)

      6/12/25 4:30:21 PM ET
      $FROG
      Computer Software: Prepackaged Software
      Technology
    • CHIEF REVENUE OFFICER Notman Tali sold $999,456 worth of Ordinary Shares (23,157 units at $43.16), decreasing direct ownership by 3% to 686,360 units (SEC Form 4)

      4 - JFrog Ltd (0001800667) (Issuer)

      6/10/25 4:30:05 PM ET
      $FROG
      Computer Software: Prepackaged Software
      Technology
    • CHIEF TECHNOLOGY OFFICER Landman Yoav sold $2,162,926 worth of Ordinary Shares (50,000 units at $43.26), decreasing direct ownership by 0.78% to 6,371,086 units (SEC Form 4)

      4 - JFrog Ltd (0001800667) (Issuer)

      6/9/25 4:31:13 PM ET
      $FROG
      Computer Software: Prepackaged Software
      Technology