• Live Feeds
    • Press Releases
    • Insider Trading
    • FDA Approvals
    • Analyst Ratings
    • Insider Trading
    • SEC filings
    • Market insights
  • Analyst Ratings
  • Alerts
  • Subscriptions
  • Settings
  • RSS Feeds
Quantisnow Logo
  • Live Feeds
    • Press Releases
    • Insider Trading
    • FDA Approvals
    • Analyst Ratings
    • Insider Trading
    • SEC filings
    • Market insights
  • Analyst Ratings
  • Alerts
  • Subscriptions
  • Settings
  • RSS Feeds
PublishGo to App
    Quantisnow Logo

    © 2026 quantisnow.com
    Democratizing insights since 2022

    Services
    Live news feedsRSS FeedsAlertsPublish with Us
    Company
    AboutQuantisnow PlusContactJobsAI superconnector for talent & startupsNEWLLM Arena
    Legal
    Terms of usePrivacy policyCookie policy

    New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs

    5/20/26 4:05:00 PM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology
    Get the next $FROG alert in real time by email

    The Hidden Costs of AI at Scale: JFrog's 2026 Software Supply Chain Security report shows threat actors weaponizing developer workflows, driving 177K new malicious packages, 495 malicious AI models, and a 451% increase in infected npm packages

    JFrog Ltd. (NASDAQ:FROG), the Liquid Software company and creators of the JFrog Software Supply Chain Platform, the system of record for trusted software artifacts, binaries, and AI assets today announced the findings of its 2026 Software Supply Chain Security State of the Union report. This year's report reveals an unprecedented acceleration in enterprise software risk as threat actors expand strikes beyond traditional package registries into AI model registries and developer tooling, creating a blind spot in current software governance frameworks.

    This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260520126325/en/

    The AI governance gap is real - and it's coming at a high cost to enterprise organizations. The JFrog 2026 Software Supply Chain Security report shows a 451% surge in malicious npm packages, AI agent skills are a new attack surface; and 97% of orgs claim AI governance while 53% still pull models from public registries where malicious payloads have been found. Read the report to learn earn how to move from reactive patching to a governance-first framework that actually keeps pace with Al speed.

    The AI governance gap is real - and it's coming at a high cost to enterprise organizations. The JFrog 2026 Software Supply Chain Security report shows a 451% surge in malicious npm packages, AI agent skills are a new attack surface; and 97% of orgs claim AI governance while 53% still pull models from public registries where malicious payloads have been found. Read the report to learn earn how to move from reactive patching to a governance-first framework that actually keeps pace with Al speed.

    "Every enterprise is adding AI to their software supply chain, which is increasing the attack surface for bad actors. Our report shows attackers are no longer just breaching traditional defenses – they are actively weaponizing the trusted models, registries, and agentic tools driving today's AI-powered development. The era of 'scan and hope' is over," said Shlomi Ben Haim, CEO & Co-Founder, JFrog. "Organizations need a single source of truth that governs every binary, every model, and every AI agent skill from the moment it enters the pipeline to the moment it is deployed in production. This is what JFrog was built to deliver."

    As AI moves from experimentation to a structural force reshaping the software supply chain, organizations are seeing a widening gap between reported security confidence and the risks accumulating in their infrastructure. Drawing on data from 18.2 billion artifacts managed across the JFrog Platform (up 136% year‑over‑year), original vulnerability research by the JFrog Security Research team, and a global survey of 1,508 security and DevOps professionals 1, this report exposes what it calls the "illusion of mastery", i.e. the growing disparity between perceived security and the reality of mounting supply chain risk.

    Key Findings Include:

    • Malicious Packages Hit an All-Time High: Malicious npm packages surged 451% year-over-year, with 177K new malicious packages detected across registries in the last year. Attackers are exploiting trust at scale – the "Qix" campaign used just 25 packages to compromise over 2.5 million downloads.
    • AI Agent Skills Emerge as a New Attack Surface: For the first time, JFrog tracked malicious AI agent skills – identifying 969 carrying high-impact payloads alongside 495 malicious AI models on Hugging Face and 56 malicious extensions on OpenVSX. Attackers are no longer just targeting code; they are targeting the autonomous tools that write, review, and deploy it.
    • Cutting through the Noise: Vulnerabilities Are Surging and Severity Scores Are Misleading: Over 48,000 new CVEs were disclosed in 2025, a 20% year-over-year increase partially driven by AI-generated code reintroducing decades-old weaknesses, like Injection (CWE-74), which grew 3,110%. Yet the JFrog Security Research team found that 66% of CVEs analyzed had minimal real-world applicability: volume-based triage is noise, while context and applicability become the mission-critical signals.
    • The Fastest-Growing Threats Are the Least Defended: Only 40% of organizations have adopted malicious package detection and secrets detection is active at just 28%. The categories growing fastest in threat volume remain the least covered by existing tooling.
    • Security Teams Bear the Human Cost of AI: 45% of respondents say reviewing and hardening AI-generated code is now a major time drain – proving that AI hasn't eliminated work – it's merely shifted the burden as threat actors weaponize upstream developer environments and agentic tools.
    • The AI Governance Gap: 97% of organizations claim they have certified model governance – yet 53% self-host models from sources where malicious payloads have been detected, and 18% have zero governance over their integrated development environments (IDE) or Model Context Protocol (MCP) servers sitting inside their developers' workflows. Thus, the gap between reported executive confidence and actual control is widening as AI development accelerates.

    "The industry is operating with a false sense of security. Vulnerabilities are growing in number, but the real threat lies in threat actors hijacking our CI/CD pipelines and developer tools before code even exists," said Shachar Menashe, VP of JFrog Security Research. "Moving to automated, platform-native governance is no longer optional – it is the only way to secure the intelligent systems creating, approving, and distributing today's software."

    "AI has not only changed how software is written; it has also increased the speed and scale at which zero-day vulnerabilities are exploited, and malicious software supply chain attacks are developed and distributed," said Yoav Landman, CTO and Co-Founder of JFrog. "To stay ahead, organizations need automated governance that curates every software asset entering the organization, whether introduced by agents or developers, and continuously monitors every release that contains those assets. The race is no longer about who discovers a zero-day first, because that information is advertised within minutes. It is about who can fortify their software supply chain at scale to keep their organization secure."

    To explore the full findings of this year's report and learn how your organization can close the AI governance gap, download the JFrog 2026 Software Supply Chain Security State of the Union. You can also check out our blog or register to join JFrog Security and developer experts for an upcoming webinar – "The Illusion of Mastery: Bridging the Al Governance Gap in 2026" – detailing the challenges, threats, and necessary actions for securing your software supply chain in the AI era.

    Like this Story? Share this on X (a.k.a. Twitter): Malicious #npm packages surged 451%; AI agent skills are now an attack surface; and 97% of orgs claim AI governance while 53% still pull models from public registries where malicious payloads have been found. The AI governance gap is real. Read the @JFrog 2026 Software Supply Chain Security report: https://bit.ly/3PRNzJB.

    #DevSecOps #SoftwareSupplyChain #Cybersecurity #AI #governance #DevGovOps

    About JFrog

    JFrog Ltd. (NASDAQ:FROG), the creators of the unified DevOps, DevSecOps, DevGovOps, and MLOps platform, is on a mission to create a world of trusted software delivery without friction from development to production. Driven by a "Liquid Software" vision, the JFrog Platform is a software supply chain system of record that is designed to power organizations as they build, manage, govern, and distribute secure software with speed and scale. Holistic security features help identify, protect, and remediate against threats and vulnerabilities. The universal, hybrid, multi-cloud JFrog Platform is available as both SaaS services across major cloud service providers and self-hosted. Millions of users and approximately 6,600 organizations worldwide, including a majority of the Fortune 100, depend on JFrog solutions to securely embrace digital transformation in the AI era. Learn more at https://jfrog.com or follow us on X @JFrog.

    _______________________________________________________________________________________

    1 JFrog commissioned 4Media Group's Atomik Research to conduct an international online survey of 1,508 IT professionals across selected industries in the United States (n=508), United Kingdom (n=125), India (n=167), Germany (n=120), France (n=125), Australia (n=165), Singapore (n=174), and Spain (n=124) between Jan-Feb. 2026. Respondents were full-time employees in IT, information systems, or technology departments holding specified job functions. All worked for organizations with 1,000+ employees and confirmed a software development team of at least 50 members. The margin of error for the overall sample is ±3 percentage points at a 95% confidence level.

     

    View source version on businesswire.com: https://www.businesswire.com/news/home/20260520126325/en/

    Media Contact:

    Siobhan Lyons, Director, Global Communications, siobhanL@jfrog.com

    Investor Contact:

    Jeff Schreiner, VP of Investor Relations, jeffS@jfrog.com

    Get the next $FROG alert in real time by email

    Crush Q1 2026 with the Best AI Superconnector

    Stay ahead of the competition with Standout.work - your AI-powered talent-to-startup matching platform.

    AI-Powered Inbox
    Context-aware email replies
    Strategic Decision Support
    Get Started with Standout.work

    Recent Analyst Ratings for
    $FROG

    DatePrice TargetRatingAnalyst
    3/24/2026$60.00Neutral → Buy
    UBS
    3/16/2026$60.00Buy
    Guggenheim
    12/17/2025$83.00Buy
    BTIG Research
    11/24/2025$65.00Buy → Neutral
    UBS
    11/7/2025$75.00Perform → Outperform
    Oppenheimer
    4/11/2025$40.00Outperform
    Raymond James
    9/5/2024$30.00 → $33.00Buy
    Needham
    8/27/2024$32.00Outperform
    Robert W. Baird
    More analyst ratings

    $FROG
    Insider Trading

    Insider transactions reveal critical sentiment about the company from key stakeholders. See them live in this feed.

    View All

    CHIEF FINANCIAL OFFICER Grabscheid Eduard sold $1,299,573 worth of Ordinary Shares (15,138 units at $85.85) as part of a pre-agreed trading plan, decreasing direct ownership by 7% to 209,658 units (SEC Form 4) (withholding obligation)

    4 - JFrog Ltd (0001800667) (Issuer)

    6/4/26 4:15:15 PM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology

    CHIEF EXECUTIVE OFFICER Shlomi Ben Haim sold $3,726,066 worth of Ordinary Shares (43,056 units at $86.54), decreasing direct ownership by 0.90% to 4,751,308 units (SEC Form 4) (for withholding tax)

    4 - JFrog Ltd (0001800667) (Issuer)

    6/4/26 4:15:10 PM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology

    CHIEF REVENUE OFFICER Notman Tali sold $1,977,785 worth of Ordinary Shares (22,854 units at $86.54), decreasing direct ownership by 3% to 728,644 units (SEC Form 4) to cover withholding tax

    4 - JFrog Ltd (0001800667) (Issuer)

    6/4/26 4:15:13 PM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology

    $FROG
    SEC Filings

    View All

    SEC Form 144 filed by JFrog Ltd.

    144 - JFrog Ltd (0001800667) (Subject)

    5/22/26 4:25:47 PM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology

    JFrog Ltd. filed SEC Form 8-K: Submission of Matters to a Vote of Security Holders

    8-K - JFrog Ltd (0001800667) (Filer)

    5/22/26 4:15:16 PM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology

    SEC Form 144 filed by JFrog Ltd.

    144 - JFrog Ltd (0001800667) (Subject)

    5/22/26 4:03:19 PM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology

    $FROG
    Analyst Ratings

    Analyst ratings in real time. Analyst ratings have a very high impact on the underlying stock. See them live in this feed.

    View All

    JFrog upgraded by UBS with a new price target

    UBS upgraded JFrog from Neutral to Buy and set a new price target of $60.00

    3/24/26 8:27:29 AM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology

    Guggenheim initiated coverage on JFrog with a new price target

    Guggenheim initiated coverage of JFrog with a rating of Buy and set a new price target of $60.00

    3/16/26 8:42:01 AM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology

    BTIG Research initiated coverage on JFrog with a new price target

    BTIG Research initiated coverage of JFrog with a rating of Buy and set a new price target of $83.00

    12/17/25 9:23:21 AM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology

    $FROG
    Press Releases

    Fastest customizable press release news feed in the world

    View All

    JFrog Announces Inclusion in Russell 3000 ® Index

    JFrog Ltd. ("JFrog") (NASDAQ:FROG), the Liquid Software Company and creators of the JFrog Software Supply Chain Platform, the system of record for trusted software artifacts, binaries, and AI assets, today announced it has been selected to be included in Russell 3000® Index as part of the 2026 Russell indexes reconstitution. This inclusion will become effective when the U.S. market closes on June 26, 2026. Inclusion in the Russell 3000 ® Index means automatic inclusion in the large-cap Russell 1000® Index or small-cap Russell 2000® Index as well as the appropriate growth and value style indexes. Investors can follow updates expected to be provided by FTSE Russell on May 29, June 5, June 1

    6/2/26 8:00:00 AM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology

    New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs

    The Hidden Costs of AI at Scale: JFrog's 2026 Software Supply Chain Security report shows threat actors weaponizing developer workflows, driving 177K new malicious packages, 495 malicious AI models, and a 451% increase in infected npm packages JFrog Ltd. (NASDAQ:FROG), the Liquid Software company and creators of the JFrog Software Supply Chain Platform, the system of record for trusted software artifacts, binaries, and AI assets today announced the findings of its 2026 Software Supply Chain Security State of the Union report. This year's report reveals an unprecedented acceleration in enterprise software risk as threat actors expand strikes beyond traditional package registries into AI mo

    5/20/26 4:05:00 PM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology

    JFrog to Present at Upcoming Investor Conferences

    JFrog Ltd. ("JFrog") (NASDAQ:FROG), the Liquid Software Company and creators of the JFrog Software Supply Chain Platform, today announced that it will present at the following investor conferences during the second quarter of 2026: JP Morgan 2026 Global Technology, Media & Telecom Conference in Boston, Massachusetts, Tuesday, May 19th, at 6:25 a.m. Pacific Daylight Time TD Cowen Technology, Media & Telecom Conference in New York, New York, Wednesday, May 27th, at 12:00 p.m. Pacific Daylight Time William Blair Growth Conference in Chicago, Illinois, Wednesday, June 3rd, at 7:20 a.m. Pacific Daylight Time Bank of America 2026 Global Technology Conference in San Francisco, Californ

    5/12/26 4:05:00 PM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology

    $FROG
    Leadership Updates

    Live Leadership Updates

    View All

    JFrog Appoints Genefa Murphy as Chief Marketing Officer to Accelerate Its Next Growth Phase

    Company Extends Executive Leadership to Lead the AI-Driven Software Supply Chain Evolution JFrog Ltd. (NASDAQ:FROG), the Liquid Software company, today announced the appointment of Genefa Murphy as Chief Marketing Officer, effective immediately. Murphy brings an expansive resume to JFrog, as a seasoned CMO and go-to-market (GTM) leader with established success in driving global enterprise software growth and strategic business expansion. Coming from software development product management roots and public company GTM leadership, Ms. Murphy also holds a PhD in User Acceptance of New Technology, from the University of Wales and is a veteran of multiple boards of directors in technology and

    1/5/26 8:00:00 AM ET
    $FIVN
    $FROG
    $HPE
    EDP Services
    Technology
    Computer Software: Prepackaged Software
    Retail: Computer Software & Peripheral Equipment

    JFrog Appoints Seasoned CIO and Digital Transformation Executive Sigal Zarmi to its Board of Directors

    Former Chief Information Officer of Morgan Stanley, PwC, GE Capital, and Staples joins JFrog's Board, Amid Major Enterprise Software Market Shifts Ahead JFrog Ltd. ("JFrog") (NASDAQ: FROG), the Liquid Software company and creators of the JFrog Software Supply Chain Platform, today announced Sigal Zarmi will join its Board of Directors, effective November 1, 2025. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250925161575/en/Sigal Zarmi, Former Chief Information Officer of Morgan Stanley, PwC, GE Capital, and Staples, Joins JFrog's Board With extensive experience as a board member across transforming companies, including ADT,

    9/25/25 4:05:00 PM ET
    $ADT
    $FROG
    $GDDY
    Diversified Commercial Services
    Consumer Discretionary
    Computer Software: Prepackaged Software
    Technology

    JFrog Appoints Sunny Rao as Senior Vice President of Asia Pacific to Drive Next Phase of Growth and Innovation Across the Region

    JFrog Ltd. ("JFrog") (NASDAQ:FROG), the Liquid Software company and creators of the award-winning JFrog Software Supply Chain Platform, today announced Sunny Rao has joined the company as Senior Vice President (SVP) of Asia Pacific (APAC) sales. Reporting directly to JFrog's Chief Revenue Officer (CRO), Tali Notman, Rao will spearhead the company's growth initiatives across APAC, helping customers achieve their business transformation goals utilizing the JFrog Platform. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250529286347/en/JFrog Appoints Sunny Rao as Senior Vice President of Asia Pacific to Drive Next Phase of Growth an

    5/29/25 9:15:00 AM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology

    $FROG
    Financials

    Live finance-specific insights

    View All

    JFrog Announces First Quarter 2026 Results

    Total First Quarter Revenues of $154.0 million; up 26% Year-over-Year First Quarter Cloud Revenues of $78.9 million; up 50% Year-over-Year Customers with ARR greater than $1 million equaled 80, up 48% Year-over-Year Trailing four quarter Net Dollar Retention equaled 120% versus 116% in prior year JFrog Ltd. ("JFrog") (NASDAQ:FROG), the creators of the JFrog Software Supply Chain Platform, the system of record for trusted software artifacts, binaries, and AI assets, today announced financial results for its first quarter 2026, ended March 31, 2026. "Q1 was a solid quarter, with strong performance across revenue, cloud growth, and all key metrics, reflecting consistent executio

    5/7/26 4:05:00 PM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology

    JFrog Announces Timing of First Quarter 2026 Financial Results

    JFrog Ltd. ("JFrog") (NASDAQ:FROG), the Liquid Software company and creators of the JFrog Software Supply Chain Platform, today announced it will report financial results for the first quarter 2026 on Thursday, May 7, 2026, following the market close. JFrog will host a conference call to discuss the results at 2:00 p.m. PT on the same day. Event: JFrog's First Quarter 2026 Financial Results Conference Call Date: Thursday, May 7, 2026 Time: 2:00 p.m. PT (5:00 p.m. ET) Webcast registration link: https://investors.jfrog.com/events-and-presentations About JFrog JFrog Ltd. (NASDAQ:FROG), the creators of the unified DevOps, DevSecOps, DevGovOps and MLOps platform, is on a mission to c

    4/8/26 4:05:00 PM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology

    JFrog Announces Fourth Quarter and Fiscal 2025 Results

    Total fiscal 2025 Revenues of $531.8 million; up 24% Year-over-Year Fiscal 2025 Cloud Revenues of $243.3 million; up 45% Year-over-Year Customers with ARR greater than $1 million equaled 74, up 42% Year-over-Year Fiscal 2025 JFrog Security Core equaled 7% of Revenue, 10% of ARR and 16% of RPO Ending RPO totaled $566 million, a 40% increase year over year JFrog Ltd. ("JFrog") (NASDAQ:FROG), the Liquid Software company and creators of the JFrog Software Supply Chain Platform, today announced financial results for its fourth quarter and fiscal year 2025 ended December 31, 2025. "Developers and AI coding agents are now building and releasing software together at unprecedented

    2/12/26 4:05:00 PM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology

    $FROG
    Large Ownership Changes

    This live feed shows all institutional transactions in real time.

    View All

    SEC Form SC 13G/A filed by JFrog Ltd. (Amendment)

    SC 13G/A - JFrog Ltd (0001800667) (Subject)

    2/13/24 7:59:52 PM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology

    SEC Form SC 13G/A filed by JFrog Ltd. (Amendment)

    SC 13G/A - JFrog Ltd (0001800667) (Subject)

    2/13/24 7:57:49 PM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology

    SEC Form SC 13G/A filed by JFrog Ltd. (Amendment)

    SC 13G/A - JFrog Ltd (0001800667) (Subject)

    2/13/24 7:56:49 PM ET
    $FROG
    Computer Software: Prepackaged Software
    Technology