Mend.io News
21 articles
Mend.io Expands AI Security with Mend AI Premium Offering
Mend.io Launches Mend AI
Mend.io has launched a new tool, Mend AI, to help organizations secure their AI and AI-generated code. The tool can identify and provide information on all 350K AI models indexed on Hugging Face, a popular open source AI library. This will allow security and compliance teams to track AI usage in their codebase, ensure secure versions of AI models are being used, and make informed policy decisions. Mend AI is being developed in collaboration with customers and will include features such as AI code snippet detection and gender bias detection.
CustomersExpand
Invicti Security & Mend.io Partner Up to Bring Customers Full Spectrum AppSec Testing
Invicti Security and Mend.io have announced a partnership to provide customers with a comprehensive range of application security testing and supply chain security tools. The partnership combines Invictis DAST, IAST, and API Security domains with Mends SAST, SCA, and Container Security solutions. The collaboration aims to provide full code coverage and continuous security, helping companies balance development speed and innovation with robust cybersecurity practices. The partnership was formed in response to the growing demand for comprehensive appsec testing solutions as cloud-native software development shifts risk attention from the network to the application level.
PartnersCustomers
Mend.io acquires cyber startup Atom Security | CTech
Israeli cybersecurity firm Mend.io has acquired Atom Security, a company specializing in cyber risk assessment. The acquisition is valued at several million dollars, marking Mends fifth acquisition in the last three years. Founded in 2011, Mend.io assists developers in managing open-source libraries, mitigating security risks, and addressing open-source license concerns. The company has secured $122 million in funding to date, including a $75 million Series D in April 2021. Atoms co-founders will join Mend.ios Cloud Native division. The integration of Atom Securitys technology into Mend.ios product line is expected to decrease the number of irrelevant findings by 60% to 70%.
Acquisition
WhiteSource Rebrands as Mend, Introduces Industry-First Automated Remediation with the Mend Application Security Platform
WhiteSource, a leader in application security, has changed its name to Mend and announced the industrys first automated remediation for custom code security issues. The company has experienced significant growth, with revenue up 800% over the past three years and the addition of 350 new customers in the last year. Mend has over 1,000 customers, including more than 25% of the Fortune 100. The company plans to invest its latest funding round of $75 million series D into its overall growth and expansion beyond the Software Composition Analysis market. Mend has acquired Diffend, Xanitizer, and DefenseCode to strengthen its position in the application security space. The companys focus on automation aims to reduce the software attack surface and the burden of application security for developers.
CustomersInvestmentAcquisition
WhiteSource eases developers' security burden by automating vulnerability detection and remediation - SiliconANGLE
Israeli startup WhiteSource, which provides a platform for securing open-source software components, aims to automate security practices for developers. The companys solution identifies vulnerabilities in an enterprises technology stack and provides real-time alerts and guidance on fixing them. WhiteSource focuses on building trust with users by gradually proving the effectiveness of its solutions and allowing users to control the pace of automation. The company also relies on crowdsourcing and a comprehensive database to provide confidence in vulnerability remediation. WhiteSource differentiates itself by going beyond vulnerability alerts and offering automated remediation. The company has a partnership with Amazon Web Services and is integrated with many AWS services. The article highlights WhiteSources participation in the AWS Startup Showcase event.
Customers
WhiteSource Acquires Diffend to Provide Software Supply Chain Security
WhiteSource, a leader in open source security and management, has acquired Diffend, an open source malware security and threat detection solution. Post-acquisition, all of Diffends commercial offerings will be available for free under the new name WhiteSource Diffend. This acquisition allows WhiteSource to offer an advanced platform for mitigating software supply chain risk. The founder of Diffend, Maciej Mensfeld, will join WhiteSource as Senior Product Manager for Software Supply Chain Security.
Acquisition
Israel's WhiteSource announces $75 million series D
WhiteSource Software, Inc. has completed a $75 million series D funding round led by Pitango Growth. The funding brings WhiteSources total funding to $121.2 million. The company has seen a fivefold increase in customers and 800% revenue growth over the past three years. WhiteSource provides a remediation-centric solution for application security, helping organizations protect their software applications without compromising speed. Microsoft, IBM, KPMG, and Comcast are among WhiteSources customers. The investment will support the companys expansion and development of a complete application security solution. Isaac Hillel, Managing Partner at Pitango Growth, will join the WhiteSource Board of Directors.
InvestmentExpand
WhiteSource Launches Extension For Microsoft Azure DevOps Services
WhiteSource has announced a new native integration for Microsoft Azure DevOps services. The integration provides Azure DevOps users with visibility over their open source components and real-time security and compliance alerts. It aims to make the lives of DevOps, development, and security managers easier by reducing remediation time and detecting vulnerabilities and compliance issues during the build stage. The integration alerts users on problematic open source components and provides a comprehensive risk report embedded in the Azure DevOps pipelines environment. This addition enhances WhiteSources offering to Microsoft Visual Studio and Azure DevOps customers, providing an end-to-end solution for their software development needs.
Partners
WhiteSource Launches Microsoft Visual Studio IDE Integration
WhiteSource, a leader in open source security and license compliance management software, has announced support for the Microsoft Visual Studio integrated development environment (IDE). This integration allows Visual Studio developers to have visibility and security alerts on problematic open source components while continuing to develop within their own environment. The integration aims to make developers lives easier by enabling them to code faster and more securely. With this new edition, WhiteSource now supports three of the top IDEs: Visual Studio, IntelliJ, and Eclipse.
Partners
WhiteSource Enhances Container Support to Provide Native Integrations for All Top Container Registries
WhiteSource, a leader in open source security and license compliance management, has announced new and expanded support for the top five container registries and complete control over Kubernetes container orchestration. The expanded support allows enterprises to track vulnerabilities in file systems, installed packages, image layers, and handled archive files without manual scanning. WhiteSources enhanced Kubernetes integration provides comprehensive visibility and control over libraries, images, alerts, vulnerabilities, and licenses. The company aims to provide customers with the tools needed for comprehensive visibility and control over containerized environments. WhiteSource is used by over 800 customers worldwide, including industry leaders such as Microsoft and IBM.
PartnersExpand
WhiteSource Launches New Product for E2E Open Source Security Throughout Container Lifecycle
WhiteSource has announced the release of WhiteSource for Containers, a solution for the detection and remediation of open source vulnerabilities within container images and containers. The solution integrates with container registries and offers advanced support for container orchestration platforms like Kubernetes. It automatically detects vulnerabilities and license compliance issues throughout the software development lifecycle. The new product includes an advanced Kubernetes agent that scans images deployed to production in new pods and alerts development teams about new vulnerabilities. WhiteSource is a pioneer in open source security management and is used by over 500 customers worldwide.
CustomersPartners
WhiteSource nabs $35M to track open source code for security vulnerabilities
Israel-based WhiteSource has raised $35 million in funding to expand its work in tracking and fixing vulnerabilities in open source components. The company plans to hire more engineers, expand its platform, and enter new geographies. WhiteSource, founded in 2011, has already secured 500 large enterprises as customers, including 23 percent of Fortune 100 companies. The funding round was led by Susquehanna Growth Equity, with participation from 83North and M12. While the company did not disclose its valuation, it is estimated to be around $200 million. WhiteSources software composition analysis solution is considered the most comprehensive on the market, offering tools to prevent vulnerabilities and mitigate security risks.
InvestmentExpand
WhiteSource Unveils Free to Use Vulnerability Checker to Combat Most Critical Open Source Vulnerabilities
WhiteSource has released a free tool called Vulnerability Checker that can detect the 50 most critical open source vulnerabilities published in the last month. The tool allows users to import and scan any library and provides a detailed report on detected vulnerabilities, severity, paths, and suggested fixes. The Vulnerability Checker syncs with WhiteSources monthly reports on top open source vulnerabilities. The company aims to provide developers with quick and accurate data on their open source usage and empower them with critical open source security information. WhiteSource is a leader in continuous open source security and license compliance management.
Customers
WhiteSource Launches Next-generation Software Composition Analysis Technology for Prioritizing Open Source Security Alerts
WhiteSource has launched its next-generation Software Composition Analysis solution called Effective Usage Analysis. This technology provides actionable insights on how components are being used in applications, reducing open source vulnerability alerts by 70%. The analysis shows which vulnerabilities are effective and impact the security of the application, allowing security and engineering teams to prioritize threats and optimize remediation. The Effective Usage Analysis will initially support Java and JavaScript and will be fully available in June.
Customers
WhiteSource Launches Contextual Pattern Matching Engine, Supporting Over 200 Programming Languages
WhiteSource has launched its Contextual Pattern Matching (CPM) Engine, a patent-pending technology that enhances capabilities for accurate detection and association of source files to source libraries. The CPM Engine improves accuracy levels, reduces sensitivity to file edits, and supports over 200 programming languages. Customers who have upgraded to the new engine have reported a substantial boost in productivity. The technology will enable WhiteSources customers to enhance their open source vulnerability, licensing, and quality management. WhiteSource is a leader in continuous open source security and license compliance management, trusted by industry leaders like Microsoft and IBM.
Customers
WhiteSource Expands Its Open Source Security Solution for Containerized Applications with Continuous Image Scanning
WhiteSource, a leader in open source security and license compliance management, has announced an enhancement to its support for containerized applications. The company has expanded its Docker container analysis tool to support full image scanning throughout all the image layers and packages within the image. This new capability allows for earlier visibility into the security of containerized applications in the Software Development Lifecycle. WhiteSource has also included full automation for monitoring images without the need to run them as active containers. The enhanced Docker container analysis tools now support container images hosted in repositories like DockerHub, Artifactory, and GitHub. The company aims to provide continuous security for containers throughout the CI/CD process and ensure the widest coverage possible across various microservices.
CustomersPartners
WhiteSource Strong Momentum Continued in 2017 Led by More Than Tripling Its Top Line
WhiteSource, a leader in open source security and license compliance management, achieved aggressive year-over-year growth in 2017 by doubling its customer base. The company expanded its suite of patented technology, doubled its employee count, and opened new offices in New York and Boston. WhiteSources growth is driven by the significant market opportunity and enterprise demand for Software Composition Analysis solutions. The company raised $10 million in a Series B round of financing led by 83North, with participation from Microsoft Ventures and David Strohm. WhiteSource also formed partnerships with Microsoft, IBM, and other companies to provide open source security solutions. The company aims to empower businesses to develop better software by harnessing the power of open source.
CustomersPartners
WhiteSource Signs Global Reseller Agreements, Making First Entrance Into the Chinese Market
WhiteSource has announced a partnership with six new resellers across the globe, including Commentator A/S, Apera LTD, Switch, Virtual Data Consultants (VDC), Web Control, and Coontec. This marks WhiteSources first entrance into the Chinese market. The partnership aims to promote the better usage of open source and provide increased value to customers. WhiteSource expects to see new business enter through these channels, expanding its reach into new markets. The company has received investment from Microsoft and 83 North, raising a $10 million Series B in June 2017. WhiteSource has been recognized as a strong performer in Software Composition Analysis (SCA) offerings by Forrester.
Partners
WhiteSource Provides First Comprehensive Analysis Tool for Docker Containers
WhiteSource has announced the release of a fully functional Docker container analysis tool that covers both the container body and the installed software. This tool allows companies to safely use and fully utilize container technology by providing security vulnerability and open source license information for the operating system and applications within each container. The solution supports over 16 programming languages and platforms. WhiteSources Docker Container analysis solution is already being used by Scalock as part of its security solution suite. WhiteSources comprehensive database allows Scalock to identify language-specific vulnerabilities in components within the container.
Partners
WhiteSource to Offer Its Open Source Management Solution to Users of Grunt and Bower
WhiteSource, the leading provider of open source management solutions, has released a solution for the JavaScript tools Grunt and Bower. The company aims to help engineering executives manage the use of open source components in their software. WhiteSource offers solutions for various programming languages and development environments. The support for Grunt and Bower allows engineering executives to control open source use in teams that program in JavaScript. JavaScripts popularity has been increasing, and WhiteSource aims to provide a comprehensive solution for managing open source components in all parts of a companys software.
Customers