Business Wire
BusinessJensen Huang’s “Buy at a Discount” remark returns to focus as Nvidia shares rise and an AI basket gainsThe Apex TimesBusinessAMD says it is expanding its AI infrastructure footprint in Saudi ArabiaThe Apex TimesBusinessVerizon readies network resources as Tropical Storm Edouard nearsThe Apex TimesBusinessNvidia shares show a rare trading pattern, underscoring how investors are rethinking semiconductor correlationsThe Apex TimesBusinessEli Lilly to buy Merida Biosciences in up-to $2.875 billion cash deal, betting on an expanded autoimmune pipelineThe Apex TimesBusinessNvidia backs MediaTek with $3.5 billion convertible-bond deal, indicating a push for local AIThe Apex TimesBusinessBoeing to resume contract talks with engineers, as strike threat remains on the tableThe Apex TimesBusinessFTC and 22 states sue Amazon, alleging it manipulated online ad auctionsThe Apex TimesBusinessAlphabet’s Google says Gemini-powered “Teamwork” agents solved open math, built a CPU simulator, and improved core open-source librariesThe Apex TimesBusinessKKR’s “mini Berkshire” push shows early results as it sells USI assets for about $17 billionThe Apex TimesBusinessDeere shares rise after Baird upgrade to OutperformThe Apex TimesBusinessReport: Exxon Mobil joins bidders for Shell’s U.S. chemicals assets, a potential shift for XOM’s refining-and-chemicals outlookThe Apex TimesBusinessJensen Huang’s “Buy at a Discount” remark returns to focus as Nvidia shares rise and an AI basket gainsThe Apex TimesBusinessAMD says it is expanding its AI infrastructure footprint in Saudi ArabiaThe Apex TimesBusinessVerizon readies network resources as Tropical Storm Edouard nearsThe Apex TimesBusinessNvidia shares show a rare trading pattern, underscoring how investors are rethinking semiconductor correlationsThe Apex TimesBusinessEli Lilly to buy Merida Biosciences in up-to $2.875 billion cash deal, betting on an expanded autoimmune pipelineThe Apex TimesBusinessNvidia backs MediaTek with $3.5 billion convertible-bond deal, indicating a push for local AIThe Apex TimesBusinessBoeing to resume contract talks with engineers, as strike threat remains on the tableThe Apex TimesBusinessFTC and 22 states sue Amazon, alleging it manipulated online ad auctionsThe Apex TimesBusinessAlphabet’s Google says Gemini-powered “Teamwork” agents solved open math, built a CPU simulator, and improved core open-source librariesThe Apex TimesBusinessKKR’s “mini Berkshire” push shows early results as it sells USI assets for about $17 billionThe Apex TimesBusinessDeere shares rise after Baird upgrade to OutperformThe Apex TimesBusinessReport: Exxon Mobil joins bidders for Shell’s U.S. chemicals assets, a potential shift for XOM’s refining-and-chemicals outlookThe Apex TimesBusinessJensen Huang’s “Buy at a Discount” remark returns to focus as Nvidia shares rise and an AI basket gainsThe Apex TimesBusinessAMD says it is expanding its AI infrastructure footprint in Saudi ArabiaThe Apex TimesBusinessVerizon readies network resources as Tropical Storm Edouard nearsThe Apex TimesBusinessNvidia shares show a rare trading pattern, underscoring how investors are rethinking semiconductor correlationsThe Apex TimesBusinessEli Lilly to buy Merida Biosciences in up-to $2.875 billion cash deal, betting on an expanded autoimmune pipelineThe Apex TimesBusinessNvidia backs MediaTek with $3.5 billion convertible-bond deal, indicating a push for local AIThe Apex TimesBusinessBoeing to resume contract talks with engineers, as strike threat remains on the tableThe Apex TimesBusinessFTC and 22 states sue Amazon, alleging it manipulated online ad auctionsThe Apex TimesBusinessAlphabet’s Google says Gemini-powered “Teamwork” agents solved open math, built a CPU simulator, and improved core open-source librariesThe Apex TimesBusinessKKR’s “mini Berkshire” push shows early results as it sells USI assets for about $17 billionThe Apex TimesBusinessDeere shares rise after Baird upgrade to OutperformThe Apex TimesBusinessReport: Exxon Mobil joins bidders for Shell’s U.S. chemicals assets, a potential shift for XOM’s refining-and-chemicals outlookThe Apex TimesBusinessJensen Huang’s “Buy at a Discount” remark returns to focus as Nvidia shares rise and an AI basket gainsThe Apex TimesBusinessAMD says it is expanding its AI infrastructure footprint in Saudi ArabiaThe Apex TimesBusinessVerizon readies network resources as Tropical Storm Edouard nearsThe Apex TimesBusinessNvidia shares show a rare trading pattern, underscoring how investors are rethinking semiconductor correlationsThe Apex TimesBusinessEli Lilly to buy Merida Biosciences in up-to $2.875 billion cash deal, betting on an expanded autoimmune pipelineThe Apex TimesBusinessNvidia backs MediaTek with $3.5 billion convertible-bond deal, indicating a push for local AIThe Apex TimesBusinessBoeing to resume contract talks with engineers, as strike threat remains on the tableThe Apex TimesBusinessFTC and 22 states sue Amazon, alleging it manipulated online ad auctionsThe Apex TimesBusinessAlphabet’s Google says Gemini-powered “Teamwork” agents solved open math, built a CPU simulator, and improved core open-source librariesThe Apex TimesBusinessKKR’s “mini Berkshire” push shows early results as it sells USI assets for about $17 billionThe Apex TimesBusinessDeere shares rise after Baird upgrade to OutperformThe Apex TimesBusinessReport: Exxon Mobil joins bidders for Shell’s U.S. chemicals assets, a potential shift for XOM’s refining-and-chemicals outlookThe Apex Times
Back to front
Broadcom ramps up Spring security patches with AI-assisted scanning and “day zero” CVE-only releases
The Apex Times

THE APEX TIMES

Business/The Apex Times/Jun 8, 1:43 PM EDT

Broadcom ramps up Spring security patches with AI-assisted scanning and “day zero” CVE-only releases

The VMware Tanzu unit said it is releasing its largest set of Spring security updates in 23 years and expanding enterprise support that separates security fixes from broader changes.

Broadcom said it is making a major security investment in the Spring and Java software ecosystem, a move aimed at helping enterprises patch faster as artificial intelligence reshapes how quickly vulnerabilities are discovered and exploited. In a June 8 announcement, Broadcom’s Tanzu business said it is releasing what it described as the largest set of Spring security updates to open source in Spring’s 23-year history, and it is extending an enterprise approach for delivering validated dependency fixes to customers who run Spring-based applications in production. Broadcom did not provide a dollar figure for the investment.

Broadcom’s plan centers on AI-assisted security analysis in its Spring engineering workflows, including “frontier model–based scanning and validation” meant to proactively identify vulnerabilities, map remediation paths, and validate fixes across Spring’s dependency ecosystem. The company linked the effort to accelerating threat discovery and a narrower window between public vulnerability disclosure and real-world exploitation. In the company’s statement, the Spring community reported more than a 1,700% increase in monthly security advisories to Broadcom from March to April 2026, underscoring what it called a surge in AI-detected security threats.

On the customer side, Tanzu Spring will provide “day zero access” to validated common vulnerabilities and exposures patches, or CVE-only patches. CVEs are standardized identifiers used to track specific software security flaws, and “CVE-only” means Broadcom intends to isolate the security fix from other unrelated changes so enterprises can remediate sooner. Broadcom said customers can obtain these validated patch-only releases via the Spring Enterprise Repository before the patches reach open source, using private artifact repositories that it says contain the official, validated patches from the Spring steward and sole committers.

Broadcom also said it is extending its “clean-room build” architecture for building Java dependencies across the entire Spring ecosystem. Clean-room builds, as described in Broadcom’s announcement, are intended to produce verifiable artifacts from controlled processes, reducing uncertainty about what code is actually included in the components organizations ship. The company tied this capability to Bitnami and said Tanzu Spring customers will gain access to a software supply chain that is validated at SLSA Level 3. SLSA, or Supply-chain Levels for Software Artifacts, is a framework for measuring how securely build processes and provenance information are handled, and Level 3 is meant to reflect a higher bar for controls.

In terms of coverage and scale, Broadcom said its Tanzu Spring approach will extend across the full transitive dependency graph managed by the Spring Boot bill of materials. A bill of materials is effectively a curated list of libraries a project pulls in, and a transitive dependency graph includes dependencies of dependencies. Broadcom said Spring Boot 4.0 alone manages 1,768 dependencies and that the full supported portfolio totals more than 100,000 validated dependency builds. It said the capability provides secured dependencies built and tested across every supported Spring version, including some older versions still in enterprise support.

Broadcom framed the initiative as part of a broader shift in software security toward supply chain risk management and faster remediation. As organizations increasingly run mission-critical systems on Java frameworks such as Spring, patching lag can compound exposure, especially when vulnerabilities emerge quickly and updates must propagate through many downstream libraries. The company also said it is enabling customers to assess their application estate in both source code and running applications and to recommend deterministic upgrades, with tools such as Tanzu Platform, Tanzu Build Service, and buildpacks designed to help “single fix” changes propagate across an application portfolio.

The announcement did not disclose key operational details such as the timeline for how quickly day-zero patches become available after CVE publication, any specific service level guarantees, or pricing for Tanzu Spring components. It also did not specify the exact model families or parameters used for AI scanning, nor did it provide counts of vulnerabilities that have already been identified through these workflows. As a result, the practical difference for customers will depend on how Broadcom operationalizes these processes in real deployments.

Next for the market is watching whether the open-source security updates and the enterprise patch-only workflow reduce mean time to remediate for Spring users, particularly those with complex dependency chains. Broadcom’s move also suggests competition may intensify around enterprise-first patch distribution and supply chain verification for widely used developer ecosystems, especially as AI-driven discovery continues to compress the patching window.

Why It Matters

  • Enterprise Spring users often patch through long dependency chains, so a faster, CVE-only delivery mechanism could reduce the time systems spend exposed to known flaws.
  • AI-assisted scanning and validation may shift security posture from reacting to disclosures toward earlier identification of vulnerabilities and quicker fix verification across dependencies.
  • SLSA Level 3 supply chain validation reflects a growing buyer preference for provenance and build integrity, not just the existence of patches.
  • The initiative increases pressure on other maintainers and enterprise tooling vendors to offer similarly fast, verified remediation pathways for widely used application frameworks.
  • If broadly adopted, “day zero” enterprise patch distribution could become a differentiator in how enterprises budget for developer tooling and security operations.

Sources

Key Facts

  • Broadcom said it is releasing what it described as the largest set of Spring security updates to open source in Spring’s 23-year history.
  • Broadcom’s Tanzu unit said it is scaling AI-assisted security analysis for Spring, including frontier model–based scanning and validation workflows.
  • Tanzu Spring will offer “day zero” access to validated CVE-only patch releases via the Spring Enterprise Repository before patches move to open source.
  • Broadcom said it is extending a clean-room build architecture for Java dependencies across the Spring ecosystem, based on controlled build processes.
  • The company said Tanzu Spring will provide a software supply chain validated at SLSA Level 3 across the transitive dependency graph managed by Spring Boot’s bill of materials, with more than 100,000 validated dependency builds across the supported portfolio.
  • Broadcom said monthly security advisories reported by the Spring community to Broadcom increased by more than 1,700% from March to April 2026, and it tied the jump to AI-enabled threat discovery and a reduced time-to-exploit window.

Technology Related

Aug 31, 6:08 PM EDT
The Apex Times

FTC and 22 states sue Amazon, alleging inflated prices in online ads scheme

The Federal Trade Commission and a coalition of states filed a lawsuit accusing Amazon of misleading advertising customers and defrauding them through inflated ad pricing. Amazon has not been found liable, and the company’s response was not included in the announcement referenced by the reporting.

FTC and 22 states sue Amazon, alleging inflated prices in online ads scheme
The Apex Times
Broadcom ramps up Spring security patches with AI-assisted scanning and “day zero” CVE-only releases | The Apex Times