Fortify continues to run a security research group which maintains the Java Open Review project and the Vulncat taxonomy of security vulnerabilities. Members of the group are also responsible for the book Secure Coding with Static Analysis and for published research, including JavaScript Hijacking, Attacking the build: Cross build Injection, Watch what you write: Preventing Cross-site scripting by observing program output and Dynamic taint propagation: Finding vulnerabilities without attacking.