
AI worms are coming — and traditional controls won't stop them
Researchers built a worm that reasons about hosts it infects, and the open-weight models powering it sit outside AI-provider safety controls.

Researchers built a worm that reasons about hosts it infects, and the open-weight models powering it sit outside AI-provider safety controls.

While prompt injection and data disclosure remain concerns, excessive agency climbed the list — not surprising with recent security incidents.

Here's how to use Spectra Analyze to hunt for malicious SVGs, from setting up queries and evaluations of samples to tips for investigation.

Researchers built a worm that reasons about hosts it infects, and the open-weight models powering it sit outside AI-provider safety controls.

While prompt injection and data disclosure remain concerns, excessive agency climbed the list — not surprising with recent security incidents.

The post-mortems of two compromises by rogue AI agents show that security teams need to focus on guardrails, not the AI model.

Research into an Active Directory takeover with a single AI prompt highlights why organizations need to focus on agentic SOCs.

Here's how to use Spectra Analyze to hunt for malicious SVGs, from setting up queries and evaluations of samples to tips for investigation.

Traditional SBOMs, signing, and provenance all have blind spots, making them no longer capable of assuring software security.

AI coding requires the stack be reconstructed with mathematical proofs built in — a task well suited to the Lean language. Here’s the reality.

Spectra Detect is now Kubernetes-native. Spectra Analyze adds AI workflows for the agentic SOC. Here's everything that shipped.

Delaying software upgrades creates a buffer against poisoned packages, but transitive dependencies continue to be a problem.

A new report finds weakening trust in AI-only testing — and more willingness to keep humans in the loop. Here's why.

Industry heavyweights bring new focus to vulnerabilities in the age of AI. Here’s how it might help improve security.

SVGs are difficult to detect, can be snuck into content — and can do malicious and legitimate actions. Here's how malicious SVGs work.

One of the most effective attack methods I've analyzed this year runs on legitimate tools and willing users — and AV and EDR is blind to it.

Threat Advisor could help teams with AI-specific risks. But a broader AppSec strategy rethink is needed in the AI era.

New RL research explains why ClickFix attacks are multiplying — and why reliable detection requires going beyond AV and EDR.
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial