
Malicious npm campaign targets developers integrating Twilio
The package poses as a security tool targeting developers looking to implement Internet-based apps with telecom networks.

The package poses as a security tool targeting developers looking to implement Internet-based apps with telecom networks.

Organizations’ cyber dollars are shifting, not growing. But AI compute costs can spiral — and that is why context matters in your agentic SOC.

Controlling coding agent overpermissioning is key to security. But recent frontier AI incidents show that problems don’t stop there.

Organizations’ cyber dollars are shifting, not growing. But AI compute costs can spiral — and that is why context matters in your agentic SOC.

The package poses as a security tool targeting developers looking to implement Internet-based apps with telecom networks.

Controlling coding agent overpermissioning is key to security. But recent frontier AI incidents show that problems don’t stop there.

The coding languages shift — fueled by Microsoft, Google, and Amazon and enabled by AI coding — is driven by the quest for secure software.

The software industry is entering the AI era burdened by legacy flaws and weaknesses, making Secure by Design essential.

With this integration, Rubrik users can now tap ReversingLabs' ransomware feed to decide whether each file in their backup is safe.

The post-mortem reaches sobering conclusions, and demands a plan of action for the AI industry — plus your SecOps strategy.

Research confirms email summary design flaws — and that any unverified content is an attack vector, so invest in threat intel.

This guide compares leading file security tools across connector coverage, throughput, file-size range, and file-type breadth.

Package managers auto-pull the latest OSS version — malware included. Protect your pipelines with this free plugin.

ExtraHop's Kanaiya Vasani unpacks the concept of the agentic SOC — and how the Agentic SOC Alliance is working to build them out.

The TeamPCP actors, alleged to be behind one of the most active supply chain threats, were arrested — but this is not the end of Shai-Hulud.

ReversingLabs built a Spectra Analyze integration with CrowdStrike Falcon. The connector is available now as part of Spectra Analyze v9.6.0.

Aurastealer, ACRStealer, and RemusStealer, a new potential LumaStealer variant, show MaaS in action. Here's what you need to know.

UAT-10147 leveraged agentic AI to go beyond scripting to deliver a backdoor. The method highlights the need for agentic SOCs.
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial