
Stop Malicious Packages with the Spectra Assure Community Plugin for JFrog Artifactory
Package managers auto-pull the latest OSS version — malware included. Protect your pipelines with this free JFrog Artifactory plugin.

Package managers auto-pull the latest OSS version — malware included. Protect your pipelines with this free JFrog Artifactory plugin.

ExtraHop's Kanaiya Vasani unpacks the concept of the agentic SOC — and how the Agentic SOC Alliance is working to build them out.

Aurastealer, ACRStealer, and RemusStealer, a new potential LumaStealer variant, show MaaS in action. Here's what you need to know.

Package managers auto-pull the latest OSS version — malware included. Protect your pipelines with this free JFrog Artifactory plugin.

ExtraHop's Kanaiya Vasani unpacks the concept of the agentic SOC — and how the Agentic SOC Alliance is working to build them out.

The TeamPCP actors, alleged to be behind one of the most active supply chain threats, were arrested — but this is not the end of Shai-Hulud.

ReversingLabs built a Spectra Analyze integration with CrowdStrike Falcon. The connector is available now as part of Spectra Analyze v9.6.0.

Aurastealer, ACRStealer, and RemusStealer, a new potential LumaStealer variant, show MaaS in action. Here's what you need to know.

UAT-10147 leveraged agentic AI to go beyond scripting to deliver a backdoor. The method highlights the need for agentic SOCs.

Organizations don’t realize how pervasive shadow AI has become. And as AI's capability grows, shadow use is harder to manage.

Attackers turned the trusted AsyncAPI CI/CD publishing pipeline against its users, and the provenance checks all came back clean.

The annual cybersecurity conference focused on frontier AI agents — and what they mean for cyber. Here are three key takeaways.

Researchers built a worm that reasons about hosts it infects, and the open-weight models powering it sit outside AI-provider safety controls.

While prompt injection and data disclosure remain concerns, excessive agency climbed the list — not surprising with recent security incidents.

The post-mortems of two compromises by rogue AI agents show that security teams need to focus on guardrails, not the AI model.

Research into an Active Directory takeover with a single AI prompt highlights why organizations need to focus on agentic SOCs.

Here's how to use Spectra Analyze to hunt for malicious SVGs, from setting up queries and evaluations of samples to tips for investigation.

Traditional SBOMs, signing, and provenance all have blind spots, making them no longer capable of assuring software security.
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial