
Malware found on npm infecting local package with reverse shell
For the first time, RL researchers discover malicious locally-installed npm packages infecting other legitimate packages.

For the first time, RL researchers discover malicious locally-installed npm packages infecting other legitimate packages.

Target on back-alert: Open source was increasingly exploited in attacks on cryptocurrency infrastructure and apps in 2024.

Risk is rising across the software supply chain while visibility remains low, making TPCRM challenging. Here's what you need to know.

Instances of malware on open-source software repositories dropped in 2024 — but OSS risk is on the rise. Here’s what you need to know.

The Exploit Prediction Scoring System is useful, but limited. Here's why your application security strategy needs an upgrade.

Leveraging binary analysis, Spectra Assure uses a pre-deployment, static approach for virtual machine security, which is faster and more thorough. Here's how it works.

The complexity of today's software development makes supply chain security essential. This new cheat sheet is a great place to start.

While open-source risks are not going away, attack trends show third-party commercial software presents the greatest risk to the enterprise.

The promise of higher development output is prompting rapid adoption of AI coding tools, but AppSec teams are in the hot seat with rising risk. Buckle up!

Orchestrating the heavy lifting of data management and analytics is easier said than done. Here are four key pillars for improving security outcomes.

With the rise of attacks on the supply chain and threats from AI, securing containers requires a modern strategy. Here are key considerations.

From the AppSec testing gap to data privacy, AI is increasing security worries. Here are key takeaways from a survey of development leaders.

Software teams will need to get on board with agentic AI. But AppSec teams need new visibility and controls for the SDLC.

Hidden weaknesses and blind trust magnify the risks from third parties, a new report finds. Here are key takeaways for your cybersecurity team.

Two new reports — and the rise of AI and supply chain attacks — make it clear organizations must look beyond vulnerability mitigation alone. Take action now.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial