
MCP rug-pull attack worries mount
This new class of AI tool supply chain attack highlights how trust of agents can be exploited.

This new class of AI tool supply chain attack highlights how trust of agents can be exploited.

AI lets software teams generate code at a rate faster than security can validate it. One way to win the race: more AI.

Researchers show how LLM fingerprinting can be used to automate generation of customized attacks.

Threat actors are leveraging the freewheeling vibe-coding trend to deliver malicious software at scale.

Here's how the EU's Cyber Resilience Act will reshape the software industry — and how that accelerates advantages.

Anthropic's new AI is a 'step change' for exposing software flaws — but also ramps up exploits. Are you ready?

AI and open source are redefining the software threat landscape. Here are the key statistics you need to know.

Here's a mitigations checklist and best practices. Plus: How RL’s xBOM and Spectra Assure Community can help.

JPMorgan Chase CISO Patrick Opet discussed his letter on third-party software risk — and how that has played out.

With AI ramping up risk, OWASP stepped up its project to help AppSec teams get up to speed — and take action.

The perimeter isn't your firewall — it's your CI/CD pipeline. Here’s what to know about TeamPCP's supply chain attack.

Shift to a data security pipeline platform to get software visibility that modern supply chain threats demand.

Research shows that AI coding can tap integrated development environments to become privileged insider threats.

AI agents create novel attack surfaces and control issues that require rethinking assumptions — and AppSec tooling.

OWASP has adopted the container security tool to slow information overload. Here’s what you need to know.
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial