
AppSec as attacker: Inside Trivy–LiteLLM
The perimeter isn't your firewall — it's your CI/CD pipeline. Here’s what to know about TeamPCP's supply chain attack.

The perimeter isn't your firewall — it's your CI/CD pipeline. Here’s what to know about TeamPCP's supply chain attack.

The malicious campaign started with Trivy and Checkmarx and has shifted to LiteLLM — and now telnix. Here's how.

Shift to a data security pipeline platform to get software visibility that modern supply chain threats demand.

The perimeter isn't your firewall — it's your CI/CD pipeline. Here’s what to know about TeamPCP's supply chain attack.

The malicious campaign started with Trivy and Checkmarx and has shifted to LiteLLM — and now telnix. Here's how.

Shift to a data security pipeline platform to get software visibility that modern supply chain threats demand.

Research shows that AI coding can tap integrated development environments to become privileged insider threats.

The final-stage malware in the Ghost campaign is a RAT designed to steal crypto wallets and sensitive data.

Here’s a look at the Ethereum Foundation’s new PQC security effort — and why you need to modernize your SecOps.

AI agents create novel attack surfaces and control issues that require rethinking assumptions — and AppSec tooling.

Here's how to assess a sample using Spectra Analyze in your environment — and create a YARA rule.

Learn how Package URLs improve vulnerability matching, which reduces alert fatigue and simplifies compliance.

OWASP has adopted the container security tool to slow information overload. Here’s what you need to know.

The OpenClaw saga is a case study on the threat from agentic AI, showing how it increases software risk.

The new tool is a step forward on AI coding risk — but it trips on modern threats because it looks only at source code.

AI coding is a game-changer — and requires AI-powered application security to fight fire with fire.

AI coding is the new reality — and it will further destabilize software supply chain security. So step up your AppSec.

RL discovered two packages containing scripts that complete a typosquatting toolchain. Here's how it worked.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial