
Why AI coding makes zero trust an AppSec requirement
Traditional SBOMs, signing, and provenance all have blind spots, making them no longer capable of assuring software security.

Traditional SBOMs, signing, and provenance all have blind spots, making them no longer capable of assuring software security.

AI coding requires the stack be reconstructed with mathematical proofs built in — a task well suited to the Lean language. Here’s the reality.

Spectra Detect is now Kubernetes-native. Spectra Analyze adds AI workflows for the agentic SOC. Here's everything that shipped.

Here's how to use Spectra Analyze to hunt for malicious SVGs, from setting up queries and evaluations of samples to tips for investigation.

Traditional SBOMs, signing, and provenance all have blind spots, making them no longer capable of assuring software security.

AI coding requires the stack be reconstructed with mathematical proofs built in — a task well suited to the Lean language. Here’s the reality.

Spectra Detect is now Kubernetes-native. Spectra Analyze adds AI workflows for the agentic SOC. Here's everything that shipped.

Delaying software upgrades creates a buffer against poisoned packages, but transitive dependencies continue to be a problem.

A new report finds weakening trust in AI-only testing — and more willingness to keep humans in the loop. Here's why.

Industry heavyweights bring new focus to vulnerabilities in the age of AI. Here’s how it might help improve security.

SVGs are difficult to detect, can be snuck into content — and can do malicious and legitimate actions. Here's how malicious SVGs work.

One of the most effective attack methods I've analyzed this year runs on legitimate tools and willing users — and AV and EDR is blind to it.

Threat Advisor could help teams with AI-specific risks. But a broader AppSec strategy rethink is needed in the AI era.

New RL research explains why ClickFix attacks are multiplying — and why reliable detection requires going beyond AV and EDR.

The Institute for Security and Technology's 'Driving AI Transparency' policy paper makes the case for AI-BOM minimum requirements.

RL recently discovered active Microsoft 365 device code phishing. Here's a walkthrough of how our researchers found the campaign.

While this repository vector is not new, researchers have uncovered a new twist for exploiting trusted metrics to hide malicious code.

Explore the new Gartner® Magic Quadrant™ for software supply chain security and learn why ReversingLabs is recognized.
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial