Spectra Assure Free Trial
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free TrialWang also provides in-depth analyses of prominent cybersecurity companies, evaluating their strengths, weaknesses, and potential failure modes. Additionally, he explores the future of SIEM (security information and event management) solutions, particularly in light of industry shifts such as the LogRhythm-Exabeam merger and the sale of IBM QRadar, highlighting the necessity for new approaches to security monitoring and analytics in the cloud era.
The Securely Built Substack, curated by Derek Fisher, explores specialized education in application and product security, with an emphasis on software safety. It underscores the need to integrate security into all aspects of technology, from personal device usage and social media interactions to professional productivity applications. Leveraging Fisher's decades of experience in engineering and security, Securely Built aims to support the creation of secure technology and provides resources to help readers improve their security practices.
Notable stories include “SAST Is Dead, Long Live SAST,” which supports the ongoing use of SAST as an essential part of a complete application security strategy but also recognizes its limitations and the necessity of integrating it with other testing methods, and “The Secure Product Lifecycle,” which emphasizes the importance of secure product lifecycle management (SPLM) in managing security risks across various software releases and versions.
The Pragmatic Engineer, a popular Substack newsletter by Gergely Orosz, offers in-depth insights into the software engineering industry, focusing on both big tech companies and high-growth startups. Highly relevant for software engineers and engineering managers, it provides actionable advice and tools to enhance leadership efficiency. The newsletter delivers an insider's perspective on major tech firms and startups, covering topics such as technical debt, distributed systems, and engineering management practices. It features deep dives into specific software engineering subjects, timely articles on industry trends, and reflections on relevant discussions.
Drawing from Orosz' experiences at Uber, Skype, and Microsoft, the newsletter provides a valuable perspective, along with a growing collection of resources, including checklists and guidelines for engineering managers and software engineers.
Walter Haydock, a security researcher and the CEO of StackAware, curates the Deploy Securely newsletter, which focuses on cloud security, DevSecOps, and secure software development practices. It covers topics including cloud security best practices, tools for integrating security into the software development lifecycle, secure coding practices, vulnerability disclosures affecting popular software, and more. The newsletter aims to offer key updates in the rapidly evolving field of cloud security and secure software development.
The Deploy Securely newsletter is as a valuable resource for security professionals, DevOps engineers, and software developers aiming to stay abreast of the latest trends and techniques for building and deploying secure applications in the cloud. By providing insights into emerging threats, best practices, and tools, it empowers its audience to enhance their own security.
The Software Analyst Newsletter, curated by Francis, specializes in analyzing software companies within the cybersecurity and data infrastructure spaces, especially AI and machine learning (ML). It covers a range of notable topics, including in-depth examinations of cybersecurity firms such as Palo Alto Networks, CrowdStrike, and Zscaler, and it explores data infrastructure and AI/ML companies such as Snowflake, Databricks, and C3.ai, evaluating their technologies, use cases, and market potential. The newsletter also offers insights into emerging trends and technologies in cybersecurity and data infrastructure, such as cloud security, zero-trust architecture, and large language models (LLMs), along with featuring interviews and commentary from industry experts and thought leaders in these domains.
The Software Analyst Newsletter caters to investors, technologists, and anyone interested in these rapidly evolving sectors, offering valuable perspectives on market dynamics, technological innovations, and strategic insights that are crucial for navigating and understanding these industries.
For those more interested in software security, check out our Chainmail newsletter on LinkedIn, which highlights the latest AppSec and software supply chain security news.


The annual cybersecurity conference focused on frontier AI agents — and what they mean for cyber. Here are three key takeaways.
Researchers built a worm that reasons about hosts it infects, and the open-weight models powering it sit outside AI-provider safety controls.
While prompt injection and data disclosure remain concerns, excessive agency climbed the list — not surprising with recent security incidents.


