
Shai-Hulud code drop: It’s open season for attacks
The npm malware's public release provides a ready-made blueprint for threat actors. Take action on supply chain security.

Freelance technology journalist. A former Senior Editor of Computerworld, Jai is a journalist and technology content writing specialist, with 20+ years of award-winning experience in IT trade journalism. He is a correspondent for the Christian Science Monitor and a contributor to Dark Reading, eWEEK, Datamation, IBM Security Intelligence, and Third Certainty. He writes features and covers breaking news stories on information security, data privacy, and big data/business analytics. His recent projects include ERP case studies and an e-book on enterprise mobility management best practices.
find Jaikumar Vijayan on:

The npm malware's public release provides a ready-made blueprint for threat actors. Take action on supply chain security.

To manage agentic AI risk, organizations need to focus more on the infrastructure they run on.

AI lets software teams generate code at a rate faster than security can validate it. One way to win the race: more AI.

AI and open source are redefining the software threat landscape. Here are the key statistics you need to know.

The new tool is a step forward on AI coding risk — but it trips on modern threats because it looks only at source code.

Here’s what you need to know about their impact on software security — and what you can do to fight back.

With AI-powered tools readily available, sophisticated attacks no longer require sophisticated attackers.

Here’s what the $1.5M investment in the Python Software Foundation will mean for AI coding and open-source security.

Trigger.dev's experience shows that you need modern controls to combat today's supply chain attacks.
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial