
Will npm's new security steps stop attacks?
While 2FA and trusted publishing help, you need visibility into how packages behave — not just who is publishing.

Freelance technology journalist. A former Senior Editor of Computerworld, Jai is a journalist and technology content writing specialist, with 20+ years of award-winning experience in IT trade journalism. He is a correspondent for the Christian Science Monitor and a contributor to Dark Reading, eWEEK, Datamation, IBM Security Intelligence, and Third Certainty. He writes features and covers breaking news stories on information security, data privacy, and big data/business analytics. His recent projects include ERP case studies and an e-book on enterprise mobility management best practices.
find Jaikumar Vijayan on:

While 2FA and trusted publishing help, you need visibility into how packages behave — not just who is publishing.

Funding of the OSS ecosystem has reached a crisis as threat actors increasingly target weaknesses in infrastructure.

While security defenders welcomed the new vulnerability-validation tool, others stress it can be just as useful for would-be attackers.

The new guidance would raise the bar for software vendors, who will need to ensure the SBOMs they generate are more detailed and machine-readable.

With attacks on popular repositories on the rise, PyPI has moved to head off a common technique for duping developers. Here’s what it accomplishes — and where there’s room for improvement.

Integrated security in AI assistants could help to catch code flaws — but they are only one layer in a comprehensive AppSec strategy.

Policy as Code is emerging as a key area of focus for AppSec teams in the age of cloud-native development. But implementation can be daunting.

The Latio AI Security Report highlights how marketing hype is creating confusion — and hurting security outcomes. Here are the top takeaways.

JPMorganChase's Pat Opet has raised a red flag. Learn why — and how SaaSBOMs can help your organization get a handle on risk.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial