
How supply chain security tools can protect ML models
SLSA and Sigstore are a good first step toward protecting ML models from attack. But they're not a panacea.

Freelance technology writer. John's work has appeared in the The Boston Globe and Boston Herald, as well as CFO, CIO, CSO, and Inc. magazines. He is a former managing editor of the Boston Business Journal and Boston Phoenix, as well as a staff writer for Government Security News.
find John P. Mello Jr. on:

SLSA and Sigstore are a good first step toward protecting ML models from attack. But they're not a panacea.

Extending validity checks is welcome, but secrets risk is bigger than that — and requires a holistic supply chain security approach.

Extending the language's bare-metal use from Linux will make Android a trusted platform — and have a broader impact on the Rust development community.

Here's why application programming interface security is critical to risk management — and the advances needed to move API security forward.

NIST's new guidelines are welcome, but some organizations may find it challenging to put them into practice.

NIST's new guidelines are welcome, but some organizations may find it challenging to put them into practice.

Will the Exploit Prediction Scoring System improve application security now — and software supply chain security in the future? Here's what you need to know.

"Shift left" is giving way to up-front software risk assessments, and companies are increasingly tapping external support for third-party compliance. Learn more from application security peers.

These leading app sec experts provide a steady flow of security knowledge to keep you up to speed.
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial