
CISA tool aims to boost security for software onboarding
The new procurement tool seeks to strengthen third-party software risk management (TPSRM). But the process is manual and cumbersome.

Freelance technology writer. John's work has appeared in the The Boston Globe and Boston Herald, as well as CFO, CIO, CSO, and Inc. magazines. He is a former managing editor of the Boston Business Journal and Boston Phoenix, as well as a staff writer for Government Security News.
find John P. Mello Jr. on:

The new procurement tool seeks to strengthen third-party software risk management (TPSRM). But the process is manual and cumbersome.

The new procurement tool seeks to strengthen third-party software risk management (TPSRM). But the process is manual and cumbersome.

ESET researchers have discovered malware that taps into OpenAI’s large language model to assist in ransomware attacks.

Here are six lessons learned from the near-miss that was the Amazon Q Developer incident. Don't let luck be your security strategy.

Here's how to integrate AI-specific risks into your existing security incident response (IR) playbook.

Application security pros need to be ready to cope with security at the speed of code. Here's how to get a handle on modern software risk.

The new AI Vulnerability Scoring System (AIVSS) picks up where the Common Vulnerability Scoring System (CVSS) falls short.

Triaging and patching, plus meeting compliance demands, all bog down modern software teams — and divert time away from development.

Replacing software engineers with AI won't be happening soon — but AI coding is already changing the software risk landscape. Is your company prepared?
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial