
BSIMM16 confirms: AI redefines AppSec
AI coding is the new reality — and it will further destabilize software supply chain security. So step up your AppSec.

Freelance technology writer. John's work has appeared in the The Boston Globe and Boston Herald, as well as CFO, CIO, CSO, and Inc. magazines. He is a former managing editor of the Boston Business Journal and Boston Phoenix, as well as a staff writer for Government Security News.
find John P. Mello Jr. on:

AI coding is the new reality — and it will further destabilize software supply chain security. So step up your AppSec.

The Vulnerable MCP Servers Lab delivers integration training, demos, and instruction on attack methods.

AI tools are making Rust a favorite language of developers — even those maintaining codebases like Microsoft’s.

NIST has broadened the Secure Software Development Framework to include the full SDLC. Here’s why it matters.

The EU’s Cyber Resilience Act legally obliges software producers to create and maintain an SBOM. Are you prepared?

A new CSA report stresses getting out in front of AI risk — and why it matters for SecOps.

Researchers explain that as threat actors move to AI-enabled malware in active operations, existing defenses will fail.

AI platforms exacerbate existing security risks. Here’s what you need to know to stay out of technical debt.

The Open Worldwide Application Security Project now includes an Agentic Top 10, an AI testing guide, and an AI vulnerability scoring tool.
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial