
The AI executive order: What AppSec teams need to know
While the new White House EO is largely focused on foundational AI, security teams reviewing AI initiatives are still in the hot seat.

While the new White House EO is largely focused on foundational AI, security teams reviewing AI initiatives are still in the hot seat.

Streamlining Software Supply Chain Security: ReversingLabs Now Accessible via AWS Marketplace

Ingrained development patterns and legacy testing tools are holdovers from a reactive era of AppSec. Here's how how to move software security forward.

Rather than wasting cycles on non-exploitable or remediated security holes, teams should focus on exploitability, and look for compromises including malware and tampering. Here's why.

ReversingLabs researchers have discovered npm packages that hide scripts broadcasting messages of peace related to the conflicts in Ukraine and in Israel and the Gaza Strip.

Zero trust can benefit threat modeling, so why not extend it to your AppSec? Understand the key benefits and challenges.

Don't neutralize CI/CD business gains by failing to account for risk. Here are best practices to ensure that your software development pipeline is secure.

SLSA and Sigstore are a good first step toward protecting ML models from attack. But they're not a panacea.

Version 1.2.0 of ReversingLabs' TitaniumCloud v2 app for Splunk SOAR adds new actions for network reputation lookups.

SBOMs are essential — but making them useful in CI/CD environments is tricky. Here are 5 key best practices.

ReversingLabs has highlighted threats in npm, PyPI and RubyGEMS in recent years. This finding shows NuGet is equally exposed to malicious activities by threat actors.

The OpenSSF's Secure Supply Chain Consumption Framework can be used to better discover the risks of open-source components — but remediation is left for organizations to figure out later.

Application security veterans Mark Curphey and John Viega went on a CISO listening tour. Here's what they learned.

Extending validity checks is welcome, but secrets risk is bigger than that — and requires a holistic supply chain security approach.

Extending the language's bare-metal use from Linux will make Android a trusted platform — and have a broader impact on the Rust development community.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial