
8 CI/CD security best practices: Protect your software pipeline
Don't neutralize CI/CD business gains by failing to account for risk. Here are best practices to ensure that your software development pipeline is secure.

Don't neutralize CI/CD business gains by failing to account for risk. Here are best practices to ensure that your software development pipeline is secure.

SLSA and Sigstore are a good first step toward protecting ML models from attack. But they're not a panacea.

Version 1.2.0 of ReversingLabs' TitaniumCloud v2 app for Splunk SOAR adds new actions for network reputation lookups.

SBOMs are essential — but making them useful in CI/CD environments is tricky. Here are 5 key best practices.

ReversingLabs has highlighted threats in npm, PyPI and RubyGEMS in recent years. This finding shows NuGet is equally exposed to malicious activities by threat actors.

The OpenSSF's Secure Supply Chain Consumption Framework can be used to better discover the risks of open-source components — but remediation is left for organizations to figure out later.

Application security veterans Mark Curphey and John Viega went on a CISO listening tour. Here's what they learned.

Extending validity checks is welcome, but secrets risk is bigger than that — and requires a holistic supply chain security approach.

Extending the language's bare-metal use from Linux will make Android a trusted platform — and have a broader impact on the Rust development community.

Here's why application programming interface security is critical to risk management — and the advances needed to move API security forward.

What’s to come for the security of open source software? ConversingLabs caught up with Mikaël Barbero of the Eclipse Foundation to answer that question. Watch (or listen) and learn.

ReversingLabs discovered that one “s” was all that separated a legit npm package from a malicious twin that delivered the r77 rootkit — and was downloaded more than 700 times.

Version 8.3 of RL's A1000 Malware Analysis Platform delivers better visuals, search, and an improved cloud sandbox. Here are all of the updates.

NIST's new guidelines are welcome, but some organizations may find it challenging to put them into practice.

NIST's new guidelines are welcome, but some organizations may find it challenging to put them into practice.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial