
Compromised npm package threatens projects
The eslint-config-prettier package exposed more than 10,000 dependent projects. The incident highlights the growing risks in automated dependency updating.

The eslint-config-prettier package exposed more than 10,000 dependent projects. The incident highlights the growing risks in automated dependency updating.

Researchers at Black Hat discussed how these tools can leave development teams vulnerable to hacks like remote-code execution.

Leading firms are using DevEx to achieve application security gains at speed. Here's how it works — and how to get started.

Application security pros need to be ready to cope with security at the speed of code. Here's how to get a handle on modern software risk.

The new AI Vulnerability Scoring System (AIVSS) picks up where the Common Vulnerability Scoring System (CVSS) falls short.

Policy as Code is emerging as a key area of focus for AppSec teams in the age of cloud-native development. But implementation can be daunting.

The software supply chain incident highlights how quickly threat actors can turn newly revealed vulnerabilities into widespread attacks.

Triaging and patching, plus meeting compliance demands, all bog down modern software teams — and divert time away from development.

Replacing software engineers with AI won't be happening soon — but AI coding is already changing the software risk landscape. Is your company prepared?

AI coding has many attractions, but organizations must have humans in the loop to keep good software risk management vibes flowing.

In this product release highlight, ReversingLabs is proud to announce new features for Spectra Analyze (formerly A1000).

Spectra Assure Community empowers VS Code users to verify an extension’s level of risk before trusting it to run with privileged system access.

ETHcode, a VS Code extension for Ethereum smart contract development, was compromised following a GitHub pull request.

3CX has transformed its software security in the two years since a damaging compromise — and RL was there to help. Here are key takeaways.

The Latio AI Security Report highlights how marketing hype is creating confusion — and hurting security outcomes. Here are the top takeaways.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial