
How AWS averted an AI coding supply chain disaster
Here are six lessons learned from the near-miss that was the Amazon Q Developer incident. Don't let luck be your security strategy.
Read More about How AWS averted an AI coding supply chain disasterHere are six lessons learned from the near-miss that was the Amazon Q Developer incident. Don't let luck be your security strategy.
Read More about How AWS averted an AI coding supply chain disasterIntegrated security in AI assistants could help to catch code flaws — but they are only one layer in a comprehensive AppSec strategy.
Read More about AI coding tools gain security — but the controls do not cut itScott Culp’s formulation still holds true — though some additions are needed that account for software supply chain security.
Read More about ‘The Immutable Laws of Security’ at 25: 5 corollaries for a new eraHere's how to integrate AI-specific risks into your existing security incident response (IR) playbook.
Read More about OWASP GenAI Incident Response Guide 1.0: How to put it to workApplication security pros need to be ready to cope with security at the speed of code. Here's how to get a handle on modern software risk.
Read More about The state of development: 5 AppSec action itemsThe new AI Vulnerability Scoring System (AIVSS) picks up where the Common Vulnerability Scoring System (CVSS) falls short.
Read More about OWASP AIVSS targets agentic AI riskPolicy as Code is emerging as a key area of focus for AppSec teams in the age of cloud-native development. But implementation can be daunting.
Read More about How to implement PaC for a more secure SDLCThe software supply chain incident highlights how quickly threat actors can turn newly revealed vulnerabilities into widespread attacks.
Read More about SharePoint zero-day: What we knowTriaging and patching, plus meeting compliance demands, all bog down modern software teams — and divert time away from development.
Read More about The true cost of CVEs: Go beyond vulnerabilitiesReplacing software engineers with AI won't be happening soon — but AI coding is already changing the software risk landscape. Is your company prepared?
Read More about Autonomous dev is coming: Is your AppSec ready?AI coding has many attractions, but organizations must have humans in the loop to keep good software risk management vibes flowing.
Read More about Vibe coding is seductive — and a serious riskThe Latio AI Security Report highlights how marketing hype is creating confusion — and hurting security outcomes. Here are the top takeaways.
Read More about AI security tools and hype: Report breaks down key considerationsEU steps up to fill gaps from the US NVD and CVE. Here's what you need to know — and why you need to think beyond vulnerabilities.
Read More about Europe's EUVD could shake up the vulnerability database ecosystemAgentic AI is a different animal for application security red teams. Here are key takeaways from the Cloud Security Alliance's new guide.
Read More about Red-teaming agentic AI: New guide lays out key concerns for AppSecLearn how third-party software risk management (TPSRM) builds on TPRM and TPCRM to protect against software-based threats.
Read More about TPSRM: What It Is — And Why It MattersGet your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial