
Dependency attack takes down ed-tech platform at scale
The Canvas LMS supply chain compromise — which hit during finals week — shows the impact of cascading attacks.

The Canvas LMS supply chain compromise — which hit during finals week — shows the impact of cascading attacks.

This TeamPCP attack is a serious wakeup call about software supply chain security — and the problems with implicit trust.

AI security leader and author Steve Wilson explains why you need to rethink security — and treat AI agents as digital workers.

The npm malware's public release provides a ready-made blueprint for threat actors. Take action on supply chain security.

To manage agentic AI risk, organizations need to focus more on the infrastructure they run on.

This latest compromises of popular and infrastructure-level npm packages are rocking the foundations open source.

AI vulnerability reporting is overwhelming teams — and NIST. But for AppSec, scaling back analysis is cause for alarm.

Here are the facts on Claude Mythos — and why a layered application security framework is essential.

As AppSec shifts focus from the components to data, your strategy needs updating. Are you on top of your trust debt?

This new class of AI tool supply chain attack highlights how trust of agents can be exploited.

AI lets software teams generate code at a rate faster than security can validate it. One way to win the race: more AI.

Researchers show how LLM fingerprinting can be used to automate generation of customized attacks.

Threat actors are leveraging the freewheeling vibe-coding trend to deliver malicious software at scale.

Here's how the EU's Cyber Resilience Act will reshape the software industry — and how that accelerates advantages.

Anthropic's new AI is a 'step change' for exposing software flaws — but also ramps up exploits. Are you ready?
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial