
The race to secure AI coding: 4 steps to rein agents in
Coding agents are privileged insiders — with keys to CI/CD pipelines even as they give rise to ‘slopsquatting.’ Here’s how to govern them.

Coding agents are privileged insiders — with keys to CI/CD pipelines even as they give rise to ‘slopsquatting.’ Here’s how to govern them.

Disabling scripts by default closes the vector worms like Shai-Hulud rely on. Here's what the update fixes — and what it doesn't.

The standard connecting AI agents to tools and data leaves security to others. Make it a do-over.

OWASP's new dependency scanner gives developers actionable fixes. But supply chain attacks aren’t yet CVEs.

Frontier AI is collapsing the time from vulnerability discovery to exploit. Here are 5 ways to update your AppSec before it hits.

48,000 CVEs were reported in 2025 — but just 58 were critical. A new report highlights why signal-to-noise ratio matters for AppSec.

VM success is determined by findings reaching developers with context — which is getting more challenging. Here's why to shift gears.

The Canvas LMS supply chain compromise — which hit during finals week — shows the impact of cascading attacks.

This TeamPCP attack is a serious wakeup call about software supply chain security — and the problems with implicit trust.

AI security leader and author Steve Wilson explains why you need to rethink security — and treat AI agents as digital workers.

The npm malware's public release provides a ready-made blueprint for threat actors. Take action on supply chain security.

To manage agentic AI risk, organizations need to focus more on the infrastructure they run on.

This latest compromises of popular and infrastructure-level npm packages are rocking the foundations open source.

AI vulnerability reporting is overwhelming teams — and NIST. But for AppSec, scaling back analysis is cause for alarm.

Here are the facts on Claude Mythos — and why a layered application security framework is essential.
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial