
5 best practices for securing your CI/CD with software bills of materials
SBOMs are essential — but making them useful in CI/CD environments is tricky. Here are 5 key best practices.

SBOMs are essential — but making them useful in CI/CD environments is tricky. Here are 5 key best practices.

The OpenSSF's Secure Supply Chain Consumption Framework can be used to better discover the risks of open-source components — but remediation is left for organizations to figure out later.

Application security veterans Mark Curphey and John Viega went on a CISO listening tour. Here's what they learned.

Extending validity checks is welcome, but secrets risk is bigger than that — and requires a holistic supply chain security approach.

Here's why application programming interface security is critical to risk management — and the advances needed to move API security forward.

NIST's new guidelines are welcome, but some organizations may find it challenging to put them into practice.

NIST's new guidelines are welcome, but some organizations may find it challenging to put them into practice.

Will the Exploit Prediction Scoring System improve application security now — and software supply chain security in the future? Here's what you need to know.

What if dev and app sec teams showed the same ingenuity, nimbleness and ruthless efficiency as cybercriminals? Fastly's Kelly Shortridge explains why that's essential to resilience.

In this episode of ConversingLabs, recorded on the sidelines of Black Hat in Las Vegas, NetRise CEO Thomas Pace talks about supply chain threats to the Internet of Things (IoT).

These leading app sec experts provide a steady flow of security knowledge to keep you up to speed.

In this ConversingLabs, Daniel Woods shares insights from his research on software warranties and discusses how shifting liability to producers could define the market.

Knowledge sharing with cybersecurity experts doesn't have to stop after Hacker Summer Camp wraps up. Follow these top speakers throughout the year.

Welcome to the latest edition of The Week in Security, which brings you the newest headlines from both the world and our team across the full stack of security: application security, cybersecurity, and beyond.

Doing just vulnerability management and piecemeal app sec testing are equivalent to paying only the interest on mounting security technical debt. Where does your organization stand?
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial