
OWASP Top 10 for LLM Applications: Can AI risk be tamed?
OWASP is expanding its Top 10 series with a list of large language model vulnerabilities. Here's what AppSec teams need to know.

OWASP is expanding its Top 10 series with a list of large language model vulnerabilities. Here's what AppSec teams need to know.

CISA hosted SBOM-a-rama on Wednesday to move software bills of material — a list of ingredients for software and services — forward. Here are top takeaways and insights.

ConversingLabs caught up with Srinivasan to discuss how OpenSSF's Security Scorecard can aid developers in assessing open source software components for their projects.

Bad actors are finding secrets across the supply chain. Here are the key attack methods — and what's needed to prevent them.

Cl0p quietly tested the flaw for two years before launching the full exploit. Lesson: Look both ways before crossing.

Software vendors that do business with the government must prove they are practicing basic supply chain security. Here's a rundown on the requirements.

Firmware attacks can pose a substantial risk to the software supply chain. Here's what your software security team can learn from the latest compromise.

Welcome to the latest edition of The Week in Security, which brings you the newest headlines from both the world and our team across the full stack of security: application security, cybersecurity, and beyond.

ReversingLabs Field CISO Matt Rose explains the difference between application security hacks and software supply chain hacks.

Compiled-code behavior analysis beats old-skool app sec tools.

ConversingLabs caught up with Chris Romeo of Kerr Ventures at RSA Conference 2023 to talk about the state of application security. Watch (or listen) — and learn.

Nvidia's tool is among the first to promise to manage the risk from generative AI. Here's what it can do — and an analysis of the scope of risk from AI.

In a recent survey, 300 IT and software pros were asked about the state of software supply chain security. Here are takeaways from a webinar discussion.

John Jackson and his Sakura Samurai crew took India up on an invitation to test the security of government websites and apps. Here are the lessons learned.

The Python repo was flooded with malicious typo-squatting packages. Weekend warriors quit defense and hit pause.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial