
Why knowing the "ground truth" is key to software security
Software bills of materials (SBOMs) deliver a ground truth for software teams. Here's how they can protect their supply chains.

Software bills of materials (SBOMs) deliver a ground truth for software teams. Here's how they can protect their supply chains.

Welcome to the latest edition of The Week in Security, which brings you the newest headlines from both the world and our team across the full stack of security: application security, cybersecurity, and beyond.

Supply chain risk management guidance incoming, like it or not

Here's how risks emerge with third-party software, and why third-party partners are best for validating software security end-to-end

Firing ‘the best of the best’ does not bode well for software security. Will the last to leave please turn off the lights?

Software Bills of Materials could become Software Bills of Mediocrity. But not if we can agree on their real value for software supply chain security.

It’s super easy to spoof Visual Studio Code extensions. And those spoofed extensions are incredibly hard to detect.

ChatGPT and Copilot are a clear and present danger to software security. Modernize your AppSec approach today

Welcome to the latest edition of The Week in Security, which brings you the newest headlines from both the world and our team across the full stack of security: application security, cybersecurity, and beyond.

Get out in front of new compliance requirements for a competitive advantage. Here's what your software organization needs to know.

Security teams should consider software supply chain risk through a new lens after the latest CircleCI incident.
Application security is foundational to the software supply chain security ecosystem. But it takes a village. Derek Fisher explains in this fireside chat with Matt Rose.

The JsonWebToken library has a flaw that could have lead to remote code execution (RCE).

Researchers compromised source code and development infrastructure for Mercedes-Benz and SiriusXM Connected Vehicle Services, raising security concerns.

In this latest attack on software development environments, the CircleCI platform may have exposed secrets used by millions of software developers.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial