
C-SCRM: We’re from the government — and we’re here to help with software supply chain security
Supply chain risk management guidance incoming, like it or not

Supply chain risk management guidance incoming, like it or not

Here's how risks emerge with third-party software, and why third-party partners are best for validating software security end-to-end

Firing ‘the best of the best’ does not bode well for software security. Will the last to leave please turn off the lights?

Software Bills of Materials could become Software Bills of Mediocrity. But not if we can agree on their real value for software supply chain security.

It’s super easy to spoof Visual Studio Code extensions. And those spoofed extensions are incredibly hard to detect.

ChatGPT and Copilot are a clear and present danger to software security. Modernize your AppSec approach today

Welcome to the latest edition of The Week in Security, which brings you the newest headlines from both the world and our team across the full stack of security: application security, cybersecurity, and beyond.

Get out in front of new compliance requirements for a competitive advantage. Here's what your software organization needs to know.

Security teams should consider software supply chain risk through a new lens after the latest CircleCI incident.
Application security is foundational to the software supply chain security ecosystem. But it takes a village. Derek Fisher explains in this fireside chat with Matt Rose.

The JsonWebToken library has a flaw that could have lead to remote code execution (RCE).

Researchers compromised source code and development infrastructure for Mercedes-Benz and SiriusXM Connected Vehicle Services, raising security concerns.

In this latest attack on software development environments, the CircleCI platform may have exposed secrets used by millions of software developers.
.webp&w=3840&q=75)
A classic dependency confusion attack revealed itself last week.

Supply chain attacks are surging — and no one is immune. That has CISOs and boards worried. Learn from these notable software supply chain attacks.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial