
MCP is a powerful new AI coding technology: Understand the risks
Model Context Protocol makes agentic AI development easier by connecting data sources — but the risks are very real. Here's what you need to know.

Model Context Protocol makes agentic AI development easier by connecting data sources — but the risks are very real. Here's what you need to know.

Malicious instructions buried in LLM sources such as documents can poison ML models. Here's how it works — and how to protect your AI systems.

The rapid rise of SaaS apps has spawned new risks. One new hopeful stands out: The SaaSBOM. Here are key steps that help rein them in.

The sequential Monte Carlo method guides LLMs to produce code that plays by basic programming rules. Here's what you need to know.

Without modern application security tooling, including binary analysis, the third-party risk management puzzle is incomplete.

Leaks from GitHub and other repos are up, but collaboration tools such as Slack and Jira are now a major threat — and a serious blind spot.

CycloneDX 1.6's ML-BOM, SaaSBOM, and CBOM are non-negotiable visibility requirements in the software supply chain security era.

The latest Data Breach Investigations Report puts the focus squarely on third-party risk. Here’s what you need to know.

The CVE's challenges mean it's time to get off the vulnerability hamster wheel and modernize your risk program.

ML attacks are evolving, putting mitigation a step behind. Here’s what to focus on — and why traditional AppSec tooling is not up to the job.

While the state of cybersecurity careers is confusing, key trends are driving companies to think big-picture — and outside of traditional roles.

Quantum random number generators can make software — including software development secrets — more secure. Here's how it works.

Vibe coding — AI coding using prompt engineering — is making application security more challenging. Here's what you need to know.

Software supply chain risks from artificial intelligence and machine learning are getting real. Here are key insights from RL’s new report.

More cracks in the NVD emerge, making the CVE system less useful. Shift your approach to keep up with software risk.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial