
OWASP Top 10 for LLM adds risks: Get on target to secure your AI models
OWASP has updated its Top 10 list with key risk areas, and recently added an AppSec tooling guide for AI. Here's what they cover — and what they don't.

OWASP has updated its Top 10 list with key risk areas, and recently added an AppSec tooling guide for AI. Here's what they cover — and what they don't.

To avoid the next CrowdStrike fiasco, CISA and other agencies recommend embracing safe deployment practices earlier in the SDLC. Here's what you need to know.

Here's why and how to push your application security further into ProdSec — and what that means to achieving the goals of CISA's Secure by Design.
.webp&w=3840&q=75)
Researcher Alon Leviev warns that the Microsoft Windows compromise posed risks that were structural — stretching well beyond the specific flaws.

Here's what you need to know about connected car security initiatives — and key lessons more broadly from software supply chain security's rough ride.

Operationalizing Third-Party Software Risk Management with Spectra Assure

A multilayered approach to prevent secrets exposure is good strategy — but it must include a final check on all software before it goes out the door.

Here's what you need to know about the version 4.12.0 update — and about managing risk from your software, whether it's open source or not.

Chris Romeo shares five key ways to merge modeling with modern software supply chain security — and improve your software risk management in the process.

Chris Romeo shares five key ways to merge modeling with modern software supply chain security — and improve your software risk management in the process.

Don't just roll the dice with commercial software risk. Here are key lessons from recent attacks for your security team.

With the threat landscape shifting, boosting your market value requires choosing the right certs. Here's what you need to know.

When developing software there are three options: good, fast, and cheap. But you can only pick two. Here's what that reality means for commercial software risk.

By leveraging modern supply chain security, you can develop better chaos engineering with deeper visibility into all software. Here are key considerations.

The Cybersecurity and Infrastructure Security Agency held its semiannual workshop on software bills of materials recently. Here's what you need to know.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial