
Fake install logs in npm packages load RAT
The final-stage malware in the Ghost campaign is a RAT designed to steal crypto wallets and sensitive data.

The final-stage malware in the Ghost campaign is a RAT designed to steal crypto wallets and sensitive data.

The compromise of Checkmarx Open VSX plugins on npm has now spread to PyPI and LiteLLM.

AI agents create novel attack surfaces and control issues that require rethinking assumptions — and AppSec tooling.

The compromise of Checkmarx Open VSX plugins on npm has now spread to PyPI and LiteLLM.

The final-stage malware in the Ghost campaign is a RAT designed to steal crypto wallets and sensitive data.

Here’s a look at the Ethereum Foundation’s new PQC security effort — and why you need to modernize your SecOps.

AI agents create novel attack surfaces and control issues that require rethinking assumptions — and AppSec tooling.

Here's how to assess a sample using Spectra Analyze in your environment — and create a YARA rule.

Learn how Package URLs improve vulnerability matching, which reduces alert fatigue and simplifies compliance.

OWASP has adopted the container security tool to slow information overload. Here’s what you need to know.

The OpenClaw saga is a case study on the threat from agentic AI, showing how it increases software risk.

The new tool is a step forward on AI coding risk — but it trips on modern threats because it looks only at source code.

AI coding is a game-changer — and requires AI-powered application security to fight fire with fire.

AI coding is the new reality — and it will further destabilize software supply chain security. So step up your AppSec.

RL discovered two packages containing scripts that complete a typosquatting toolchain. Here's how it worked.

Threat actors targeted developers with a bogus package — a shift away from the recent crypto development hack focus.

Here’s what you need to know about their impact on software security — and what you can do to fight back.

With AI-powered tools readily available, sophisticated attacks no longer require sophisticated attackers.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial