
Device code phishing bypasses password stealing
The Microsoft 365 phishing campaign persuades victims to complete a real authentication process that authorizes an attacker-controlled device.

The Microsoft 365 phishing campaign persuades victims to complete a real authentication process that authorizes an attacker-controlled device.

RL has documented CVE-2026-46316, and developed two YARA rules to help detect exploits of the multi-tenant cloud vulnerability.

The standard connecting AI agents to tools and data leaves security to others. Make it a do-over.

The Microsoft 365 phishing campaign persuades victims to complete a real authentication process that authorizes an attacker-controlled device.

RL has documented CVE-2026-46316, and developed two YARA rules to help detect exploits of the multi-tenant cloud vulnerability.

The standard connecting AI agents to tools and data leaves security to others. Make it a do-over.

Agentic AI will disrupt how SOC teams are built — and the way CISOs hire. Here’s how to embrace AI.

RL has discovered two social engineering attack techniques targeting users via short-form videos. Here’s how they work.

The attack is notable for its breadth, flooding npm with malicious package versions.

OWASP's new dependency scanner gives developers actionable fixes. But supply chain attacks aren’t yet CVEs.

Frontier AI is collapsing the time from vulnerability discovery to exploit. Here are 5 ways to update your AppSec before it hits.

48,000 CVEs were reported in 2025 — but just 58 were critical. A new report highlights why signal-to-noise ratio matters for AppSec.

RL has discovered a new supply chain attack affecting 9.8M total downloads across Red Hat's Hybrid Cloud Console JavaScript ecosystem.

The new landscape report maps 35 vendors addressing an emerging category of risk: AI agents writing insecure code at machine speed.

VM success is determined by findings reaching developers with context — which is getting more challenging. Here's why to shift gears.

The Canvas LMS supply chain compromise — which hit during finals week — shows the impact of cascading attacks.

Analyzing C2 responses from compromised GitHub Actions linked a current threat to an earlier one, showing the value of retrohunting.

This TeamPCP attack is a serious wakeup call about software supply chain security — and the problems with implicit trust.
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial