GeneralSBOMs Won't Save Your Compliance Program
The Conventional Wisdom Your compliance team needs an SBOM. The EU Cyber Resilience Act demands it. Executive Order 14028 requires it. Every vendor pitch deck promises that generating and managing Sof
Expert perspectives on application security, compliance, and emerging threats
GeneralThe Conventional Wisdom Your compliance team needs an SBOM. The EU Cyber Resilience Act demands it. Executive Order 14028 requires it. Every vendor pitch deck promises that generating and managing Sof
GeneralDebian developers recently voted to encourage, but not require, disclosure of AI assistance in code contributions. The decision was to make disclosure voluntary, with mandatory human review of AI-gene
GeneralYou ve probably heard the predictions: AI will make us abandon human-readable code for machine-optimized languages. We ll all be writing in some new AI-first syntax by 2027. Your investments in Rust a
GeneralThe Conventional Wisdom Your compliance team wants to know if the AI model you re deploying is secure. Your vendor shows you certifications. Your engineers run penetration tests against the model s AP
Get weekly security insights and compliance updates delivered to your inbox.
GeneralIf you re building agentic AI systems, you ve probably considered an MCP Gateway as your security layer. Don t. While the abstraction looks clean on architecture diagrams, it creates more problems tha
GeneralYou re reviewing more pull requests than ever. Your team s throughput has doubled, and you re catching issues you ve never seen before: logic errors that compile cleanly, API calls that look right but
GeneralScope This guide addresses the perception gap between executive leadership and security practitioners on AI system security. It s designed for security engineers who need to: Translate technical AI se
GeneralYour coding agents are writing thousands of lines per week. You re tracking the output in Git. But what about the prompts, skills, and instructions that shape what those agents produce? Most teams tre
GeneralScope This guide focuses on managing the security of transitive dependencies, the indirect libraries your direct dependencies pull in. You ll learn how to identify these hidden components, assess thei
GeneralYour AI coding assistant just suggested a package. It autocompleted the import, generated the integration code, and saved your team 45 minutes. It also pulled in a library that hasn t been updated in
GeneralYour security team might be debating the wrong issue about AI-generated code. The real question isn t whether you need new testing methods for AI-written code versus human-written code. It s whether y
GeneralMost security teams treat secrets rotation as a solved problem. You ve got a vault, set rotation policies, and automated the process. Box checked. But here s the uncomfortable truth: you re spending e
GeneralScope This guide addresses the verification gap created when AI-generated code outpaces your team s ability to test it. If you re seeing commit volumes spike, PRs multiply, or your CI queue backing up
GeneralOmdia s Theresa Lanowitz reports a measurable shift: organizations are accelerating investment in offensive security capabilities, specifically penetration testing and red team tools powered by agenti
GeneralYour team just deployed an AI agent that drafts contracts, schedules meetings, and pulls customer data from three different systems. Someone asks: How does it authenticate? The answer you get back is
GeneralYour AI agents aren t just writing code anymore. They re generating gigabytes of execution traces that your compliance team wants to audit, your debugging team needs to query, and your infrastructure