 | AI domain takeover takeaway: Focus on the harness not the model | 2026-08-06 | True | John P. Mello Jr. | True | | |
 | How to Leverage Spectra Analyze's Search for SVG Analysis | 2026-08-05 | True | Zaria Vuksan | True | | |
 | Hidden in plain sight: How SVGs carry malicious scripts | 2026-07-21 | True | Zaria Vuksan | True | | |
 | ClickFix doesn't attack your knowledge. It attacks your trust. | 2026-07-16 | True | Toni Dujmović | True | | |
 | The tale of ClickFix: 5 takeaways from RL’s new threat report | 2026-07-14 | True | Paul Roberts | True | | |
 | AI-BOM minimum elements proposal builds on SBOM lessons | 2026-07-09 | True | Ericka Chickowski | True | | |
 | Spectra Analyze in Action: Hunting Device Code Phishing Pages | 2026-07-08 | True | RL Research Team | True | | |
 | ‘Download pumping’ joins the trust-abuse bandwagon | 2026-07-07 | True | John P. Mello Jr. | True | | |
 | Should frontier AI firms fund OSS ecosystem security? | 2026-06-24 | True | Jaikumar Vijayan | True | | |
 | npm v12 blocks install scripts: What it means for software security | 2026-06-16 | True | John P. Mello Jr. | True | | |
 | Device code phishing bypasses password stealing | 2026-06-12 | True | Robert Simmons | True | | |
 | How to defend ARM64 cloud infrastructure from ITScape | 2026-06-11 | True | Robert Simmons | True | | |
 | Phishing Attacks Leverage TikTok, Instagram Reels | 2026-06-09 | True | Zaria Vuksan | True | | |
 | How 56 npm packages used binding.gyp to steal CI/CD secrets | 2026-06-04 | True | RL Research Team | True | | |
 | CVE Lite CLI closes dependency gap — but won't stop modern threats | 2026-06-04 | True | John P. Mello Jr. | True | | |
 | Get ahead of frontier AI: 5 AppSec strategy upgrades | 2026-06-03 | True | Ericka Chickowski | True | | |
 | CVE noise drowns out supply chain threats | 2026-06-02 | True | John P. Mello Jr. | True | | |
 | 31 Red Hat npm packages backdoored in 72 seconds | 2026-06-01 | True | RL Research Team | True | | |
 | Forrester Names RL in Agentic Development Security Market | 2026-05-28 | True | Jasmine Noel | True | | |
 | Researcher's Notebook: Hunting Megalodon Fossils | 2026-05-26 | True | Robert Simmons | True | | |
 | Dependency attack takes down ed-tech platform at scale | 2026-05-26 | True | Ericka Chickowski | True | | |
 | GitHub breach: The development ecosystem is in the hot seat | 2026-05-22 | True | John P. Mello Jr. | True | | |
 | Parental Control Flaw Allows Google Account Hacks | 2026-05-19 | True | Zaria Vuksan | True | | |
 | Shai-Hulud code drop: It’s open season | 2026-05-15 | True | Jaikumar Vijayan | True | | |
 | Mini Shai-Hulud tears at OSS trust | 2026-05-12 | True | Paul Roberts | True | | |
 | How Dirty Frag rose from the Copy Fail exploit | 2026-05-12 | True | Igor Lasic | True | | |
 | Selective NVD enrichment: Why it matters | 2026-05-07 | True | John P. Mello Jr. | True | | |
 | Spectra Analyze in Action: Retrohunting Bots | 2026-05-06 | True | Zaria Vuksan | True | | |
 | 'Copy Fail' Flaw: 5 YARA Rules for Detection | 2026-05-01 | True | Maik Morgenstern | True | | |
 | MCP rug-pull attack worries mount | 2026-04-29 | True | John P. Mello Jr. | True | | |
 | Claude adds malware to crypto agent | 2026-04-29 | True | Vladimir Pezo | True | | |
 | LLMmap puts its finger on ML attacks | 2026-04-22 | True | John P. Mello Jr. | True | | |
 | QR Code Phishing Evolves: How to Keep Up | 2026-04-21 | True | Igor Lasic | True | | |
 | Vibeware: More than bad vibes for AppSec | 2026-04-16 | True | John P. Mello Jr. | True | | |
 | Graphalgo fake recruiter campaign returns | 2026-04-09 | True | Karlo Zanki | True | | |
 | Claude Mythos: Get your AppSec game on | 2026-04-08 | True | Ericka Chickowski | True | | |
 | 28 application security stats that matter | 2026-04-07 | True | Jaikumar Vijayan | True | | |
 | Axios: How AppSec teams should respond | 2026-04-02 | True | Paul Roberts | True | | |
 | ClickFix: YARA Rules Catch What AV Misses | 2026-04-02 | True | Toni Dujmović | True | | |
 | GenAI Security Project ramps up guidance | 2026-03-31 | True | John P. Mello Jr. | True | | |
 | AppSec as attacker: Inside Trivy–LiteLLM | 2026-03-27 | True | Igor Lasic | True | | |
 | The TeamPCP supply chain attack evolves | 2026-03-27 | True | Paul Roberts | True | | |
 | How AI agents can weaponize IDEs | 2026-03-25 | True | John P. Mello Jr. | True | | |
 | Fake install logs in npm packages load RAT | 2026-03-24 | True | Lucija Valentić | True | | |
 | OpenClaw lesson: AI agents are a black hole | 2026-03-18 | True | Ericka Chickowski | True | | |
 | How to Examine Polyglot Files with Spectra Analyze | 2026-03-17 | True | Josh Morin | True | | |
 | OpenClaw and AI risk: 3 AppSec lessons | 2026-03-10 | True | Ericka Chickowski | True | | |
 | Inside the NuGet hackers' toolset | 2026-02-26 | True | Petar Kirhmajer | True | | |
 | Malicious NuGet package targets Stripe | 2026-02-25 | True | Petar Kirhmajer | True | | |
 | How to Use YARA Retrohunting for Defense | 2026-02-18 | True | Ashlee Benge | True | | |