Independent intelligence for application security and software supply chain.
Daily reporting on supply chain attacks, security vendor moves, and standards changes that matter to engineers and compliance teams.
Featured coverage
Breach & incident coverage
Coverage of real breaches with response timelines and disclosure links. Recent reporting includes attacks on the npm ecosystem, popular CLI tools, IDE extensions, and major SaaS infrastructure.
Standards & frameworks
NIST guidance, OWASP frameworks, CISA advisories, EU regulatory updates, and the standards work that affects how production teams build and ship.
Vendor directory
Application security and software supply chain vendors organized by capability: SAST, DAST, SCA, SBOM management, secrets scanning, ASPM, CI/CD security, and API testing.
Glossary & reference
Definitions in plain English covering application security, software supply chain, vulnerability management, AI security, identity, threat modeling, and DevSecOps.
Latest Articles
Browse all 1455 articlesTerm of the Day
Browse all 248 termsAttribute-Based Access Control
Attribute-Based Access Control is a method of managing who can access what by evaluating characteristics (attributes) of the person requesting access, the resource being accessed, and the context of the request. Instead of assigning permissions based on fixed roles, it uses flexible rules that can consider many factors at once, such as a user's department, the sensitivity level of a resource, or the time of day. This makes it more adaptable than simpler access control models.
Read full definitionVendor Directory Spotlight
Browse all 152 vendors
CrowdStrike
Defend Your Digital World with Precision
CrowdStrike is a global cybersecurity leader with an advanced cloud-native platform designed to protect endpoints, cloud workloads, identities, and data. Their Application Security Posture Management (ASPM) offering allows organizations to prevent unauthorized access and detect malicious activities across various devices. With tailored bundles available for different industries and sizes, CrowdStrike ensures robust protection against malware, ransomware, and sophisticated threats while providing visibility and control for safe usage of removable media devices. Their expertise extends into the cyber insurance sector, reinforcing their commitment to comprehensive cybersecurity solutions.

ARMUR
Secure your code, safeguard your future
Armur AI offers advanced code vulnerability scanning, specializing in Static Application Security Testing (SAST) and smart contract auditing using LLM agents. The platform supports multiple programming languages including GO, Rust, JavaScript, and Python, enabling thorough static code analysis to identify vulnerabilities early in the development process. Additionally, Armur provides tools for auditing Solidity smart contracts and other blockchain contracts, ensuring robust security measures for decentralized applications. With features like Dynamic Application Security Testing (DAST) and Vulnerability Assessment and Penetration Testing (VAPT), Armur empowers developers and security professionals to secure their code effectively before deployment.

Security Compass
Modeling Threats, Building Secure Futures
Security Compass offers threat modeling and secure development solutions. The site highlights threat modeling, “implementation-ready requirements for developers and agents,” and “secure development training,” positioned to “design compliant software” and aligned to “evolving AI and security standards.” The company notes the acquisition of Devici, a threat modeling platform, and promotes a Partner Portal and consultation options. Pricing language indicates “Pricing is in USD” with volume-based discounts and an invitation to “Contact us for a consultation.” The site also encourages subscription to a monthly Security Digest newsletter. Beyond platform capabilities, Security Compass presents training and partner/consultation channels for customers seeking secure development and application-security practices.
Featured Resources
Browse all 7 resourcesOWASP API Security Top 10 - Free Practical Guide
Download the free 17-page guide to the OWASP API Security Top 10. Learn each API risk, how attackers exploit it, and the controls that stop them.


