All About RAG: What It Is and How to Keep It Secure
Learn about retrieval-augmented generation, one complex AI system that developers are using.
Next-Gen Vulnerability Assessment: AWS Bedrock Claude in CVE Data Classification
Learn more about how organizations can use open source software to innovate while minimizing risk.
A Guide to Open Source Software
SAST – All About Static Application Security Testing
Learn about Static Application Security Testing (SAST). Understand the importance, benefits, & how to choose the right SAST tool for your org.
Hallucinated Packages, Malicious AI Models, and Insecure AI-Generated Code
Worried about attackers using AI models to write malicious code? Here are three other ways AI model use can lead to attacks.
Quick Guide to Popular AI Licenses
Not all “open” AI licenses are truly open source. Learn more about the most popular licenses on Hugging Face.
NVD Update: Help Has Arrived
There’s hope yet for the world’s most beleaguered vulnerability database.
Responsible AI Licenses (RAIL): Here’s What You Need to Know
Learn about this family of licenses that seek to limit harmful use of AI models.
NVD Update: More Problems, More Letters, Some Questions Answered
We’re not saying the NVD is dead but it’s not looking good.
Mend.io and Sysdig Launch Joint Solution for Container Security
Learn how the Mend.io and Sysdig integration boosts container security by combining runtime insights and vulnerability prioritization.
How Do I Protect My AI Model?
Learn essential strategies to secure your AI models from theft, denial of service, and other threats, covering copyright issues, risk management, and secure storage practices
Quick Guide to the OWASP OSS Risk Top 10
Learn about the top 10 risks of open source software, beyond just CVEs. From known vulnerabilities to unapproved changes.
What Makes Containers Vulnerable?
Learn about the vulnerabilities that containers bring to your applications and how to address them to keep attackers at bay.
NVD’s Backlog Triggers Public Response from Cybersec Leaders
The National Vulnerability Database’s backlog triggers a public response from cybersecurity leaders. Concerns raised, open letter to Congress
OWASP Top 10 for LLM Applications: A Quick Guide
Discover the OWASP Top 10 for LLM Applications in this comprehensive guide. Learn about vulnerabilities, & prevention techniques.
What You Need to Know About Hugging Face
Stay informed about the risks and challenges of AI models with Hugging Face. Learn how to identify and secure AI-generated code.