software supply chain malware

National Cybersecurity Strategy Requires Orgs to Rethink Software Quality

Software development is a global effort, with DevOps teams often dispersed around the world. According to Statista, there will be over 27.7 million developers worldwide in 2023. That’s a lot of engineers creating millions of lines of code each day, all of which are orchestrated within an enterprise’s DevOps workflow. With ... Read More
Security Boulevard

New Research from Sonar on Cost of Technical Debt

|
New original research from Sonar puts a spotlight on the millions of dollars that businesses lose when they fail to implement an optimal approach for software development ... Read More
Modern AppSec Tools Must Focus on Reducing Attackability, Not Chasing Bugs

Modern AppSec Tools Must Focus on Reducing Attackability, Not Chasing Bugs

Developers need findings with higher context, not additional findings, in order to make applications secure in today’s environment.Photo by Johnson Wang on UnsplashFor too long, application security vendors have been focused on finding vulnerabilities in the individual components of an application. Success for many appears to be measured by the quantity ... Read More
AppSec Shift Left Progress Report

Progress in Numbers: Our First Customer Report

Having spent 15 years detecting malware — virus, intrusions, worms, nation-state attacks, etc — I learned that much of security is reactive. We let the bad guy shoot first and then try to figure out how we are going to protect ourselves. Software vulnerabilities are one of the most important problems in security and ... Read More
Welcome to the future of application security

Welcome to the future of application security

Yesterday’s announcement of the acquisition of Semmle by GitHub (Microsoft) is a ringing endorsement of the need to move security to the left— “shift left”. It is a validation of the growing influence of software developers in the world, the importance of code analysis for securing software in modern DevOps ... Read More
A New Approach to Application Security Testing

A New Approach to Application Security Testing

If the appsec industry were to develop a better AST solution from scratch, what would it look like?As software, aka applications, microservices, and workloads, increasingly moves into the cloud, its protection has become paramount. Recent research highlights this need, pointing to application vulnerabilities as the leading source of security breaches ... Read More
Can Security be a Business Enabler?

Can Security be a Business Enabler?

Finding, prioritizing, and fixing vulnerabilities during Development and protecting the applications from attacks in Production is the security best-practice. Yet, this is ineffective, resource intensive and exacerbated as organizations modernize their development practices. This blog provides the blueprint for a purpose-built approach to make our applications more secure.Let’s look at ... Read More