AppSec Observer
Contrast’s application security blog provides the latest trends and tips in DevSecOps through instrumentation and security observability.

Cybersecurity Insights with Contrast CISO David Lindner | 06/13/25
Insight No. 1 — The great CISO exodus: Why your top defenders are planning a silent escape What happens when your most critical security minds are quietly planning their exit? With 53% ...

How ADR Sees the Attacks that Other Cybersecurity Tools Miss | Application-Layer Security | Contrast Security
Contrast Marketing | | Application Detection and Response (ADR), Application Layer Attacks, Application Security, Cross-Site Scripting (XSS), Data breaches, EDR, path traversal, sql injection, unsafe deserialization, Vulnerability Exploitation, waf
If your tools can’t see what’s happening inside your apps and application programming interfaces (APIs), they can’t stop breaches. And the truth is, perimeter and endpoint tools were never designed to detect ...

Northstar: The First Unified Application Detection and Response (ADR) Platform | Contrast Security
Contrast | | ADR, ADR (Application Detection and Response), Contrast AI SmartFix, Contrast Graph, Contrast MCP Server, Flex Agent, Northstar, runtime, runtime protection
Today, Contrast is launching Northstar — a major leap forward in securing modern applications and application programming interfaces (APIs) ...

Cybersecurity Insights with Contrast CISO David Lindner | 06/06/25
David Lindner, Director, Application Security | | AI legal ownership, CVSS scores, Cybersecurity Insights, Data Governance, data provenance, LLMs, machine learning, malware trends, risk prioritization, threat actor names
Insight No. 1 — Fixing threat actor names Microsoft and CrowdStrike announced that they’ll work together on the headache of multiple names for the same threat actors. But what matters most is ...

AI Speed Paradox | Securing AI Generated Code | Contrast Security
Contrast Marketing | | AI, AI Code Security, AppSec, attacks, Code, deployment, risk, runtime, security, threats, Vulnerabilities
AI-powered code is developing so fast that security defenses can't keep up, leaving new vulnerabilities in its wake. The speed is outstripping traditional security measures, demanding immediate and radical changes to organizational ...

Cybersecurity Insights with Contrast CISO David Lindner | 05/30/25
David Lindner, Director, Application Security | | ADR, Agentic AI, AgenticAI, dbir, exploitation, identity, Insights, passwordless, remediation, security, Validation
Insight No. 1 — Prioritize proof over promises in agentic AI SC World recently noted that there were three points missing from agentic AI conversations at RSAC. I agree. Many new technologies ...

Navigating os.Root and Path Traversal Vulnerabilities | Go 1.24 Detection and Protection Methods | Contrast Security
Max Sours, Senior Software Engineer | | Contrast ADR, Contrast Assess, file system, Go 1.24, Go Agent, golang, os.Root, path traversal, security, vulnerability
The latest Go release — Go 1.24, released in February 2025 — introduced a significant security enhancement: the os.Root type. ...

Cybersecurity Insights with Contrast CISO David Lindner | 05/23/25
Contrast Marketing | | Application Detection and Response (ADR), Application Security, Breach, CISOs, communication, Cybersecurity, EDR, layoffs, waf
Insight No. 1 — Instead of layoffs, bank on your security team. Using Infosec layoffs to chase short-term payroll savings in cybersecurity is a dangerous gamble that will inevitably cost far more ...

Contrast Secures AI Applications and Modern Software | Forrester 2025 SAST Report | Contrast Security
Contrast Marketing | | AI Applications, APIs, Attack, Contrast Security, Forrester, Report, SAST, security, software, Vulnerabilities
A new report from independent research firm Forrester has several major findings. ...

Contrast MCP Server | AI Code Security and Vulnerability Remediation | Contrast Security
Joseph Beeton, Senior Application Security Researcher, Contrast Security | | AI Code Security, AI Coding Agent, Contrast MCP Server, GitHub Copilot, Interactive Application Security Testing (IAST), JNDI Vulnerability, Model Context Protocol (MCP), sql injection, Vulnerability Remediation
Contrast Security is proud to announce the launch of our MCP server. Smart assistants help you find and fix mistakes in your writing. Now, picture an assistant fixing security weaknesses in your ...