mobile application security

5 Reasons Why Mobile Application Security Fails

Traditionally, large organizations and the enterprise have been the focus for hackers and malicious attacks, but in recent years, the rise of sophisticated hacking tools and leaked databases on the dark web, ...
Security Boulevard

Open Source Code: Trojan Horse for Attacks?

On June 2, it was revealed that the Octopus Scanner malware had infected at least 26 open source code repositories on GitHub. Once downloaded, the malware specifically targets the Apache NetBeans Java ...
Security Boulevard
DevOps productivity series — GitHub for DevSecOps

DevOps productivity series — GitHub for DevSecOps

GitHub & DevSecOps Productivity TipsThis article was originally published at ShiftLeft Blog.My colleague Andrew Fife wrote about our passion to focus on developer experience and productivity with our NextGen Static Analysis platform ...
open source security

DevOps Chats: Open Source Security, With WhiteSource

WhiteSource, one of the leaders in the software composition analysis space, recently released its annual report, “The State of Open Source Security Vulnerabilities.” It is chock full of good data and findings ...
Security Boulevard
data leakage

Survey: Third-Party Code Proves Vulnerable

A recent survey of 307 IT professionals conducted Osterman Research on behalf of PerimeterX, a provider of cybersecurity tools for web applications, suggests there’s a lot of third-party code running on websites ...
Security Boulevard
Cybersecurity Issues in Mobile App Development

Cybersecurity Issues in Mobile App Development

Mobile app development has become a key factor for the success of any business. And as mobile apps have grown more popular among users, it’s important for developers to make security of ...
Security Boulevard
Why Framework Choice Matters

Why Framework Choice Matters in Web Application Security

One of the oldest clichés in web application security is that, "It doesn't matter which framework you choose, if you know what you're doing". In my experienced opinion, off the back of ...
Many Developers Have Yet to Take Responsibility for Code Security, Reveals DevOps Study

Many Developers Have Yet to Take Responsibility for Code Security, Reveals DevOps Study

A DevOps survey revealed that many developers have yet to take responsibility for the security of the code they produce. According to Checkmarx’s report, “Managing Software Exposure: Time to Fully Embed Security ...
Cupertino Code Signing, The Next Generation (Maybe It'll Work)

Cupertino Code Signing, The Next Generation (Maybe It’ll Work)

via Josh Pitts (a staff engineer at OKTA), and writing on the company blog, comes a well crafted explanatory piece on what he has discovered in the third-party-code-signing Apple Inc. (NasdaqGS: AAPL) ...