DevSecOps
OpenSSF Siren: Security for One, Security for All
The OpenSSF Siren is a fresh, new take on ye old security mailing list ...
No Country for No-Code: Are We Heading Towards a Wild West of Software Security?
The specter of an untrained employee creating applications is alarming: No-code/low-code platforms empower employees with no application security knowledge to develop programs that security teams don’t know exist ...
Sumo Logic Previews GenAI Tool to Improve DevSecOps Observability
Sumo Logic this week at the RSA Conference previewed a copilot that leverages generative artificial intelligence (AI) to make it simpler for IT and cybersecurity professionals of varying levels of experience to ...
The Role of DevOps in Orchestrating Enterprise-Wide Cloud Security
By implementing DevSecOps practices, organizations can proactively address security concerns early in development, reducing vulnerabilities ...
What OpenTofu 1.7 Means for DevSecOps
With built-in end-to-end encryption, OpenTofu is a natural DevSecOps fit ...
The Role of AI in Securing Software and Data Supply Chains
Expect attacks on the open source software supply chain to accelerate, with attackers automating attacks in common open source software projects and package managers ...
Securing Open Source Software, the Cyber Resilience Act Way
The Eclipse Foundation is spearheading an effort to create a unified framework for secure software development ...
From Chaos to Clarity: Streamlining DevSecOps in the Digital Era
Organizations need a scalable security orchestration framework that eliminates friction in DevSecOps workflows and drives efficiency in real-time ...
JFrog Survey Surfaces Raft of DevSecOps Challenges
A JFrog survey found that 60% of IT professionals typically spend four days or more remediating application vulnerabilities in a given month ...
appCD Launches Platform to Securely Provision Cloud Infrastructure
appCD's platform analyzes an application about to be deployed and automatically generates the code to provision the required infrastructure ...
AISecOps: Expanding DevSecOps to Secure AI and ML
AISecOps, the application of DevSecOps principles to AI/ML and generative AI, means integrating security into models' life cycles ...
Cycode Acquires Bearer to Extend ASPM Platform
Cycode has acquired Bearer, a provider of a set of tools for SAST, API discovery and identification of sensitive data ...

