DevSecOps
DevOps World 2022: Developer and Security Links Protect Your Supply Chain
Ever since the SolarWinds attack back in December 2020, software supply chain attacks have been top-of-mind for any company that builds software. The idea of endangering not just your organization by being ...
Playwright: A Modern, Open Source Approach to End-To-End Testing
I was excited when I started writing my first end-to-end tests years ago. The idea was promising; create an automated test suite that spins up a browser and mimics your user's behavior ...
Federal Agencies Share DevSecOps Guidelines
The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and the Office of the Director of National Intelligence (ODNI) have published a set of DevSecOps best practices based on the Enduring ...
Supply Chain Security: Has the Next SolarWinds Already Happened?
More than two years after the now-infamous hack of the firm SolarWinds, the incident is very much in the foreground of conversations about cybersecurity defense, threat detection and incident response. As evidence ...
The Missing Link in DevOps Cloud Security
We’ve all seen the data from the latest Verizon Data Breach Incident Report that shows half of security breaches stem from credential abuse. It's clear that credential compromise is an epidemic in ...
Why DevOps Teams Need Security Engineers
In the episode of View with Vizard, Mike Vizard sits down with Om Vyas, chief product officer for oak9, as he explains why security engineers need to become part of every DevOps ...
Avoiding Security Review Delays
In the summer of 2021, I had lunch with a senior security developer at one of Seattle's leading tech firms. Even though we were relaxed in the sunny and cool afternoon of ...
Cycode Expands Scope of AppDev Security Platform
At the Black Hat USA 2022 conference, Cycode this week announced it has added static application security testing (SAST) and container scanning capabilities to its software composition analysis (SCA) platform that is based ...
What GitHub’s 2FA Mandate Means for Devs Everywhere
Multifactor authentication (MFA) is becoming increasingly standard within software development organizations, with GitHub recently announcing that two-factor authentication (2FA) will be mandatory for all code contributors by the end of 2023. This ...
GitHub Brings 2FA to JavaScript Package Manager
GitHub has made generally available a two-factor authentication tool for the package manager for JavaScript applications maintained by its NPM, Inc. arm. In addition, all npm packages have been re-signed and there ...
CREST Defines Quality Verification Standard for AppSec Testing
At the Black Hat USA 2022 conference, CREST today shared a quality assurance verification standard to improve application security testing. The standard is based on the open source framework defined by the ...
IBM Unveils Simulation Tool for Attacking SCM Platforms
At the Black Hat USA 2022 conference, IBM today revealed it is making available a toolkit for launching simulated attacks against source code management (SCM) platforms. The toolkit was launched as a ...

