DevSecOps
15 Ways Software Becomes a Cyberthreat
Software is an integral part of private and commercial life; there is no way around it. You need software to do your taxes, book a flight or browse the internet. Software has ...
Progress Expands Scope of Compliance-as-Code Capabilities
Progress this week extended its DevSecOps portfolio—built atop the Chef automation framework it acquired in 2020—to now include the ability to programmatically address compliance mandates. At the same time, Progress has updated ...
How to Secure CI/CD Pipelines With DevSecOps
Many companies are adopting a DevOps approach in their workflows as IT moves toward a more automated and cloud-native world—but for some industries, this migration isn't easy. Many of these companies—in finance, ...
Does GraphQL Introduce New Security Risks?
The GraphQL query language is an excellent tool for increasing the ease of data sharing. The premise is that you request the fields you need in a single bundled request, avoiding multiple ...
OpenSSF Adds Open Source Package Analysis Tool Prototype
The Open Source Security Foundation (OpenSSF) has made available a prototype of a package analysis tool that has already identified more than 200 malicious packages uploaded to PyPI and npm software components ...
Checkmarx Report Highlights Need for AppSec Collaboration
A research report published by Checkmarx finds the same basic malicious software developed using multiple programming languages as cyberattackers industrialize their malware development processes. Checkmarx, a provider of code scanning tools, shared ...
DevSecOps: Realities of Policy Management
Policy management is essential to scale cloud environments and is key to secure DevOps practices. It enables organizations to manage policies put in place that secure the cloud environment, ensure Kubernetes configurations ...
Twitter/Bluesky ADX Algorithm | Cloud Energy Use ‘Tripled’ | Apple Staff are Revolting
In this week’s The Long View: Bluesky—Twitter’s research spinout—opens its ADX algorithm, Irish data-center electricity worries grow, and Apple employees are the latest to rise up against hybrid working ...
Synopsys Sets Course After Agreeing to Acquire WhiteHat Security
Synopsys, Inc. plans to add dynamic application security testing (DAST) tools to its software-as-a-service (SaaS) platform in the wake of agreeing to acquire WhiteHat Security from NTT Security Corp. for approximately $330 ...
Self-Service Helps Devs Solve Cloud Security and Compliance
Organizations that need compliance must follow a growing number of security standards—PCI, HIPAA, SOC 2 and GDPR just to name a few. Every new standard gives rise to an exhaustive list of ...
Datadog Unfurls Application Security Service
Datadog, Inc. today made generally available an Application Security Monitoring (ASM) service that is based on the same agent software that many DevOps teams already use to monitor applications. Pierre Betouin, vice ...
What Should Elon Musk Do? | Passwordless Future: Tense | WebKit iOS Monopoly Ends?
In this week’s The Long View: Everyone has Twitter advice for Elon Musk, passwordless vision is vacuous, and Apple prevented from forcing Safari ...

