DevSecOps
Only 30% of Orgs Fully Implement DevSecOps
With the pressure to release more rapidly, security is shifting left within the continuous development pipeline at most organizations. This imperative is increasing with the rise of cyberattacks. Yet both a lack ...
Rails 7 FTW | WFH is SOP | 586M Passwords Dumped
In this week’s The Long View: Ruby on Rails 7.0 is go, working from home is still de rigueur, and HIBP gets far, far bigger ...
Best of 2021 – Torvalds’ Bug Warning is a Lesson for Linux Users
As we close out 2021, we at DevOps.com wanted to highlight the most popular articles of the year. Following is the third in our series of the Best of 2021. Linux does, ...
How Log4j Becomes a Serious DevOps Problem
The recent discovery of the Apache Log4j vulnerability has wide-ranging implications for anyone who develops software, especially for those in the DevOps realm. What’s most troubling about the vulnerability (CVE-2021-44228) is how ...
Bridging the AppSec and DevOps Disconnect
Research estimates that cybercrime is going to cost the world $10.5 trillion annually by 2025, so it is no surprise that cybersecurity has become a top priority for business leaders. Today, security ...
Log4j: It’s All About the Supply Chain, Baby!
In 2021, the security story in DevOps and DevSecOps has been the supply chain. So, it’s only fitting that we are currently experiencing the mother of all supply chain issues with the ...
Log4j: Is There Such a Thing as ‘Too Much’ Open Source?
The Log4j vulnerability got me thinking: Is there such a thing as too much open source? Before anyone immediately fires off a flaming email, rage tweet or scathing blog post, hear me ...
Log4j Puts Effective IT Operations at Center Stage
News of the Apache Log4j vulnerability exploit is striking fear into the hearts of both software makers and users. Log4j is the most popular Java logging service used today, with over 400,000 ...
U.S. Govt. CX EO | Mozilla Revenue | Log4j Latest
In this week’s The Long View: Improving U.S. government CX, how much money Mozilla makes, and the latest on the Log4j/Log4Shell débâcle ...
Overcoming Challenges to Automating DevSecOps
In the last few years, DevSecOps has been widely adopted among organizations looking to get proactive with their security. Traditionally, development teams would continuously implement and deploy new applications into the enterprise ...
Stacklet Embeds Collaboration in Compliance-as-Code Platform
Stacklet has added collaboration capabilities to its security and compliance platform that automatically groups related notifications, routes them to the right stakeholders and integrates with existing workflows and collaboration tools. The Stacklet ...
Securing the Software Supply Chain with Behavioral Analysis
Lately, software supply chains find themselves in a very interesting and uncomfortable position—the industry spotlight—and not in a good way. While significant and costly breaches such as SolarWinds or Kaseya make front-page ...

