DevSecOps
Fugue Aims to Simplify Securing Infrastructure-as-Code
Fugue today unveiled a 1.0 release for Regula, an open source policy engine for infrastructure-as-code (IaC) security that comes with prebuilt libraries for implementing hundreds of policies that validate configurations on Amazon ...
JFrog Acquires Vdoo to Advance DevSecOps
JFrog today announced it has agreed to acquire Vdoo for $300 million in cash to gain a set of analytics tools that discover vulnerabilities in application binaries. Vdoo's scanning tools, infused with ...
Dynatrace Applies AI to Surface App Vulnerabilities
Dynatrace has enhanced the security module to its observability platform that leverages its Davis artificial intelligence (AI) engine to automatically identify the software libraries and open source packages that represent the greatest ...
AppSec Marketing in the Age of DevSecOps
A while back, I had a conversation with a friend I went to school with (currently a senior member of the engineering team at a large retail chain) who was tasked with ...
Report: The State of Cloud-Native Application Security
The cloud brings tremendous capabilities in terms of increased deployment fluidity and automation. Along with cloud adoption has come the use of cloud-native tools built specifically for developing applications for this domain ...
Google Proposes SLSA Framework to Secure Software Supply Chains
Google is proposing organizations adopt a framework for securing the integrity of software artifacts across a software supply chain. Kim Lewandowski, a product manager for open source software security at Google, said ...
No More Hot Potato: How Collaboration is Key in Application Security
Technology is accelerating at an unprecedented rate and companies with little digital footprint or experience in application security are struggling to keep up. With more and more breaches and vulnerabilities being detected ...
Learning ‘The Third Way’ of DevOps – Continuous Improvement
I refer to the third way of DevOps–continuous experimentation and learning, as simply continuous improvement. In some sense, there is no way to learn the third way of DevOps because it is, ...
How to Analyze Your Code for Security Vulnerabilities
Shifting Left 2.0 is a two-day virtual conference taking place from 9 a.m. to 2 p.m. PDT on June 22nd-23rd that dives deep into application security in the modern tech space. Security ...
Accurics Aligns DevSecOps Platform With GitLab
Accurics today announced it has integrated its tool for discovering violations of security policies that occur when developers provision infrastructure as code with both the continuous integration and continuous delivery (CI/CD) platform ...
Majority of Orgs Lack Visibility Into Container Vulnerabilities
Today’s blend of third-party application dependencies and polyglot software development often makes assessing risk difficult. With many new cloud-native deployment models, it can be tricky to discover potential vulnerabilities. These threats take ...
Learning ‘The Second Way’ of DevOps – Continuous Feedback
As indicated in my prior blog Learning the 'First Way' of DevOps–Continuous Flow, many organizations are struggling to realize well-engineered DevOps, even the 'first way' of DevOps – continuous flow. The first ...

