IT Security

Veracode Report Shines Spotlight on Massive Application Security Debt

In an analysis of more than a million applications, Veracode found 42% contained flaws that remained unfixed for longer than…

2 months ago

Squaring the Circle: How to Make Public APIs Private

Many API attacks are effectively zero-day, novel attacks that exploit recent and unique changes to specific APIs. Here's how to…

2 months ago

Legit Security Adds Sensors to Detect Usage of Gen AI Tools to Write Code

Legit Security updated its ASPM platform with the ability to detect when developers use generative AI tools to write code.

2 months ago

Survey: Cyberattacks Aimed at Software Supply Chains are Pervasive

A survey found the vast majority of respondents work for organizations that experienced a software supply chain incident in the…

2 months ago

GitGuardian Allies With CyberArk to Better Protect App Secrets

GitGuardian has allied with CyberArk to streamline secrets detection and management by making it easier to share insights.

2 months ago

OX Security Optimizes DevSecOps to Improve Application Security

OX Security updated its ASPM platform to enable DevSecOps teams to instantly identify applications with vulnerable code.

3 months ago

Cycode Discloses GitHub Actions Vulnerability in Google Bazel Project

Cycode discovered a command injection vulnerability in the way GitHub Actions updated Google's open source Bazel project.

3 months ago

Snyk Acquires Helios to Extend Reach of ASPM Platform

With its Helios acquisition, Snyk plans to add an ability to capture application runtime data to extend the capabilities of…

3 months ago

5 Security Threats DevOps Teams Should Know

DevOps security (DevSecOps) is about breaking down silos and promoting open collaboration across teams.

3 months ago

Survey: Widespread Inability to Remediate App Vulnerabilities

A survey found only 20% of IT and security professionals are confident in their ability to detect a vulnerability before…

3 months ago