IT Security
Rust Foundation Allies With OpenSSF and JFrog to Secure Code
The Rust Foundation announced today it is working with the Open Source Security Foundation (OpenSSF) and JFrog to help maintainers secure open source software created using the Rust programming language. Rebecca (Bec) ...
Federal Agencies Share DevSecOps Guidelines
The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and the Office of the Director of National Intelligence (ODNI) have published a set of DevSecOps best practices based on the Enduring ...
Avoiding Security Review Delays
In the summer of 2021, I had lunch with a senior security developer at one of Seattle's leading tech firms. Even though we were relaxed in the sunny and cool afternoon of ...
IBM Unveils Simulation Tool for Attacking SCM Platforms
At the Black Hat USA 2022 conference, IBM today revealed it is making available a toolkit for launching simulated attacks against source code management (SCM) platforms. The toolkit was launched as a ...
JFrog Aligns With AWS to Improve Cloud Application Security
At the AWS re:Inforce event this week, JFrog announced it integrated its JFrog Xray software composition analysis tool with AWS Security Hub, a cloud security posture management (CSPM) service that alerts IT ...
Scribe Security Unveils Pair of Tools to Secure Software Supply Chains
Scribe Security today unveiled a Scribe Integrity tool that scans software artifacts to make sure they comply with IT organizations' security policies before they are integrated into an application. The Scribe Integrity ...
Styra Unfurls Cloud Service for Implementing Compliance-as-Code
Styra, Inc. today launched an authorization service based on the Open Policy Agent (OPA) software that can be invoked via an application programming interface (API). Torin Sandall, vice president of open source ...
Rezilion Launches Vulnerability Prioritization Platform
Rezilion today announced general availability of a platform that enables DevOps teams to better prioritize remediation efforts by identifying which vulnerabilities both run in memory and actually impact a class or function ...
GitGuardian Tightens Integration With GitHub to Secure Secrets
GitGuardian has expanded its ability to secure code repositories by providing deeper integration with GitHub. Ziad Ghalleb, product marketing manager for GitGuardian, said the results of security scans are now provided in ...
This DevSecOps Thing Is Real After All
Whether you made it to San Francisco, California last month for RSA Conference or not, you don’t want to miss Tuesday’s DevOps Connect: DevSecOps Virtual Summit. On Tuesday, July 12, 2022, we ...
Turning Off DevSecOps Noise for Functional Fidelity
Analyzing the DevOps and DevSecOps software marketplace demonstrates the high demand for tools and platforms that reduce false positives. As businesses and organizations adopt a rigorous, disciplined software development life cycle and ...
More Than Half of DevOps Pros Have Backdoor Access to IT Infrastructure
A survey of 600 DevOps professionals conducted by strongDM, a platform for managing access to IT infrastructure, found nearly two-thirds (64%) had productivity impacted on a daily or weekly basis because of ...

