IT as Code
Does GraphQL Introduce New Security Risks?
The GraphQL query language is an excellent tool for increasing the ease of data sharing. The premise is that you request the fields you need in a single bundled request, avoiding multiple ...
OpenSSF Adds Open Source Package Analysis Tool Prototype
The Open Source Security Foundation (OpenSSF) has made available a prototype of a package analysis tool that has already identified more than 200 malicious packages uploaded to PyPI and npm software components ...
Checkmarx Report Highlights Need for AppSec Collaboration
A research report published by Checkmarx finds the same basic malicious software developed using multiple programming languages as cyberattackers industrialize their malware development processes. Checkmarx, a provider of code scanning tools, shared ...
Stytch Launches New, Flexibility-First SDK
Passwordless solutions have been a trend for a while now, improving user experience (UX) while reducing exposure to common attack vectors. Now, Stytch’s new JavaScript SDK aims to make password-free authentication a ...
Synopsys Sets Course After Agreeing to Acquire WhiteHat Security
Synopsys, Inc. plans to add dynamic application security testing (DAST) tools to its software-as-a-service (SaaS) platform in the wake of agreeing to acquire WhiteHat Security from NTT Security Corp. for approximately $330 ...
Pulumi Extends Infrastructure-as-Code Reach
At its online PulumiUP conference, Pulumi announced it will make its Pulumi CrossCode translation technology available to third parties and DevOps teams. The technology was developed to integrate a wide range of ...
vFunction Tool Uses AI to Help Convert Monolithic Java Apps
vFunction today added the ability to employ artificial intelligence (AI) to automatically assess the level of effort required to convert a monolithic Java application into a set of microservices. Bob Quillin, chief ...
CloudBolt Adds Modular Automation Framework to Tame Hybrid Clouds
CloudBolt Software this week added a framework consisting of eight modules that collectively make it simpler to automate, optimize and govern hybrid cloud computing environments. Jeff Kukowski, CloudBolt CEO, said the goal ...
BMC Integrates DevOps Mainframe Portfolio With Git
BMC has expanded its efforts to bring DevOps best practices to the development of mainframe applications by integrating the BMC Compuware ISPW continuous integration/continuous delivery (CI/CD) platform with Git repositories. In addition, ...
Riverbed Unveils Unified Observability Platform
Riverbed today launched a beta of a unified observability platform it will make available under the Alluvio by Riverbed brand name. Jim Hansen, senior vice president for product management at Riverbed, said ...
Defining the Next Cycle of Technology
We’re in the middle of what we at ScyllaDB dubbed The Next Tech Cycle. Not “The World of Tomorrow” nor “The Shape of Things to Come” nor “The Wave of the Future”—because ...
MDR for DevSecOps: How Managed Security Can Help You Shift Left
What is managed detection and response (MDR)? Managed detection and response (MDR) is an outsourced service that helps organizations detect threats on endpoints, respond to them and carry out proactive threat hunting ...

