DevOps.com

  • Latest
    • Articles
    • Features
    • Most Read
    • News
    • News Releases
  • Topics
    • AI
    • Continuous Delivery
    • Continuous Testing
    • Cloud
    • Culture
    • DataOps
    • DevSecOps
    • Enterprise DevOps
    • Leadership Suite
    • DevOps Practice
    • ROELBOB
    • DevOps Toolbox
    • IT as Code
  • Videos/Podcasts
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • DevOps Unbound
  • Webinars
    • Upcoming
    • On-Demand Webinars
  • Library
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Related Sites
    • Techstrong Group
    • Container Journal
    • Security Boulevard
    • Techstrong Research
    • DevOps Chat
    • DevOps Dozen
    • DevOps TV
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
  • Media Kit
  • About
  • Sponsor
  • AI
  • Cloud
  • Continuous Delivery
  • Continuous Testing
  • DataOps
  • DevSecOps
  • DevOps Onramp
  • Platform Engineering
  • Low-Code/No-Code
  • IT as Code
  • More
    • Application Performance Management/Monitoring
    • Culture
    • Enterprise DevOps
    • ROELBOB
Hot Topics
  • npm is Scam-Spam Cesspool ¦ Google in Microsoft Antitrust Thrust
  • 5 Key Performance Metrics to Track in 2023
  • Debunking Myths About Reliability
  • New Relic Bets on AI to Advance Observability
  • Vega Cloud Commits to Reducing Cloud Costs

Tag: OWASP

ZAP Menlo Security - cloud security

Update to Open Source ZAP Tool Improves DAST Performance

Avatar photoMike Vizard | November 1, 2022 | attack proxy, DAST, devsecops, OWASP, SAST, ZAP
An update to the OWASP Zed Attack Proxy (ZAP) open source dynamic application security testing (DAST) tool made available today improves performance by employing a multi-threaded passive scanner engine. Version 2.12.0 of ...
mobile app testing efficient CREST Android mobile app development

CREST Defines Quality Verification Standard for AppSec Testing

Avatar photoMike Vizard | August 9, 2022 | Black Hat 2022, CREST, OWASP, Software Supply Chain
At the Black Hat USA 2022 conference, CREST today shared a quality assurance verification standard to improve application security testing. The standard is based on the open source framework defined by the ...
Quali SigStore OWASP DevSecOps vulnerabilities security Pulumi DevSecOps Analyzing Code for Security Vulnerabilities

The Everything-As-Code Revolution and the OWASP Top 10

Avatar photoAakash Shah | August 4, 2022 | application development, as-code, devsecops, OWASP
After years of stagnation, the Open Web Application Security Project (OWASP) Top 10 list finally saw some shakeup. Most notably, insecure design debuted on the list as the number four security risk ...
OWASP

What the New OWASP Top 10 Changes Mean to Devs

Avatar photoPankaj Gupta | June 23, 2022 | application security, AppSEcurity, devops, log4j, OWASP, security, ShiftLeft, SSRF, WAF
The open web application security project (OWASP) recently updated its top 10 list of the most critical security risks to web applications after four years. It represents the most radical shake-up since ...
OWASP

What Is OWASP?

Mitch Ashley | January 11, 2021 | OWASP, OWASP static code analysis, OWASP Top 10, perforce, what is OWASP
With cybersecurity attacks rising, it is important for you to enforce secure software best practices, like OWASP and the OWASP Top 10. OWASP helps you to safeguard your code against software security ...
Cycode CodeLogic scanning Contrast Security secrets scan dynamic

DevSecOps Implementation: Dynamic Scans

Avatar photoDon Macvittie | November 30, 2020 | application vulnerabilities, devops implementation, devsecops, Dynamic Application Security Testing, OWASP
This is the third installment in this series on DevSecOps. Read the first installment, on static analysis, here and the second installment, on source composition analysis, here. One weakness of static analysis ...
source composition analysis

DevSecOps Implementation: Source Composition Analysis

Avatar photoDon Macvittie | November 16, 2020 | application vulnerabilities, NVD, open source licensing, open source vulnerabilities, OWASP, Source Code Analysis
This is the second installment in this series on DevSecOps. Read the first installment, on Static Analysis, here. One of the better additions to security in recent years is source composition analysis ...
OWASP API Security

Breaking Down the OWASP API Security Top 10, Part 2

Avatar photoErez Yalon | January 3, 2020 | API, API security, database management systems, injection vulnerability, OWASP, personal identifiable information, SQL injection
Due to the widespread usage of APIs, and the fact that attackers realize APIs are a new attack frontier, the OWASP API Security Top 10 Project was launched. From the beginning, the ...
Breaking Down the OWASP API Security

Best of 2019: Breaking Down the OWASP API Security Top 10, Part 1

Avatar photoErez Yalon | January 1, 2020 | API, API security, authentication endpoints, OWASP, secure coding
As we close out 2019, we at DevOps.com wanted to highlight the five most popular articles of the year. Following is the fifth in our weeklong series of the Best of 2019 ...
DevOps and Security Shield Your Application

DevOps and Security: Be Ready to Shield Your Application

Avatar photoDebarghya Pandit | April 16, 2019 | application security, CI/CD pipelines, devops tools, devsecops, Jenkins, OWASP, software security
All of us have heard of continuous improvement/continuous delivery (CI/CD). There are many benefits to implementing CI/CD, as it helps seamless integration from end to end for development and deployment processes. CI/CD ...

Protego Spearheads Launch of the OWASP Official Serverless Top 10 Project

Avatar photoDevOps.com | November 19, 2018 | application attacks, OWASP, Protego Labs, serverless
Report to Educate Application Security Practitioners on Serverless Application Risks and Mitigation Techniques  Baltimore, Maryland - The Open Web Application Security Project (OWASP) released today the official OWASP Serverless Top 10 project initiated ...

Techstrong TV – Live

Click full-screen to enable volume control
Watch latest episodes and shows

Upcoming Webinars

https://webinars.devops.com/overcoming-business-challenges-with-automation-of-sap-processes
Tuesday, April 4, 2023 - 11:00 am EDT
Key Strategies for a Secure and Productive Hybrid Workforce
Tuesday, April 4, 2023 - 1:00 pm EDT
Using Value Stream Automation Patterns and Analytics to Accelerate DevOps
Thursday, April 6, 2023 - 1:00 pm EDT

Sponsored Content

The Google Cloud DevOps Awards: Apply Now!

January 10, 2023 | Brenna Washington

Codenotary Extends Dynamic SBOM Reach to Serverless Computing Platforms

December 9, 2022 | Mike Vizard

Why a Low-Code Platform Should Have Pro-Code Capabilities

March 24, 2021 | Andrew Manby

AWS Well-Architected Framework Elevates Agility

December 17, 2020 | JT Giri

Practical Approaches to Long-Term Cloud-Native Security

December 5, 2019 | Chris Tozzi

Latest from DevOps.com

npm is Scam-Spam Cesspool ¦ Google in Microsoft Antitrust Thrust
March 31, 2023 | Richi Jennings
5 Key Performance Metrics to Track in 2023
March 31, 2023 | Sarah Guthals
Debunking Myths About Reliability
March 31, 2023 | Kit Merker
New Relic Bets on AI to Advance Observability
March 30, 2023 | Mike Vizard
Vega Cloud Commits to Reducing Cloud Costs
March 30, 2023 | Mike Vizard

TSTV Podcast

On-Demand Webinars

DevOps.com Webinar ReplaysDevOps.com Webinar Replays

GET THE TOP STORIES OF THE WEEK

Most Read on DevOps.com

Don’t Make Big Tech’s Mistakes: Build Leaner IT Teams Instead
March 27, 2023 | Olivier Maes
How to Supercharge Your Engineering Teams
March 27, 2023 | Sean Knapp
Five Great DevOps Job Opportunities
March 27, 2023 | Mike Vizard
The Power of Observability: Performance and Reliability
March 29, 2023 | Javier Antich
Cloud Management Issues Are Coming to a Head
March 29, 2023 | Mike Vizard
  • Home
  • About DevOps.com
  • Meet our Authors
  • Write for DevOps.com
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • Privacy Policy

Powered by Techstrong Group, Inc.

© 2023 ·Techstrong Group, Inc.All rights reserved.