White House publishes guidelines requiring government agencies to obtain formal assurances from third-party software providers that they are following secure software development practices.
The Spring Security team plans to release Spring Authorization Server, it long-awaited in November of this year.
Our Agile Architect wants to talk about lessons learned from his experiences with test automation. As usual, he does it in his own unique way.
App security tools provider Contrast Security adds software composition analysis capabilities to its free in CodeSec "developer-first" scanner.
Application security testing company Checkmarx and cybersecurity workflow and productivity startup Seemplicity today announced a new partnership aimed at simplifying the "find-to-fix" lifecycle and accelerating the time to remediation of vulnerabilities found throughout the software development lifecycle .
Veeam Software kicks off its annual user conference with a product roadmap that showcases features planned for the release of Veeam Backup & Replication v12, as well as key solution innovations for cloud-native solutions, SaaS offerings, and some deeper integrations of Kasten by Veeam K10 for Kubernetes.
The OpenSSF announced 19 new members, including Citi, Huawei, Spotify, Alibaba, and JFrog, who added their names to a roster that already includes Google, Microsoft, AWS, Meta, and Cisco.
Cybersecurity solutions provider Contrast Security unveils four new GitHub Actions aimed at making the process of automating security testing within native pipelines more accessible to developers.
The Application Security Division of NTT Ltd. releases a solution designed to make it possible for developers to conduct dynamic application security testing (DAST) at each phase of the software development cycle.
The U.S. Federal Trade Commission intends to use its "full legal authority to pursue companies that fail to take reasonable steps to protect consumer data from exposure as a result of the Log4j vulnerability," the commission warned.
A critical-remote code execution vulnerability in the widely used Log4j open-source Java logging library, "has given cybercriminals the perfect attack campaign on a silver platter."
Synopsys, a provider of electronic design automation (EDA), semiconductor IP, and application security testing tools and services, acquires app vulnerability management company Code Dx.
Cybersecurity pros have a new online resource, the RSAC Marketplace, which its creators describe as "the equivalent of a year-round RSA expo."
Sonatype expands the latest version of its Nexus platform to offer "full-spectrum control of the cloud-native software development lifecycle."
GrammaTech today announced a technology partnership with GitLab to integrate the GrammaTech CodeSonar Static Application Security Testing solution with GitLab's Ultimate DevSecOps platform.
Application Security Testing solutions provider Veracode today announced the launch of a two-week collegiate competition designed to challenge student teams in the U.S. and the U.K. to test their secure coding skills.
Software security solutions provider Checkmarx today launched a new open-source static analysis tool designed to allow developers to write more secure infrastructure-as-code.
Ivanti enhances the capabilities of its flagship Enterprise Service Management (ESM) portfolio with greater automation capabilities between service management and SecOps.
Cloud security provider Accurics announced that it is extending support in its Terrascan open-source tool for detecting compliance and security violations across Infrastructure as Code to two Cloud Native Computing Foundation projects: Helm and Kustomize.
Version 1.0 of the new debugger for Python in Visual Studio Code (VS Code), called Debugpy, shows up in the latest update of the popular Python tooling for the open source, cross-platform code editor.
A new report from Veracode analyzes 130,000 applications, and finds that it takes about six months for teams to close half the security flaws they find.
The Cloud Security Alliance does a deep-dive analysis of nine of last year's Egregious 11: Top Threats to Cloud Computing.
New security solution surfaces vulnerabilities in third-party code used in the development of custom applications.
Automated IT and security solutions provider Ivanti today announces two additions to its Neurons "hyper-automation" platform: Neurons for Patch Intelligence and Neurons for Spend Intelligence.
The results of a new survey suggest that a growing number of security and development professionals are convinced of the value of Security Champions programs.
More Tech Library