Software security solutions provider Checkmarx today launched a new open-source static analysis tool designed to allow developers to write more secure infrastructure-as-code.
Java apps earn higher security vulnerability score than .NET apps, a Contrast Lab report finds.
A new report from Application Security Testing (AST) solutions provider Veracode shows that software developers working in the retail and hospitality sector are fixing flaws in their companies' software at a faster rate than five other sectors--despite having to work with applications that tend to be older and larger than other sectors.
Red Hat announced that it is acquiring Kubernetes-native security provider StackRox sometime in the first quarter of 2021. It's first acquisition by Red Hat since it was acquired by IBM.
BMC unveils new capabilities and enhancements for its Automated Mainframe Intelligence (AMI) and Compuware portfolios to protect mainframe customers' uptime and availability, defend the mainframe against cybersecurity threats, and advance enterprise DevOps.
Ivanti enhances the capabilities of its flagship Enterprise Service Management (ESM) portfolio with greater automation capabilities between service management and SecOps.
Cloud security provider Accurics announced that it is extending support in its Terrascan open-source tool for detecting compliance and security violations across Infrastructure as Code to two Cloud Native Computing Foundation projects: Helm and Kustomize.
Version 1.0 of the new debugger for Python in Visual Studio Code (VS Code), called Debugpy, shows up in the latest update of the popular Python tooling for the open source, cross-platform code editor.
New security solution surfaces vulnerabilities in third-party code used in the development of custom applications.
Automated IT and security solutions provider Ivanti today announces two additions to its Neurons "hyper-automation" platform: Neurons for Patch Intelligence and Neurons for Spend Intelligence.
The results of a new survey suggest that a growing number of security and development professionals are convinced of the value of Security Champions programs.
Authentication solution provider Okta has extended its Okta Devices Platform Service capabilities to developers via the Okta Devices SDK, which provides packaged tooling to build passwordless sign-in flows through branded push notifications with biometric capabilities, minimizing friction for end-users and increasing security posture.
Cloud security provider Accurics announced a new GitHub app designed to further automate the programmatic enforcement of security policies throughout the software development workflow.
ZeroNorth announces a new set of capabilities for its SaaS-based security platform aimed at removing friction between security and DevOps teams by making security "integral and transparent" within the SDLC.
Sumo Logic's fourth annual Illuminate user conference, virtual this year because of the pandemic, wrapped up yesterday after two days of educational sessions, expert keynotes, and product and initiative announcements.
CloudBees recently announced a new set of DevSecOps capabilities for its continuous integration and delivery (CI/CD) solutions, including feature flag integration within the CI and CD environments, which the company is billing as an industry first.
Sonatype's malicious code detection bots discovered and confirmed the presence of new vulnerable npm packages that exfiltrate/broadcast the target's IP, username, and device fingerprint info onto a public GitHub page where anyone can gain access.
Microsoft enables continuous developer-driven "fuzzing" with newly open sourced tool.
Cloud security provider Accurics has release an update of its free and open-source Terrascan static code analyzer with new support for Kubernetes.
A group of leading tech industry heavy weights that includes Microsoft, IBM, and Google, announced the formation of a new software foundation to consolidates industry efforts to improve the security of open-source software.