Security News


White House Calls for 'Attestations' of Secure Practices from Third-Party Software Providers

White House publishes guidelines requiring government agencies to obtain formal assurances from third-party software providers that they are following secure software development practices.

A Visit to the Automated Testing Zoo

Our Agile Architect wants to talk about lessons learned from his experiences with test automation. As usual, he does it in his own unique way.

Contrast Security Adds SCA in Free CodeSec Tool

App security tools provider Contrast Security adds software composition analysis capabilities to its free in CodeSec "developer-first" scanner.

Checkmarx and Seemplicity Join Forces to Simplify the Find-to-Fix Lifecycle

Application security testing company Checkmarx and cybersecurity workflow and productivity startup Seemplicity today announced a new partnership aimed at simplifying the "find-to-fix" lifecycle and accelerating the time to remediation of vulnerabilities found throughout the software development lifecycle .

Veeam Previews Major Product Updates at Annual User Conference

Veeam Software kicks off its annual user conference with a product roadmap that showcases features planned for the release of Veeam Backup & Replication v12, as well as key solution innovations for cloud-native solutions, SaaS offerings, and some deeper integrations of Kasten by Veeam K10 for Kubernetes.

Contrast Security Partners with GitHub to Deliver 'Pipeline-Native' Security to Developers

Cybersecurity solutions provider Contrast Security unveils four new GitHub Actions aimed at making the process of automating security testing within native pipelines more accessible to developers.

New 'Vantage Prevent' Solution Shifts DAST Left

The Application Security Division of NTT Ltd. releases a solution designed to make it possible for developers to conduct dynamic application security testing (DAST) at each phase of the software development cycle.

Blue Server Graphic

Companies Facing FTC Legal Action Over Log4j Breaches

The U.S. Federal Trade Commission intends to use its "full legal authority to pursue companies that fail to take reasonable steps to protect consumer data from exposure as a result of the Log4j vulnerability," the commission warned.

Dark City IMage

Log4j Remote Code Execution Vulnerability Likely to Affect Millions

A critical-remote code execution vulnerability in the widely used Log4j open-source Java logging library, "has given cybercriminals the perfect attack campaign on a silver platter."

Synopsys Adds Code Dx to AppSec Portfolio

Synopsys, a provider of electronic design automation (EDA), semiconductor IP, and application security testing tools and services, acquires app vulnerability management company Code Dx.

New RSAC Marketplace 'Expands RSA Conference' for Cybersecurity Pros

Cybersecurity pros have a new online resource, the RSAC Marketplace, which its creators describe as "the equivalent of a year-round RSA expo."

Silver Pins

Sonatype Unveils NextGen Nexus Platform

Sonatype expands the latest version of its Nexus platform to offer "full-spectrum control of the cloud-native software development lifecycle."

GrammaTech Partners with GitLab to Add Shift-Left Capabilities to the CI/CD Pipeline

GrammaTech today announced a technology partnership with GitLab to integrate the GrammaTech CodeSonar Static Application Security Testing solution with GitLab's Ultimate DevSecOps platform.

Veracode Launches 'Hacker Games' to Test Student Cybersecurity Skills

Application Security Testing solutions provider Veracode today announced the launch of a two-week collegiate competition designed to challenge student teams in the U.S. and the U.K. to test their secure coding skills.

Checkmarx Unveils New Open Source IaC Scanning Engine

Software security solutions provider Checkmarx today launched a new open-source static analysis tool designed to allow developers to write more secure infrastructure-as-code.

Java Apps More Vulnerable than .NET Apps, Report Finds

Java apps earn higher security vulnerability score than .NET apps, a Contrast Lab report finds.

Devs in Retail and Hospitality Fix Flaws Faster, Veracode Report Concludes

A new report from Application Security Testing (AST) solutions provider Veracode shows that software developers working in the retail and hospitality sector are fixing flaws in their companies' software at a faster rate than five other sectors--despite having to work with applications that tend to be older and larger than other sectors. 

Red Hat to Acquire StackRox

Red Hat announced that it is acquiring Kubernetes-native security provider StackRox sometime in the first quarter of 2021. It's first acquisition by Red Hat since it was acquired by IBM.

BMC Pumps Up Mainframe Intelligence, Security, and DevOps

BMC unveils new capabilities and enhancements for its Automated Mainframe Intelligence (AMI) and Compuware portfolios to protect mainframe customers' uptime and availability, defend the mainframe against cybersecurity threats, and advance enterprise DevOps.

Gears

Ivanti Neurons Platform Provides Automation between Service Management and SecOps

Ivanti enhances the capabilities of its flagship Enterprise Service Management (ESM) portfolio with greater automation capabilities between service management and SecOps.