Topic: security

Security and usability are not mutually exclusive in mobile applications

Organizations that build or maintain mobile applications have a greater responsibility than ever to secure their applications as the number of application downloads continues to grow.  3.8 billion smartphone users accounted for 218 billion app downloads in 2020 alone. Zimperium conducted a survey last year in which 250 enterprises described the security issues they  struggled … continue reading

Google Identity Services update makes it easier to implement authentication

Last year, Google announced Google Identity Services (GIS), which is a set of APIs that consolidated several identity offerings from the company. Included in the GIS development kit are the Sign in with Google button and the authentication prompt One Tap.  Now, Google is adding an authorization feature to GIS to bolster the offerings of … continue reading

Report: 64% of companies were impacted by supply chain attacks mostly due to increased OSS reliance

The software industry’s reliance on open source along with a sharp increase in open source software (OSS) dependencies helped to make supply chains a major security target. 64% of organizations were impacted by a software supply chain attack in the last year according to a recent report.   The report, The 2022 State of the Software … continue reading

Kong Enterprise 2.7 released with 25% improved performance

API company Kong announced the general availability of Kong Enterprise 2.7, which delivers 25% faster performance compared to previous versions, improved security, and streamlined workflows.  Kong Enterprise is a service connectivity platform that enables organizations to secure, connect and orchestrate their APIs and services across cloud native, hybrid and on-premise environments.  The new version achieved … continue reading

Security perimeter is no more as attack surface continues to expand

For a long time, security teams have been able to mostly rely on the safety of a security perimeter, but with things like IoT, embedded development, and now remote and hybrid work, this notion of a defensible perimeter is totally gone.  Having all of these connected devices that don’t live under one network expands the … continue reading

OpenSSF announces new project for improving supply chain security

OpenSSF announced the Alpha-Omega Project to improve the security posture of open-source software by working together with software security experts.  Microsoft and Google are supporting the project, which aims to improve global OSS supply chain security by working with project maintainers to systematically look for new, as-yet-undiscovered vulnerabilities in open source code with a $5 … continue reading

Codefresh Software Delivery Platform now generally available

Codefresh launched the Codefresh Software Delivery Platform (CSDP), which brings the Argo toolset, including Workflows, Events, CD, and Rollouts, into a single platform. Argo is an open-source project that Codefresh maintains that offers tools for running workflows and managing clusters in Kubernetes. “Enterprise-class tooling for Argo – built on GitOps best practices – enables faster … continue reading

ShiftLeft CORE gets new vulnerability identification features

Security company ShiftLeft today announced the new release of its ShiftLeft CORE platform with the Velocity Update that has new features for identifying and addressing potential vulnerabilities earlier in the software development life cycle.  New features and capabilities include the ability to perform code analysis for Kotlin apps for mobile development, which is an early-stage … continue reading

Weaveworks acquires Magalix to secure Kubernetes

Weaveworks acquired the policy-as-code startup Magalix to secure Kubernetes applications by integrating the solution into Weave GitOps.  “Enterprise customers have made it clear that trusted application delivery is critical to the success of their increasingly complex cloud native platforms,” said Alexis Richardson, the CEO of Weaveworks. “With the acquisition of Magalix, Weaveworks introduces customizable policies, … continue reading

SD Times news digest: White House Open Source Security Summit; Jetpack Window Manager release candidate; Google’s solution challenge 2022

Organizations such as the Linux Foundation, OpenSSF, Google, Akamai, and Red Hat attended a White House Summit meant to address supply chain security challenges following the recent log4j crisis.  “The open-source ecosystem will need to work together to further cybersecurity research, training, analysis, and remediation of defects found in critical open-source software projects. These plans … continue reading

SD Times news digest: DevOps Institute announces event lineup for 2022 and new certifications; GitLab security releases; Analytics for in-app events

The DevOps Institute announced its lineup for 2022 events and webinars and plans for two new DevOps certifications.  The new certifications include DevOps Practitioner and DevOps Engineering Foundation. Also, SKILup Days, SKILup Hours, and SKILup Festival 2022: A Live DevOps Educational Experience will provide insights and education needed by DevOps professionals in a wide variety … continue reading

2021 Year in Review: Microsoft

This year, Microsoft went all in on open-source and security and launched a plethora of new solutions aimed at bettering the lives of developers working remotely and on-premises.  Microsoft launched its flagship Visual Studio 2022 and .NET 6. in November. .NET 6 is a follow-up to the notable .NET 5, which merged .NET Framework and … continue reading

DMCA.com Protection Status