Topic: security

Veracode: DevSecOps is having a positive impact on security, but the state of security still has a long way to go

Even with a stronger focus on security this year, most software is still riddled with security vulnerabilities. According to Veracode’s State of Software Security (SOSS) report, 87.5 percent of Java applications, 92 percent of C++ applications, and 85.7 percent of .NET application contain at least one vulnerability. In addition, over 13 percent of applications contain … continue reading

SD Times news digest: Android Keystore, Flexera and MachineShop’s technology alliance, and Clarity

Google announced new security updates to its Android Pie Keystore. The Keystore provides cryptographic tools for securing user data. “Keystore moves the cryptographic primitives available in software libraries out of the Android OS and into secure hardware. Keys are protected and used only within the secure hardware to protect application secrets from various forms of … continue reading

SD Times news digest: Google’s security warning, Stack Decisions, and Git 2.20

Google is notifying developers about an ongoing investigation, and applications and SDKs that may be at risk for abuse. The company revealed last week two apps were removed from the Google Play Store because of evidence of attribution abuse. The company also found abuse in three ad network SDKs and have began contacting developers using … continue reading

SD Times news digest: Amazon S3 leaks, Flexera AdminStudio 2018 R3, and Databricks Apache Spark 2.4 support

AWS has added four new controls to S3 to help prevent leaks. Amazon S3 buckets and objects are private by default, but settings can be changed that make them public. “We want to make sure that you use public buckets and objects as needed, while giving you tools to make sure that you don’t make … continue reading

SD Times Blog: How to effectively build a security awareness program for your organization

At the Infosecurity North America conference in New York City this week, a group of security executives from various organizations came together to talk about the key features of successful security awareness programs. All panelists stressed the importance of developing a strategy that is tailored to their individual organization. Matt Nappi, CISO at Stony Brook … continue reading

SD Times news digest: SignalFx Microservices APM, Dart 2.1, and Bugcrowd’s pen testing solution

Cloud monitoring company SignalFx has revealed SignalFx Microservices APM, which is a new application performance monitoring solution designed for DevOps teams. The solution is built on top of the company’s streaming analytics platform, giving it access to power data analytics. “The world happens in real-time and if something goes wrong, finding problems minutes later just … continue reading

Going to school on open-source security

Open-source software forms the backbone of most modern applications. According to the 2018 Black Duck by Synopsys Open Source Security and Risk Analysis Report, 96 percent of the 1,100 commercial applications that the company audited for the survey contained open-source components, with each application containing an average of 257 open-source components. In addition, on average, … continue reading

SD Times open-source project of the week: Infosys DevOps Platform

Infosys has released what it calls a enterprise-class integrated DevOps platform into open source. According to the company’s Chief Operating Officer Pravin Rao, “enterprises pursuing digital transformation require Agile and DevOps at scale to rapidly adopt new technologies, transform legacy systems and respond swiftly to new requirements.” The Infosys DevOps Platform is meant to address … continue reading

SD Times news digest: Neo4j raises $80 million, Amazon Future Engineer and Google’s new security controls

Graph database solution provider Neo4j has closed an Series E round of funding at $80 million. This brings the company’s total growth funding to $160 million since 2007. The funding will be used to help the company power business applications with graph databases as well as increase the product to support popular use cases such … continue reading

Using machine learning and AI to develop API-based security solutions

Application security threats continue to increase in sophistication and number as the technologies that enable them do as well. There have been reports of a 12 percent increase in banking trojans. Twenty-three percent increase in spyware. Twenty-two percent increase in botnets and other crypto mining malicious apps. While there are tools and technologies available to … continue reading

Data Theorem launches API security solution for serverless and microservices

The rise of microservices and serverless applications has enabled developers to build apps at scale and with less complexity at lower costs. But these new modern apps also come with a new set of issues and problems developers have to be concerned about. Data Theorem today announced new automated API solutions aimed at addressing threats … continue reading

Transitioning from DevOps to Rugged DevOps: Avoiding the pitfalls

As many as four out of five companies leveraging a DevOps approach to software engineering do so without integrating the necessary information security controls, underscoring the urgency with which companies should be evaluating “Rugged” DevOps (also known as “shift left”) to build security into their development life cycle as early as possible. Rugged DevOps represents … continue reading

DMCA.com Protection Status