Veracode today released its findings from its annual State of Software Security Report, which revealed that the persistent use of components in software development is creating unmanaged risk. The report also found that companies can benefit if they accelerate their application security programs. Veracode found that a single popular component with a critical vulnerability spread … continue reading
Veracode announced Developer Sandbox today, a new feature that allows developers and security risk teams to have more control over their application security processes. With this feature, developers can review security processes early in the development life cycle, and they have the ability to scan full applications or components as they write them. This allows … continue reading
It’s no secret that computer security is a difficult area of expertise. At the annual RSA Conference in San Francisco this week, attendees were treated to a host of solutions to solve their security woes. As usual, however, software development is not the focus. Robert Griffin, chief security architect at RSA, agreed that developing secure … continue reading
Software developers still reeling from the constant security failures throughout the open-source stack in 2014 can take at least some comfort from the proceedings at this year’s RSA Conference in San Francisco. Most of the solutions, talks and products discussed at the show are not focused on the developer-induced security flaws that caused such a … continue reading
A tour of Boston’s high-tech corridor offers a snapshot of the application development market … continue reading
New approaches to security for enterprise applications focus on everything outside of the programmer that can be secured … continue reading
Personal devices on networks and Anonymous dominated discussion, while talk of locking down networks ceased … continue reading
Cross-site scripting can pose a significant problem, but Veracode has devised a system to easily fight them … continue reading
Tests can be run at any point in the development life cycle by using SecurityReview’s Upload APIs … continue reading
The new service from Veracode can perform quick intelligence service checks on software for dynamic or manual testing … continue reading