DevSecOps

June 11, 2024

To help organizations navigate the myriad issues and challenges that arise when embedding security into the DevOps process and provide a path to success, the Cloud Security Alliance (CSA), together with Software Assurance Forum for Excellence in Code (SAFECode), drafted a series of white papers based on six critical pillars described in CSA's Reflexive Security Framework ...

June 06, 2024

API security requires a holistic approach to the design, implementation, maintenance, and lifecycle management of all things API. With API traffic making up almost 70% of all Internet traffic, they are a lucrative target for cybercriminals. 84% of organizations admit they don’t currently have advanced API security in their stack, so it’s unsurprising that API-related security incidents cost global businesses as much as $75 billion annually ...

June 03, 2024

There is no way to overestimate the significance of strong application security in the quickly changing digital world ... In this blog, we explore some key trends shaping the landscape of application security testing services in 2023 ...

May 31, 2024

In Episode 62 of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler from EMA discuss the cybersecurity careers in the market right now ...

May 24, 2024

In Episode 61 of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler from EMA discuss the importance of understanding the human side of cybersecurity ...

May 23, 2024

The 2024 Cloud Security Report from Cybersecurity Insiders and Check Point is now available for download. The new report draws on the experience and perspective of over 800 cloud and cybersecurity professionals to provide a deep look at the current state of cloud security. We asked these industry experts to evaluate the effectiveness of their existing security measures and to report on the adoption of the latest security solutions at their companies. Taken all together, these insights provide a comprehensive view of the big opportunities and persistent challenges of cloud security ...

May 17, 2024

In Episode 60 of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler from EMA recap the 2024 RSA Conference ...

May 13, 2024

Managing and securing your software supply chain is vital to delivering reliable, trusted releases in today's software world. With the constant growth of open-source components, assessing your organization's ability to manage them is crucial. To help you prepare, JFrog compiled a report ...

May 09, 2024

Open source projects thrive on community contributions, but this openness can be a double-edged sword. Consistency, collaboration, and diligence are critical when prioritizing open source security. Still, questions linger about the impact of new trends and developments on OSS security best practices and the wider community ...

May 08, 2024

A surprising amount of organizations aren't embracing automation when it comes to securing cloud deployments, according to the State of DevSecOps 2024 report from Datadog ...

May 07, 2024

Gartner predicts that 75% of employees will acquire, modify, or create technology outside IT's visibility by 2027. That statistic is staggering, but it's not new. Developers inherently want to use the best, most efficient tool for the task, even if it's not within the company's approved tech stack ...

May 03, 2024

In Episode 59 of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler from EMA celebrate Star Wars Day and discuss how the evil Empire failed due to security immaturity ...

April 26, 2024

In Episode 58 of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler from EMA preview the 2024 RSA conference ...

April 25, 2024

Remember that troublesome Terraform misconfiguration that leaked sensitive keys? Security incidents like that are the stuff of developer nightmares. Safeguarding our Infrastructure as Code (IaC) becomes a non-negotiable part of the DevSecOps game. Policy as Code (PaC) steps in to assist us in staying ahead of the curve with the sheer volume of IaC templates, scripts, and modules. Here are five steps to securing IaC with PaC ...

April 19, 2024

In Episode 57 of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler from EMA discuss IoT vulnerabilities for consumers ...

April 18, 2024

The runaway train of change continues at a relentless pace in the world of IT infrastructure. As computing drives from on-premises to the cloud out to the edge, the proliferation of devices shows no sign of letting up either ... What does this mean for DevOps? ...

April 12, 2024

In Episode 56 of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler from EMA discuss tax fraud and how to be aware of it ...

April 09, 2024

As companies grapple with the rapid integration of AI into web applications, questions of risk mitigation and security are top of mind. AI-infused coding and secure defaults offer the potential for improved security, but organizations are still challenged with practical steps beyond just writing intent into policies and procedures. Further there are unique challenges with consumer-facing models not related to work, but something that must be managed as part of the growing attack surface ...

April 08, 2024

Using open source software has many benefits for organizations. It fosters transparency and innovation, provides flexibility and customization, cuts cost on development and enables collaboration among other developers. However, organizations could open themselves up to risks if the open source software isn't developed securely ...

April 05, 2024

In Episode 55 of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler from EMA discuss the latest Linux SSH attacks and their impact on supply chain ...

April 04, 2024

Recently, platform engineering has become the next big thing, sparking interest in its focus on developing self-service internal developer platforms (IDPs) for streamlined software delivery and lifecycle management ... In platform engineering, the platform is supported by layered services or tools, created and maintained by a dedicated product team, designed to help the needs of software developers by essentially stitching together components to create a frictionless developer experience ...

April 01, 2024

Today, more than 98% of websites around the world use JavaScript as their go-to client-side coding language. But this use introduces challenges — today the average web page has more than 60 third-party scripts that are unmonitored and have uncontrolled access to forms and data anywhere on the page. Here are four examples of challenges businesses are facing as a result ...

March 29, 2024

In Episode 54 of the Cybersecurity Awesomeness Podcast, Chris Steffen and Ken Buckler from EMA discuss a recent phishing attack at EMA, and what organizations can do about phishing ...

March 28, 2024

Over 80% of survey respondents indicated that a critical security issue in deployed software impacted their DevOps delivery schedule in the last year, according to the Global State of DevSecOps 2023 report from Synopsys ...

March 27, 2024

Software developers are showing an unprecedented surge of interest in generative AI, with topic engagement in GPTs — a family of artificial intelligence models — increasing 3,600% year over year, according to O'Reilly's Technology Trends for 2024 report ...

Pages