NightVision Launches Application Testing Solution
May 30, 2024

NightVision launched a new software testing and security solution that enables developers to identify, locate, and remediate exploitable vulnerabilities throughout the software development lifecycle (SDLC).

Software developers can set up and run scans within minutes and receive intelligence on critical vulnerabilities and where they reside.

NightVision's modern gray-box security testing approach is designed to remediate software vulnerabilities long before production to reduce development costs, bolster security and resiliency, and ease the burdens on developer and security teams.

"For years, we have failed to provide software developers with testing tools to perform quickly and accurately. The shortcomings of the AppSec market have put us in the software insecurity predicament we find ourselves in today," said George Prince, CEO of NightVision. "The Secure By Design movement has popularized the concept of making the default route during the SDLC secure by providing safe building blocks for developers. The foundation of these secure defaults should be dynamic testing, prioritizing the risks that are actually exploitable in an application. Our focus is simple: Provide quick and easy guardrails for developers to identify and remediate critical vulnerabilities so they can continue to ship new products and features."

The NightVision AppSec solution simulates attacks to see what is actually exploitable and traces findings back to code. Key product capabilities include:

- API Identification – In real environments of fast-moving development teams, comprehensive API documentation is often absent. NightVision automatically generates detailed documentation of existing APIs to scan undocumented or under-documented APIs, making testing more accurate and comprehensive than previously possible.

- Shadow API discovery: When analyzing code before simulating attacks, shadow APIs can be uncovered via source code analysis that was not meant to be introduced to production. NightVision can discover and test these Shadow APIs that are often ungoverned, perform higher privileged functions, and previously have not been tested for security issues.

- Pinpoints Vulnerable Code -- NightVision identifies issues at the exact area(s) of code in the dev environment so developers don't have to spend time chasing down or validating vulnerability reports, saving money and precious engineering resources.

- The Attacker POV -- Developers can locate vulnerabilities at the origin with the exact area of code highlighted to get a perspective on applications the way attackers would.

- Comprehensive Scans -- Thoroughly scan apps on public and private networks for full coverage and run comprehensive scans within 3-10 minutes to share insightful results throughout the organization. Google Firing Range tests show a 200% higher coverage than the closest competitor.

- Seamless Integration – Integrate directly into the Continuous Integration/Continuous Delivery (CI/CD) pipeline to scan each pull request in minutes. Create a frictionless cycle between development and security teams through easy workflows.

- Plug-and-Play Testing – Developers need little to no custom coding during scan set-up, and then comprehensive scans are completed within minutes through cloud-enabled simultaneous parallel scanning.

"To say that AI has exponentially increased the speed of software development and the spread of bad and vulnerable code is an understatement," said Kinnaird McQuade, NightVision CTO and co-founder. "The software-based attacks we have seen over recent years are child's play compared to what we could see if AppSec testing solutions don't perform quicker and more comprehensively."

Share this

Industry News

March 27, 2025

webAI and MacStadium(link is external) announced a strategic partnership that will revolutionize the deployment of large-scale artificial intelligence models using Apple's cutting-edge silicon technology.

March 27, 2025

Development work on the Linux kernel — the core software that underpins the open source Linux operating system — has a new infrastructure partner in Akamai. The company's cloud computing service and content delivery network (CDN) will support kernel.org, the main distribution system for Linux kernel source code and the primary coordination vehicle for its global developer network.

March 27, 2025

Komodor announced a new approach to full-cycle drift management for Kubernetes, with new capabilities to automate the detection, investigation, and remediation of configuration drift—the gradual divergence of Kubernetes clusters from their intended state—helping organizations enforce consistency across large-scale, multi-cluster environments.

March 26, 2025

Red Hat announced the latest updates to Red Hat AI, its portfolio of products and services designed to help accelerate the development and deployment of AI solutions across the hybrid cloud.

March 26, 2025

CloudCasa by Catalogic announced the availability of the latest version of its CloudCasa software.

March 26, 2025

BrowserStack announced the launch of Private Devices, expanding its enterprise portfolio to address the specialized testing needs of organizations with stringent security requirements.

March 25, 2025

Chainguard announced Chainguard Libraries, a catalog of guarded language libraries for Java built securely from source on SLSA L2 infrastructure.

March 25, 2025

Cloudelligent attained Amazon Web Services (AWS) DevOps Competency status.

March 25, 2025

Platform9 formally launched the Platform9 Partner Program.

March 24, 2025

Cosmonic announced the launch of Cosmonic Control, a control plane for managing distributed applications across any cloud, any Kubernetes, any edge, or on premise and self-hosted deployment.

March 20, 2025

Oracle announced the general availability of Oracle Exadata Database Service on Exascale Infrastructure on Oracle Database@Azure(link sends e-mail).

March 20, 2025

Perforce Software announced its acquisition of Snowtrack.

March 19, 2025

Mirantis and Gcore announced an agreement to facilitate the deployment of artificial intelligence (AI) workloads.

March 19, 2025

Amplitude announced the rollout of Session Replay Everywhere.

March 18, 2025

Oracle announced the availability of Java 24, the latest version of the programming language and development platform. Java 24 (Oracle JDK 24) delivers thousands of improvements to help developers maximize productivity and drive innovation. In addition, enhancements to the platform's performance, stability, and security help organizations accelerate their business growth ...