NightVision Launches Application Testing Solution
May 30, 2024

NightVision launched a new software testing and security solution that enables developers to identify, locate, and remediate exploitable vulnerabilities throughout the software development lifecycle (SDLC).

Software developers can set up and run scans within minutes and receive intelligence on critical vulnerabilities and where they reside.

NightVision's modern gray-box security testing approach is designed to remediate software vulnerabilities long before production to reduce development costs, bolster security and resiliency, and ease the burdens on developer and security teams.

"For years, we have failed to provide software developers with testing tools to perform quickly and accurately. The shortcomings of the AppSec market have put us in the software insecurity predicament we find ourselves in today," said George Prince, CEO of NightVision. "The Secure By Design movement has popularized the concept of making the default route during the SDLC secure by providing safe building blocks for developers. The foundation of these secure defaults should be dynamic testing, prioritizing the risks that are actually exploitable in an application. Our focus is simple: Provide quick and easy guardrails for developers to identify and remediate critical vulnerabilities so they can continue to ship new products and features."

The NightVision AppSec solution simulates attacks to see what is actually exploitable and traces findings back to code. Key product capabilities include:

- API Identification – In real environments of fast-moving development teams, comprehensive API documentation is often absent. NightVision automatically generates detailed documentation of existing APIs to scan undocumented or under-documented APIs, making testing more accurate and comprehensive than previously possible.

- Shadow API discovery: When analyzing code before simulating attacks, shadow APIs can be uncovered via source code analysis that was not meant to be introduced to production. NightVision can discover and test these Shadow APIs that are often ungoverned, perform higher privileged functions, and previously have not been tested for security issues.

- Pinpoints Vulnerable Code -- NightVision identifies issues at the exact area(s) of code in the dev environment so developers don't have to spend time chasing down or validating vulnerability reports, saving money and precious engineering resources.

- The Attacker POV -- Developers can locate vulnerabilities at the origin with the exact area of code highlighted to get a perspective on applications the way attackers would.

- Comprehensive Scans -- Thoroughly scan apps on public and private networks for full coverage and run comprehensive scans within 3-10 minutes to share insightful results throughout the organization. Google Firing Range tests show a 200% higher coverage than the closest competitor.

- Seamless Integration – Integrate directly into the Continuous Integration/Continuous Delivery (CI/CD) pipeline to scan each pull request in minutes. Create a frictionless cycle between development and security teams through easy workflows.

- Plug-and-Play Testing – Developers need little to no custom coding during scan set-up, and then comprehensive scans are completed within minutes through cloud-enabled simultaneous parallel scanning.

"To say that AI has exponentially increased the speed of software development and the spread of bad and vulnerable code is an understatement," said Kinnaird McQuade, NightVision CTO and co-founder. "The software-based attacks we have seen over recent years are child's play compared to what we could see if AppSec testing solutions don't perform quicker and more comprehensively."

Share this

Industry News

January 30, 2025

OutSystems announced the general availability (GA) of Mentor on OutSystems Developer Cloud (ODC).

January 30, 2025

Kurrent announced availability of public internet access on its managed service, Kurrent Cloud, streamlining the connectivity process and empowering developers with ease of use.

January 29, 2025

MacStadium highlighted its major enterprise partnerships and technical innovations over the past year. This momentum underscores MacStadium’s commitment to innovation, customer success and leadership in the Apple enterprise ecosystem as the company prepares for continued expansion in the coming months.

January 29, 2025

Traefik Labs announced the integration of its Traefik Proxy with the Nutanix Kubernetes Platform® (NKP) solution.

January 28, 2025

Perforce Software announced the launch of AI Validation, a new capability within its Perfecto continuous testing platform for web and mobile applications.

January 28, 2025

Mirantis announced the launch of Rockoon, an open-source project that simplifies OpenStack management on Kubernetes.

January 28, 2025

Endor Labs announced a new feature, AI Model Discovery, enabling organizations to discover the AI models already in use across their applications, and to set and enforce security policies over which models are permitted.

January 27, 2025

Qt Group is launching Qt AI Assistant, an experimental tool for streamlining cross-platform user interface (UI) development.

January 27, 2025

Sonatype announced its integration with Buy with AWS, a new feature now available through AWS Marketplace.

January 27, 2025

Endor Labs, Aikido Security, Arnica, Amplify, Kodem, Legit, Mobb and Orca Security have launched Opengrep to ensure static code analysis remains truly open, accessible and innovative for everyone:

January 23, 2025

Progress announced the launch of Progress Data Cloud, a managed Data Platform as a Service designed to simplify enterprise data and artificial intelligence (AI) operations in the cloud.

January 23, 2025

Sonar announced the release of its latest Long-Term Active (LTA) version, SonarQube Server 2025 Release 1 (2025.1).

January 23, 2025

Idera announced the launch of Sembi, a multi-brand entity created to unify its premier software quality and security solutions under a single umbrella.

January 22, 2025

Postman announced the Postman AI Agent Builder, a suite empowering developers to quickly design, test, and deploy intelligent agents by combining LLMs, APIs, and workflows into a unified solution.

January 22, 2025

The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, announced the graduation of CubeFS.