Security News

IBM and Snyk: Developers must lead the charge on cybersecurity
2022-02-07 22:12

The interesting part about where IBM is actually headed is, security and what we actually do in security is about protecting the surface area. When you look at Snyk and Snyk's kind of whole ethos is to say, "Well, that's the core. That's the heart. You have to be developer-first." And the meaning of that, one of my favorite things to do is to talk to a chief security officer and say, "Yes, you're kind of here to sort of help secure the organization and you are the one likely to sign the check, but you're not the most important user of the product." Because the most important user of the product, the biggest risk we both face is the developers don't actually pick it up.

Persistent data breaches fueling developer interest in cybersecurity
2022-02-02 04:30

Interest in specific topics within cybersecurity grew significantly. Between last year's high-profile incidents involving ransomware, supply chain attacks, the exploitation of critical systems vulnerabilities and the new focus on cryptocurrency theft, it's likely that interest in cybersecurity topics will continue to climb in 2022 and beyond.

Cultivating a security-first mindset for software developers
2022-01-19 07:00

Understandably, security teams are recalibrating and sorting out where more security investments are needed in the new year. The software development community is responding to these developments and recognizes that approaching security as an afterthought encourages attacks and their resulting damages.

JavaScript developer destroys own projects in supply chain “lesson”
2022-01-11 19:54

If you were a user of either of those projects, and if you are inclined to accept any and all updates to your source code automatically without any sort of code review or testing. We've written about security holes suddenly showing up in numerous coding communities, including PHP programmers, Pythonistas, Ruby users, and NPM fans.

Need to improve application security? Reduce friction between developers and security teams
2021-12-29 05:00

"The findings confirm our belief that security teams must make improving their relationship with developers a major priority in 2022," said Harshil Parikh, CEO of Tromzo. "They can do this by making security easy for developers. This means integrating security checks into the SDLC and transitioning from security gates to security guardrails so security can become a first-class citizen once and for all."

Apple's Pegasus lawsuit a 'declaration of war' against offensive software developers, says Kaspersky director
2021-11-24 13:12

The humble PC continues to bring home the bacon for Dell, with shipments to corporate customers going through the roof, in spite of previous worries about shortages and price hikes. Things are less rosy at HP, which has been caught out by the recent collapse in Chromebook orders.

Threat actors offer millions for zero-days, developers talk of exploit-as-a-service
2021-11-17 08:33

While mostly hidden in private conversations, details sometimes emerge about the parallel economy of vulnerability exploits on underground forums, revealing just how fat of a wallet some threat actors have. If it takes too long, developers may lose the chance to make big money because competitors may come up with an exploit variant, dragging down the price.

What is wrong with developer security training?
2021-11-02 06:30

What excites a security professional is not exciting for developers because, at the end of the day, a developer needs to build, not to break. While it can be fun to find and exploit a security vulnerability, this should not be the goal of secure coding training.

Feds cuff Russian said to be developer of 'Trickbot' ransomware
2021-10-29 05:58

The US Department of Justice claims it's arrested a member of a gang that deployed the Trickbot ransomware. A heavily-redacted indictment names Vladimir Dunaev as a developer of the malware, and alleges he was "a Malware Developer for the Trickbot Group, overseeing the creation of internet browser injection, machine identification, and data harvesting codes used by the Trickbot malware".

Fintech developers dissatisfied with their current roles, a major risk for their employers
2021-10-14 03:30

Rapyd published a report conducted by 451 Research, to assess the market dynamics of fintech developers around the world. Key findings in the report include a growing demand for fintech developers to create payment applications and building in-house tools as well as general job dissatisfaction.