Security News

Most AppSec pros see a growing divide between them and developers
2020-09-23 03:30

75% of AppSec practitioners and 49% of developers believe there is a cultural divide between their respective teams, according to ZeroNorth. Understanding the cultural divide and its implications Developer and AppSec practitioners don't agree on which function is responsible for the security of applications.

75% of AppSec practitioners see a growing cultural divide between AppSec and developers
2020-09-22 12:35

Thirty-nine percent of developers said the security team is responsible for securing apps, while 67% of AppSec practitioners said their teams are responsible, according to a new study. Seventy-five percent of application security practitioners and 49% of developers believe there is a cultural divide between their respective teams that could increase organizational risk, according to a new study by the Ponemon Institute and ZeroNorth, a provider of risk-based vulnerability orchestration across applications and infrastructure.

Microsoft open-sources tool that enables continuous developer-driven fuzzing
2020-09-16 10:31

Microsoft has open-sourced OneFuzz, its own internal continuous developer-driven fuzzing platform, allowing developers around the world to receive fuzz testing results directly from their build system. Fuzzing is an automated software testing technique that involves entering random, unexpected, malformed and/or invalid data into a computer program.

Review: Web Security for Developers: Real Threats, Practical Defense
2020-09-15 03:30

After a short lesson in internet history, the author puts the reader in the shoes of the attacker and explains how simple it is to hack a website, as well as how easy it is to obtain and apply hacking tools. The author proceeds to offer basic knowledge about how the internet, browsers, web servers and programmers work.

Developer Security Firm Snyk Raises $200 Million at $2.6 Billion Valuation
2020-09-09 15:32

Boston-based developer security company Snyk on Wednesday announced that it has raised $200 million in a Series D funding round, valuing the firm at more than $2.6 billion. Snyk earned unicorn status in January 2020, after it raised $150 million in a Series C funding round.

Apple will release iOS 14 without this privacy feature: What iPhone users and developers need to know
2020-09-04 23:07

The iOS 14, iPadOS 14, and tvOS 14 anti-tracking feature is on hold until early 2021 to give developers time to make the necessary changes, according to Apple. Apple released iOS 14 without a new anti-tracking feature.

Lattice CrossLink-NX FPGA: Helping developers meet demand for embedded and smart vision applications
2020-09-04 01:15

Lattice helps developers meet this growing demand for embedded and smart vision applications by offering a variety of low-power FPGAs and comprehensive solutions stacks designed to enable the quick and easy implementation of applications like video signal bridging, aggregation and splitting, image processing, and the AI/ML inferencing used to train smart vision models. "Peiju Chiang, Product Marketing Manager at Lattice, said,"Lattice is a leading provider of innovative, low power solutions for smart and embedded vision applications.

The best developer-centric security products
2020-08-31 21:25

Check out this guide of the best developer-centric security products. From HashiCorp to Snyk to oso, we're finally seeing security embrace the developer class, and it couldn't have come at a more opportune time.

Medical Data Leaked on GitHub Due to Developer Errors
2020-08-26 13:49

Ursem, self-appointed "Lamest hacker you know" found the leaked info in a simple search to see if someone "Is actually stupid enough to upload medical customer data to GitHub," he told DataBreach.net. The report describes one errant developer referred to as the "Typhoid Mary of Data Leaks" because of the multiple errors and repetition of these errors in his use of GitHub in relation to not just storage and management of medical data, but other files as well.

Terrascan open source software helps developers build secure cloud infrastructure
2020-08-18 04:30

Accurics unveiled a major upgrade to Terrascan, the open source static code analyzer that enables developers to build secure infrastructure as code. The new Terrascan architecture leverages the Open Policy Agent engine from CNCF, which dramatically simplifies policy definition for developers that want to create custom policies as well as provides over 500 out-of-the-box policies for the CIS Benchmark.