Security News

Regular Pen Testing Is Key to Resolving Conflict Between SecOps and DevOps
2023-02-15 09:28

As attack surfaces expand and applications become more complex, regular pen tests become a crucial component of a strong web application security posture. Pen testing is often conducted periodically, which results in a "Security sprint" every time a new test is scheduled.

Microsoft tries again to ignite interest in DevOps cloud security
2022-10-12 16:30

Microsoft is rolling out its usual host of cloud security features and services at this week's Ignite 2022 conference, with the focus on what's happening in and outside the firewall. Protecting against sensitive information being shared by teams is also a theme, according to the show briefing, although some of the newly-announced security features have been previewed with Redmond Microsoft 365 E5 license users.

Development of secure software now an imperative for global DevOps teams
2022-09-01 08:00

GitLab released the results of its annual DevSecOps survey which highlights the continued prioritization of security and compliance, investment in toolchain consolidation, and the ongoing impacts of rapid DevOps adoption. This Help Net Security video reveals how organizations continue to consolidate their DevOps toolchains and processes.

Is security becoming a priority for DevOps teams?
2022-08-24 03:30

The 2022 survey results highlight security as the highest-priority investment area for organizations, with more than half of security team members stating their organizations have either shifted security left or plan to this year. Security has surpassed even cloud computing as the number one investment area across DevOps teams at global organizations.

How to manage the intersection of Java, security and DevOps at a low complexity cost
2022-08-15 04:30

In this Help Net Security video, Erik Costlow, Senior Director of Product Management at Azul, talks about Java centric vulnerabilities and the headache they have become for developers everywhere. He touches on the need for putting security back into DevOps and how developers can better navigate vulnerabilities that are taking up all of their efforts and keeping them from being able to focus on the task at hand.

DevOps teams worry CSPs are becoming competitors
2022-04-19 18:28

Tech teams worry about protecting intellectual property in addition to managing costs and ensuring reliability when selecting a cloud service provider, according to a new report. It's not an either/or situation with 20% of companies that use a smaller cloud provider also use a hyperscaler.

The latest salary trends in the global DevOps industry
2022-04-07 03:30

Puppet revealed the findings of its report which revealed how the post-pandemic environment directly impacted DevOps salaries as organizations invest in competitive compensation and top talent. "The gradual decrease in a wage gap hopefully points to a long-term shift in pay equity. As a DevOps leader, I am inspired by this progression and I look forward to seeing more equality in wages and gender parity across DevOps overall."

DevOps market to exceed $30 billion by 2028
2022-03-30 03:00

The DevOps market is expected to surpass $30 billion by 2028, as reported in a research study by Global Market Insights. The rising demand for rapid software developments across industries is likely to further support the DevOps market growth.

Securing DevOps amid digital transformation
2022-03-22 07:00

DevOps - an all-encompassing term for automating and managing digital transformation - helps organizations succeed with digital transformation by shifting the cultural mindset of the business, breaking down silos and paving the way for continuous processes. Ensuring your organization's digital transformation and DevOps processes are secure.

Microsoft Azure DevOps revives TLS 1.0/1.1 with rollback
2022-03-15 19:24

Last November, Rajesh Ramamurthy, director of product management for Azure DevOps, announced plans to phase out support for TLS 1.0/1.1 because of the risk of protocol downgrade attacks and other TLS vulnerabilities outside Microsoft's control. TLS downgrade attacks aim to turn strong, more recent versions of TLS into weaker, earlier versions of the protocol to facilitate further exploitation.