Top

Category: Software Security

Software Security


Software Security

Hackers stole ancestry data of 6.9 million users, 23andMe finally confirmed

December 5, 2023

Via: Ars Technica

It has now been confirmed that an additional 6.9 million 23andMe users had ancestry data stolen after hackers accessed thousands of accounts by likely reusing previously leaked passwords. 23andMe previously disclosed in a Securities and Exchange Commission filing that 0.1 […]


Software Security

3 security best practices for all DevSecOps teams

December 4, 2023

Via: InfoWorld

It’s been over 10 years since Shannon Lietz introduced the term DevSecOps, aiming to get security a seat at the table with IT developers and operators. The question is, how far has security come since then? Do DevSecOps teams have […]


Software Security

6 security best practices for cloud-native applications

November 14, 2023

Via: InfoWorld

The emergence of cloud-native architectures has dramatically changed the ways applications are developed, deployed, and managed. While cloud-native architectures offer significant benefits in terms of scalability, elasticity, and flexibility, they also introduce unique security challenges. These challenges often diverge from […]


Software Security

eBPF Kubernetes Security Tool Tetragon Improves Performance and Stability

November 7, 2023

Via: InfoQ

Isovalent has announced the 1.0 release of Cilium Tetragon, their eBPF-based Kubernetes security observability and runtime enforcement tool. Policies and filters can be applied directly via eBPF to monitor process execution, privilege escalations, and file and network activity. Tetragon can […]


Software Security

The state of API security in 2023

November 2, 2023

Via: InfoWorld

In today’s rapidly transforming digital world, APIs have become the linchpin for quick delivery of business functionality. These digital connectors underpin much of the enterprise innovation we witness today, from seamless customer experiences to integrated partner ecosystems. Yet, as the […]


Software Security

Scaling security: How to build security into the entire development pipeline

October 31, 2023

Via: CIO

When an application is finally ready for deployment, the last thing the development team wants to hear is: “Stop! There’s a security issue.” And then, after months of painstaking work, their application launch is delayed even further. That’s why Discover® […]


Software Security

Android will now scan sideloaded apps for malware at install time

October 18, 2023

Via: Ars Technica

The Google Play Store might not be perfect for stopping Android malware, but its collection of scanning, app reviews, and developer requirements makes it a lot safer than the wider, unfiltered Internet. The world outside Google’s walled garden has no […]


Software Security

New cryptographic protocol aims to bolster open-source software security

October 5, 2023

Via: ZDnet

BastionZero’s OpenPubkey, which is a new cryptographic protocol that’s designed to fortify the open-source software ecosystem, is now a Linux Foundation open-source project. Docker is also integrating OpenPubkey, so that you can use it for container signing. This innovative cryptographic […]


Software Security

OpenSSF New Manifesto Urges the Software Industry to Take Responsibility for Open Source Security

August 31, 2023

Via: InfoQ

The Open Source Consumption Manifesto from OpenSSF aims to make the software industry more aware of its responsibility when it comes to ensuring the software supply chain remains secure and healthy. The importance of open source software today cannot be […]


Software Security

Chrome Supports Key Pinning on Android to Improve Security

August 11, 2023

Via: InfoQ

Key pinning, a technique used to prevent an attacker from tricking a vulnerable certificate authority (CA) into issuing an apparently valid certificate for a server, is now used in Chrome for Android, version 106. This helps preventing man-in-the-middle attacks against […]


Software Security

A new hope for software security

July 24, 2023

Via: InfoWorld

The Log4j vulnerability in December 2021 spotlighted the software supply chain as a massively neglected security surface area. It revealed just how interconnected our software artifacts are, and how our systems are only as secure as their weakest links. It […]


Software Security

What’s the state of Zero Trust security?

June 28, 2023

Via: CIO

Zero Trust adoption is accelerating, with over half of organizations reporting they have adopted Zero Trust Security, according to research independently conducted by leading security research firm Ponemon Institute, sponsored by Hewlett Packard Enterprise. In the report, The 2023 Global […]


Software Security

From details to big picture: how to improve security effectiveness

June 22, 2023

Via: CIO

Benjamin Franklin once wrote: “For the want of a nail, the shoe was lost; for the want of a shoe the horse was lost; and for the want of a horse the rider was lost, being overtaken and slain by […]


Software Security

Getting ahead of cyberattacks with a DevSecOps approach to web application security

June 20, 2023

Via: CIO

Web applications are foundational to a company’s business and brand identity yet are highly vulnerable to digital attacks and cybercriminals. As such, it’s vital to have a robust and forward-leaning approach to web application security. With an estimated market size […]


Software Security

Hackers Threaten to Release Reddit Data Unless API Changes Are Rolled Back

June 19, 2023

Via: MacRumors

A ransomware group that hacked into Reddit’s servers back in February is threatening to release stolen data if Reddit does not walk back its planned API changes, reports Bleeping Computer (via The Verge). At the time of the hack, no […]


Software Security

Need To Know Data Redaction Software

June 15, 2023

Via: TechBullion

In today’s Finance world, the protection of sensitive information has become paramount. With data breaches and privacy concerns on the rise, individuals and organizations alike are seeking effective solutions to safeguard their confidential data. One such solution is data redaction […]


Software Security

A Security Culture: Top Priorities for CISOs and their Teams

June 6, 2023

Via: InformationWeek

Cybercrime is increasing in efficiency, efficacy, and scale. Although organizations are frantically trying to prevent attacks from reaching their environments, there’s also an understanding that breaches are inevitable. According to IBM’s 2022 Cost of a Data Breach report, 83% of […]


Software Security

Microsoft is finally making Edge a much more secure place to surf the web

June 2, 2023

Via: TechRadar

Keeping safe online is about to get a lot easier for Edge users thanks to a major security update from Microsoft. The software giant has revealed it is working on an upgrade for its web browser that will bring “enhanced […]


Software Security

API security: key to interoperability or key to an organization?

May 31, 2023

Via: CIO

Most applications built today leverage Application Programming Interfaces (APIs), code that makes it possible for digital devices, applications, and servers to communicate and share data. This code, or collection of communication protocols and subroutines, simplifies that communication, or data sharing. […]


Software Security

Cloud-based IT operations are on the rise

May 23, 2023

Via: InfoWorld

The people who maintain traditional data center systems have always objected to having IT assets managed by systems outside their firewalls. Years ago, when I predicted that this would happen, people would often laugh and not believe me. The signs […]