Application Security
GitHub makes push protection generally available to warn developers whenever they include a secret in a commit.
Hi, what are you looking for?
As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.
GitHub makes push protection generally available to warn developers whenever they include a secret in a commit.
Open banking can be described as a perfect storm for cybersecurity. At one end, small startups with financial acumen but little or no security...
CISA has opened proposed guidance for secure software development to public review and comment.
Apiiro’s Risk Graph Explorer helps security teams to understand their application attack surface.
GitHub this week introduced NPM package provenance and deployment protection rules and announced general availability of private vulnerability reporting.
VMware warns of two critical vulnerabilities -- CVE-2023-20864 and CVE-2023-20865 -- in the VMware Aria Operations for Logs product.
Boston-based Mobb has raised $5.4 million in seed funding for a product that automatically fixes vulnerabilities found in applications developed by customers.
Adobe documents 56 security defects in multiple products, some serious enough to expose Windows and macOS users to code execution attacks.
Consulting giant KPMG spins out a startup building technology to secure AI (artificial intelligence) applications and deployments.
OpenSSL 1.1.1 will reach EoL in six months and users are instructed to either upgrade to a newer version or pay for extended support...
Twitter sent a copyright notice to code hosting service GitHub to request the removal of a repository that contained Twitter source code.
Backslash Security banks seed-stage capital to build new technology to identify and mitigate “toxic code flows” in cloud-native applications.
Black Lantern Security introduces Badsecrets, an open source tool for identifying known or weak cryptographic secrets across multiple platforms.
GitHub this week made secret scanning generally available and free for all public repositories.
While there are many routes to application security, bundles that allow security teams to quickly and easily secure applications and affect security posture in...
GitHub this week announced the revocation of three certificates used for the GitHub Desktop and Atom applications.
PayPal is alerting roughly 35,000 individuals that their accounts have been targeted in a credential stuffing campaign.
Drupal released updates that resolve four vulnerabilities in Drupal core and three plugins.
A new report finds that barely 1% of all SBOMs being generated today meets the “minimum elements” defined by the U.S. government.
A CSRF vulnerability in the source control management (SCM) service Kudu could be exploited to achieve remote code execution in multiple Azure services.