Topic: security

premium The importance of security testing

With more development teams today using open-source and third-party components to build out their applications, the biggest area of concern for security teams has become the API. This is where vulnerabilities are likely to arise, as keeping on top of updating those interfaces has lagged. In a recent survey, the research firm Forrester asked security … continue reading

Open source in 2024: Tackling challenges related to security, AI, and long-term sustainability

The first piece of open source code was published just over 70 years ago, and now open-source software finds itself in almost every application that exists today.  A 2024 report from Synopsys found that the average application has over 500 open source components in it, and most recent industry reports show that over 95% of … continue reading

Google Safe Browsing now performs real-time checks in privacy-preserving manner

Google has announced a new way to further protect its privacy-minded users who are browsing using Google Safe Browsing, which is a Google Search setting that warns users when they may be entering a potentially dangerous site.  While it has warned users about harmful sites across 5 billion devices since its launch 15 years ago, … continue reading

New Relic adds proof-of-exploit reporting to its IAST tool

New Relic has introduced enhanced features to its Interactive Application Security Testing (IAST) tool, including a novel proof-of-exploit reporting function for more effective application security testing.  This update allows New Relic’s users to pinpoint exploitable vulnerabilities within their applications, allowing them to replicate issues for easier remediation before they release new software versions. This advancement … continue reading

Biden-Harris Administration to require secure software development attestation form for government software

As part of its ongoing efforts to improve cybersecurity, the Biden-Harris Administration has announced that it has approved a secure software development attestation form. The form, which was jointly developed by CISA and the Office of Management and Budget (OMB), will be required to be filled out by any company providing software that the Government … continue reading

WSO2 updates Identity Server with a new API that allows for browser-less authentication

WSO2 is updating its open-source identity and access management (IAM) software, Identity Server. Key highlights of Identity Server 7.0 include a new authentication API, a new visual editor, and one-click access to application templates. The new authentication API allows developers to build authentication flows that happen directly in an application rather than redirecting to a … continue reading

Report: Security suffering due to a “zombie code” apocalypse

A majority of codebases contain outdated components, or “zombie code,” which can result in unpatched vulnerabilities lingering long after they should have been fixed. According to Synopsys’ Open Source Security and Risk Analysis report, which was released today, 91% of codebases contain components that are at least 10 versions out-of-date. Furthermore, 49% of codebases contain … continue reading

White House recommends software be written in memory safe languages to improve cybersecurity

The White House Office of the National Cyber Director (ONCD) is calling on technology leaders to work together to reduce the software attack surface by adopting memory safe programming languages. Memory safety bugs are one of the most prevalent security issues over the last few decades, according to a report published by the office. These … continue reading

OpenSSF shares progress for its Alpha-Omega project in 2023

The Open Source Security Foundation (OpenSSF) released the annual report for its Alpha-Omega project, an initiative that focuses on identifying and remedying vulnerabilities within source code to create a safer digital environment.  According to OpenSSF, the Alpha-Omega project has become a pivotal player in enhancing the security infrastructure of open-source software, reflecting a proactive approach … continue reading

Apple makes changes to iOS, Safari, and App Store in response to EU’s Digital Markets Act

Apple has announced significant updates to iOS, Safari, and the App Store, specifically for the European Union, in response to the Digital Markets Act (DMA).  These updates encompass over 600 new APIs, enhanced app analytics, support for alternative browser engines, and more options for app payment processing and iOS app distribution. These changes aim to … continue reading

O’Reilly finds 3,600% increase in interest in generative AI in last year

It’s no surprise that people have grown more interested in AI over the last year. The technology insights company O’Reilly has just published its annual trends report, in which it revealed just how much more interest people have these days. According to the findings, interest in GPT and generative AI has grown 3,600% year over … continue reading

Quest Software unveils new standalone Toad Data Studio solution to simplify database management and analysis

Quest Software, a provider of systems management, data protection, and security software, has announced the general availability of Toad Data Studio. This all-in-one platform is designed to streamline database management across multi-database platform environments. The release comes at a time when the complexity of database infrastructure is increasing and enterprises are struggling with agility and … continue reading

DMCA.com Protection Status