BSIMM9: Hot off the presses and better than ever

Have you heard of the BSIMM? If you have, you know it’s the best way to measure your software security initiative (SSI) year after year to see how it’s evolving and how you compare to your peers. If you haven’t, you’re in luck: … Continue reading BSIMM9: Hot off the presses and better than ever

Webinar: Static analysis helps DevOps teams maintain velocity securely

Static application security testing (SAST) is the process of examining source code for security defects. SAST is one of many checks in an application security assurance program designed to find and fix security vulnerabilities early in the DevOps proce… Continue reading Webinar: Static analysis helps DevOps teams maintain velocity securely

What’s so special about zero-day vulnerabilities?

You may have heard about the zero-day vulnerability in the Tor Browser that was disclosed yesterday. It’s a big deal, and not just because of the ethics of buying and selling undisclosed vulnerabilities. Many people who use Tor Browser do so beca… Continue reading What’s so special about zero-day vulnerabilities?