Drupal fixes three vulnerabilities, including one RCE

Drupal’s security team has fixed three vulnerabilities in the popular content management system’s core, one of which (CVE-2020-13663) could be exploited to achieve remote code execution. Drupal is a free and open-source web content manageme… Continue reading Drupal fixes three vulnerabilities, including one RCE

New infosec products of the week: June 5, 2020

Checkmarx SCA: New SaaS-based software composition analysis solution CxSCA leverages Checkmarx’s source code analysis and automation capabilities, empowering security and development teams to identify vulnerabilities within open source software that pr… Continue reading New infosec products of the week: June 5, 2020

Cooking up secure code: A foolproof recipe for open source

The use of open source code in modern software has become nearly ubiquitous. It makes perfect sense: facing ever-increasing pressures to accelerate the rate at which new applications are delivered, developers value the ready-made aspect of open source … Continue reading Cooking up secure code: A foolproof recipe for open source

One private equity firm sells Checkmarx to another for $1 billion

The application security company Checkmarx is changing ownership again. The private equity firm Insight Partners said on Monday it will sell Checkmarx to Hellman & Friedman, another private equity company, at a valuation of $1.15 billion. Intsight has owned Checkmarx since June 2015, when investors injected $84 million into the Israeli company. Intsight will retain a significant minority stake in Checkmarx under the terms of the deal. “As cybersecurity threats continue to intensify, we strongly believe that embedding security early in the software development lifecycle is critical,” Tarim Wasim, a partner at Hellman & Friedman, said in a statement. “We look forward to building on Checkmarx’s tremendous success to date and supporting the company’s rapid growth in the years ahead.” Founded in 2006, Checkmarx says it mitigates enterprise security risk by helping developers find vulnerabilities, then fix them. The company is perhaps best known for discovering a number of bugs […]

The post One private equity firm sells Checkmarx to another for $1 billion appeared first on CyberScoop.

Continue reading One private equity firm sells Checkmarx to another for $1 billion

Checkmarx simplifies AST automation for modern development and DevOps environments

Checkmarx, the global leader in software security solutions for DevOps, announced at the RSA Conference 2020 new enhancements to its market-leading Software Security Platform to empower more seamless implementation and automation of application securit… Continue reading Checkmarx simplifies AST automation for modern development and DevOps environments

Security pitfalls to avoid when programming using an API

OWASP’s API Security Project has released the first edition of its top 10 list of API security risks. The most common and perilous API security risks API abuse is an ongoing problem and is expected to escalate in the coming years, as the number o… Continue reading Security pitfalls to avoid when programming using an API