Secure Development

We'll walk you through the critical step of integrating security into the software development lifecycle (SDLC). You'll hear from the experts on everything from working with developers, to the best ways to assess code for security and the latest development trends and technologies.

Developers, Never Leave Your IDE Again: Veracode Greenlight provides secure coding feedback within seconds, and within your IDE

jworthington's picture
By Janet Worthington January 25, 2017  | Secure Development
Veracode Greenlight: Security Unit Testing Inside Your IDE

To stay competitive, every company in every industry has to not only create software, but also create it fast. This pressure has most likely trickled down to your development team, which is feeling squeezed to meet ever-tighter deadlines and continually get new products and features out the door. In turn, we’re seeing the adoption of new, speedier development and deployment practices, such... READ MORE

How We’re Making Developer Training More Interactive, Flexible and Fun

eying's picture
By Emilie Ying January 24, 2017  | Secure Development
Veracode video-based developer training

Everyone knows security training is important. But many organizations struggle to make security training more effective. At Veracode, we’ve implemented several innovations to make our eLearning platform even more engaging, relevant, user-friendly and fun. Over the past five years, we have continued to add online courses to keep up with the changing climate of threats in the real world,... READ MORE

Securing DevOps: Enough With the Cynicism

jlavery's picture
By Jessica Lavery January 23, 2017  | Secure Development
Cynicism about devops is popular initially.

If an industry continuously talks about how a trend is going to be a hurdle, it becomes a hurdle. Conversely, if an industry views the trend as an opportunity and talks about it in such terms, thinking shifts toward the potential this trend brings for improvement. We are seeing this phenomenon with DevOps, but not in a good way. Security professionals are talking about the hurdles of securing... READ MORE

Top Takeaways From Veracode’s Developer Survey

jzorabedian's picture
By John Zorabedian December 21, 2016  | Secure Development

We recently conducted a survey of developers and development managers to find out what’s on their minds and how their concerns compare to those of application security teams. The results contain some surprises. What’s not surprising is that development teams are feeling pressured to meet productivity goals, while still meeting requirements for quality and stability. Add to that the... READ MORE

The Future of AppSec is DevSecOps

jlavery's picture
By Jessica Lavery December 19, 2016  | Secure Development
What's next for application security in 2017?

With 2016 coming to an end, we, like many companies, are reflecting on the trends of the past year. We are also looking outward to what the future holds for application security, and it has never been clearer that the future of application security will be tied to DevOps and integrating security into DevOps environments. As such, it is crucial that security becomes part of the entire software... READ MORE

You’re Invited: A DevOps Dinner Party

ktcampbell's picture
By Katie Campbell December 16, 2016  | Secure Development

With the holidays quickly approaching, I can’t help but think about all of the dinner parties just around the corner and the many hours of “forced family fun” as we like to call it in our house. Don’t get me wrong, I love all the dishes that get whipped up by my family members, but with that comes the fact that you need to sit around the dinner table … for hours... READ MORE

5 Ways to Keep Your Applications Safe From Vulnerable Components

TJarrett's picture
By Tim Jarrett December 1, 2016  | Secure Development

In earlier blog posts in this series, we’ve learned more about how the vulnerability used to break into the San Francisco Municipal Transportation Agency’s computers may have come from a single vulnerable open source component. We’ve talked a little about how developers use open source components – and why it’s hard for them to know what’s in their applications... READ MORE

How One Open Source Component Put Up to 25% of Java Applications at Risk

TJarrett's picture
By Tim Jarrett November 30, 2016  | Secure Development
Open Source Component Risk

In the first part of our blog series on the ransomware attack on the San Francisco Municipal Transportation Agency, we discussed how the attacker chose to exploit a deserialization vulnerability in WebLogic to compromise vulnerable systems. And we learned that this vulnerability was a big target, because it is the result of a component (Apache Commons Collections) present in about 50 percent of... READ MORE

Why the Ransomware Attack on San Francisco Is Such a Big Deal

TJarrett's picture
By Tim Jarrett November 29, 2016  | Secure Development
Ransomware attack on San Francisco Municipal Transportation Authority

The day after Thanksgiving saw the San Francisco Municipal Transportation Agency hit with a ransomware attack. The attacker demanded 100 bitcoins (about $73,000) to unlock the computer systems and ticketing machines. According to security journalist Brian Krebs, the SFMTA wasn’t targeted for political reasons – it was a target of opportunity discovered by an attacker looking for... READ MORE

Your Secure Coding Partner: Introducing Veracode AppSec Tutorials

twhite's picture
By Tyler White November 22, 2016  | Secure Development
Using Developer Pairing to Improve Productivity

The driver races ahead, attempting to stay on track as his speed is slowly increasing. Right beside him the navigator sits, guiding the driver’s efforts through his treacherous endeavor. They are both striving to keep pace with the other, as the intensity is ramping up. Everything is about to spin out of control. Then the alarm goes off, and the driver backs away from the keyboard to now... READ MORE

Love to learn about Application Security?

Get all the latest news, tips and articles delivered right to your inbox.

 

 

 

contact menu