Endor Labs launches an agentic AI-powered SAST tool that drastically reduces false positives, identifies deeper code flaws and helps DevSecOps teams secure AI-generated code across 40+ languages.
appCD Launches Platform to Securely Provision Cloud Infrastructure
appCD’s platform analyzes an application about to be deployed and automatically generates the code to provision the required infrastructure.
5 Security Threats DevOps Teams Should Know
DevOps security (DevSecOps) is about breaking down silos and promoting open collaboration across teams.
Legit Security Applies AI to Detect Vulnerable Application Secrets
Legit Security expanded the scope of its ASPM platform to make use of AI to discover vulnerable application secrets more accurately.
HashiCorp Acquires BluBracket to Extend Secrets Management Reach
HashiCorp this week acquired BluBracket to add a set of static secrets discovery tools to its portfolio.
Mobb Launches Community Edition of Automated Remediation Tool
Mobb today made available a free community edition of a namesake tool that creates fixes to open source vulnerabilities. The fixes are based on the results of code scanning by […]
Software Supply Chain Risk Management: A 2023 Guide
Software supply chain risk management (SSCRM) refers to the process of identifying, assessing and mitigating risks associated with third-party software components and services that are integrated into software products. SSCRM […]
The Scariest Things About SCA
It is a time of ghouls, mischievous spirits and David S. Pumpkins. In the spirit of Halloween, here are the top five scariest limitations of software composition analysis (SCA) tools […]
Cycode Expands Scope of AppDev Security Platform
At the Black Hat USA 2022 conference, Cycode this week announced it has added static application security testing (SAST) and container scanning capabilities to its software composition analysis (SCA) platform that […]
CodeLogic Toolkit Increases Visibility Into App Dependencies
CodeLogic launched today a toolkit that enables developers to scan binaries, runtime application behavior and database connections and then leverage graph technology to identify connections and dependencies in real-time. Brian […]








