📰 Software Security News
Page 43 - Software Security News Today
Fast, Ad-Free News Updates
Stay updated with breaking news from Software Security. Real-time updates on events, politics, business and more.
April 21, 2021
LinkedIn The goal of a software security program is not to find security vulnerabilities; it is to find and fix security vulnerabilities. If you’ve got flaw details describing the vulnerabilities in your code, but dont have the context needed to address them – you don’t have what you need to lower your risk of breach. Its like getting an x-ray, and then only receiving the radiologists report with no context or guidance from a doctor. Youve got all the details, but dont know what to do wi...
April 16, 2021
LinkedIn The goal of a software security program is not to find security vulnerabilities; it is to find and fix security vulnerabilities. If you’ve got flaw details describing the vulnerabilities in your code, but dont have the context needed to address them – you don’t have what you need to lower your risk of breach. Its like getting an x-ray, and then only receiving the radiologists report with no context or guidance from a doctor. Youve got all the details, but dont know what to do wi...
April 7, 2021
BankInfoSecurity May 5, 2021 Twitter The pace of digital transformation has reached a speed never before seen, forcing organizations into an “adapt or die” situation. Software is at the center of it all, placing increased pressure on DevOps leaders, AppSec managers, and developers to develop and deploy software faster to keep their organizations digitally competitive and relevant. However, this need for speed comes at a price, as security often falls by the wayside. As the proliferation of...
March 15, 2021
A trio of security holes -- CVE-2021-27365, CVE-2021-27363, and CVE-2021-27364 -- was found by security company GRIMM researchers in an almost forgotten corner of the mainline Linux kernel. The first two of these have a Common Vulnerability Scoring System (CVSS) score above 7, which is high. While you may not have had a SCSI or iSCSI drive in ages, these 15 years old bugs are still around. One of them could be used in a Local Privilege Escalation (LPE) attack. In other words, a normal user cou...
March 12, 2021
The unearthed vulnerabilities in the Linux kernel are located in the iSCSI module used for accessing shared data storage facilities.
March 11, 2021
Security unease for digital innovators 14:00 | 11/03/2021 Security unease for digital innovators. Source: freepik.com The National Cyber Security Center (NCSC) under the Ministry of Information and Communications (MIC) on February 24 warned state-owned agencies and enterprises, commercial banks, and financial institutions about possible network attacks via VMwareâs software. Several privacy flaws in VMwareâs products vCenter, ESXi, and Cloud Foundation ...
March 10, 2021
EmEz kicked off the interview by asking Armando to introduce himself and explain to us why it is important to hear what he needs to say. Armando responded by informing us that he has a “background in technology and computer science,” and is currently in an award winning, 7-year career in the Financial Technology (FinTech) space specializing in crypto currency. He actually has his own niche crypto currency based company, “built for the recruitment industry” entitled, In 2009, whi...
March 9, 2021
Dave Ferguson, Principal Solution Architect, Veracode Traditionally, software development training falls short on security. And as enterprises embrace the “shift left” movement, that gap puts them at risk. Veracode’s Dave Ferguson discusses the gap and how Veracode’s new Security Labs was developed to fill it. In an interview with ISMG, Ferguson discusses: Findings from the latest State of Software Security report; Why developer training falls short on security; The new Security Labs i...
March 2, 2021
Quarter of Healthcare Apps Contain High Severity Bugs. Veracode urges more regular scanning of applications
January 28, 2021
Over the past 11 years, Veracode has explored the challenges in secure application development against the backdrop of new threats and evolving expectations in the