Application Security

Farshad on the Application Security Weekly Podcast: Lessons That The XZ Utils Backdoor Spells Out
Farshad Abasi was invited once again to speak on the Application Security Weekly Podcast, hosted by Mike Shema! In this…
Threat Modeling & Risk Assessment for Developers
Threat modeling and risk assessment is a structured approach that enables an organization to identify, quantify, and address the threats…
Farshad on the Application Security Weekly Podcast: Creating the Secure Pipeline Verification Standard
Farshad Abasi recently appeared on the Application Security Weekly Podcast where he discussed the innovative Secure Pipeline Verification Standard he’s…
Farshad Discusses CI/CD Pipelines & Emerging Threats at Developer Week 2024
As modern software development practices evolve, CI/CD pipelines have emerged as a potent, yet under-secured frontier. This has resulted in…
Next-Level AppSec: Transforming Secure Development using Automation Platforms
As the rate of application adoption accelerates globally, teams are expected to produce software faster, and often under tight budget…
Application Attacks on the Rise
One alarming trend in the fintech industry is the sharp increase in application attacks. According to recent reports, 64% of…
Why Security Design Reviews are More Effective than Pentesting
Many companies rely on pentesting to achieve compliance and strengthen their security posture. However, pentesting alone cannot identify all of…
The-power-of-Threat-Modeling
The Power of Threat Modeling for Application Security
Threat modeling stands as the cornerstone of modern application security, offering a strategic approach that empowers companies to safeguard their…
How to Minimize False Positives in Automated Application Security Scans
Every time a software development team introduces new code into their Software Development Life Cycle (SDLC), it potentially opens up…
The Challenge with Using Multiple Security Scanners
Development and security teams rely on automated scanners such as SAST, SCA, DAST, and others to scan applications for bugs…