Email Alerts
-
Adobe focuses on secure software development lifecycle
With its popular software increasingly targeted by hackers, Adobe has stepped up efforts to secure its applications. Article
-
Former @stake researcher Aitel insists on data classification
Know your data before turning to the cloud, says Dave Aitel, CTO of Immunity Inc. Aitel criticized traditional security technologies at FIRST Conference 2010. Article
-
Static source code analysis tools: Pros and cons
Static source code analysis tools can greatly improve application security, but it takes knowledge and expertise to use them correctly. Expert Michael Cobb explains why. Ask the Expert
-
Gary McGraw on software security research
Gary McGraw and Sammy Miguez of CIgital talk about the latest version of the Building Security in Maturity Model (BSIMM). Thirty major companies were interviewed to find out how the firms implement security into their processes. News
-
Cigital expands software security model, includes data from 30 major firms
The Building Security in Maturity Model is free and includes a framework that outlines the best practices used at major companies. Article
-
Researchers aim to smarten Web application security scanners
Adding the "human element" to scanners could help pen testers evaluate a larger portion of an application's attack surface, according to two researchers at SOURCE Boston 2010. Article
-
Metasploit creator sees no end to software security vulnerability issues
Metasploit creator and vulnerability expert H.D. Moore says secure coders are doing a better job creating applications with fewer bugs, but an ever increasing number of applications leaves no shortage in the number of new software vulnerabilities. In... Interview
-
Secure software development lifecycle still lacking at dev firms
Survey finds more firms adding security into the software development lifecycle, still many fail to use a formal methodology. Article
-
Google researchers out kernel bugs in Windows, Linux and VMware
Google engineers find 20 kernel flaws, half of which are still not patched. Article
-
fuzz testing (fuzzing)
Fuzz testing or fuzzing is a technique used by ethical hackers to discover security loopholes in software, operating systems or networks by massive inputting of random data to the system in an attempt to make it crash... (Continued) Definition
Security Management Strategies for the CIO