Google Cloud Launches Security Command Center Enterprise
InfoQ » DevSecOps
by
1M ago
Google Cloud has launched Security Command Center (SSC) Enterprise, a cloud risk management solution that offers proactive cloud security with enterprise security operations. The solution helps customers manage and mitigate risk across multi-cloud environments and is enhanced by Mandiant expertise ..read more
Visit website
OpenSSF Adds Attestations to SBOMs to Validate How Software is Built
InfoQ » DevSecOps
by
3M ago
The Open Source Security Foundation (OpenSSF) has recently announced SBOMit, a tool designed to bolster Software Bills of Materials (SBOMs) with in-toto attestations. This development, announced under the OpenSSF Security Tooling Working Group, increases transparency and security in the software development process ..read more
Visit website
Cloudflare, Google and AWS Disclose HTTP/2 Zero-Day Vulnerability
InfoQ » DevSecOps
by
6M ago
On October 10th, Cloudflare, Google, and AWS disclosed a novel zero-day vulnerability attack known as the "HTTP/2 Rapid Reset." This attack exploits a weakness in the HTTP/2 protocol to generate enormous Distributed Denial of Service (DDoS) attacks, up to almost 400 million requests per second (rps ..read more
Visit website
AI a “Must-Have” in GitLab’s 2023 Global DevSecOps Report
InfoQ » DevSecOps
by
7M ago
GitLab has released their 2023 Global DevSecOps AI report, with the key finding that AI and ML use is evolving from a "nice-to-have" to a "must-have". The report shows that 23% of organizations are already using AI in software development, and of those, 60% are using it daily. Furthermore, 65% of respondents said they are using AI and ML for testing now, or would be within the next three years ..read more
Visit website
Report Finds Heavy Use of Open-Source Solutions for Kubernetes Security
InfoQ » DevSecOps
by
1y ago
A recent survey by Armo on the use of security software solutions with Kubernetes found that over half of respondents leverage open-source tooling. Companies using open-source tooling use on average 3.6 different tools. These open-source tools were predominately used for service mesh, network policy and micro-segmentation, and misconfiguration scanning ..read more
Visit website
Snyk Announces General Availability of Snyk Cloud and Enhancements to its Platform
InfoQ » DevSecOps
by
1y ago
Snyk, a developer security platform, recently announced the general availability of their cloud security tool, Snyk Cloud, and improvements to their platform. Extending support for software bill of materials (SBOM), the improvements include new reporting capabilities and self-service resources ..read more
Visit website
Security as a Product - a Coordination Game between DevOps and InfoSec
InfoQ » DevSecOps
by
1y ago
Kelly Shortridge, a product and strategy expert in information security, has described how security should be treated as a product. Analyzing the "we mindset" and game theory she puts forth DevOps and InfoSec as a coordination game ..read more
Visit website
GitLab 13.9 Introduces Security Alerts Dashboard, Maintenance Mode, and More
InfoQ » DevSecOps
by
1y ago
The latest release of GitLab introduces over 60 new features, mostly aimed at improving support for DevSecOps at scale and better handling the complexity of automation at scale ..read more
Visit website
Attackers Found Building Malicious Container Images Directly on Host
InfoQ » DevSecOps
by
1y ago
Aqua’s cyber security research team, ‘Nautilus,’ has found a new attack technique targeting misconfigured Docker Daemon API ports to build an image directly on the target host container infrastructure, in order to mine cryptocurrency. Further investigation by the team uncovered an associated 330k malicious image pulls from an infrastructure of 23 container images stored in Docker Hub ..read more
Visit website
Improve Your Software Quality and Speed of Delivery. Learn How at InfoQ Live on July 20th
InfoQ » DevSecOps
by
1y ago
Learn how automation, continuous testing, and supply management techniques can improve software quality and speed of delivery. Get valuable insights from world-class domain experts at InfoQ Live on July 20th ..read more
Visit website

Follow InfoQ » DevSecOps on FeedSpot

Continue with Google
Continue with Apple
OR