Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Security

DevSecOps trend accelerates: CIOs are changing who is responsible for cybersecurity

CIOs are remaking the IT function — no longer will security and developer teams be siloed. Recent survey data from 451 Research, part of S&P Global Market Intelligence, and published by Elastic shows a major shift in who is using application security tools, suggesting that DevSecOps is not just an idea, but a growing reality for IT decision makers. IT decision-makers allocated application security tools to 48% of development teams in 2020, compared to just 29% in 2015.

Devo's 2022 Cybersecurity Predictions: Part One

There’s only one thing that’s certain in cybersecurity: The cyberthreat landscape is constantly changing, and the tools and solutions we have at our disposal to combat cybercrime must continue evolving if we are to stay ahead of — or at least keep up with — them. As 2021 winds down, the Devo security team is already looking ahead to the most pressing cybersecurity trends likely to appear in 2022. Here are my top three predictions for the new year.

58% of customers experienced technical issues during Black Friday 2021

The shift to an online-first world, accelerated by the Covid-19 pandemic, has made more consumers choose to shop online than ever before. In 2020, more than 100 million US customers shopped online during the Black Friday weekend, resulting in a 22% increase in online spending. Netacea was interested in how people shopped online, and whether they experienced any Black Friday issues in 2021.

Detecting Log4j (Log4Shell): Mitigating the impact on your organization

At midnight last Thursday, we experienced one of the most notable infosec events in years. A new zero-day exploit in a popular logging package for Java, Log4j, was discovered. The exact origin and timeline are still being investigated, but it’s important to note that this was not just a vulnerability announcement. The information disclosed was rapidly followed by fully functional exploit code—and the exploit itself turned out to be trivial to execute.

Log4j Log4Shell Vulnerability: All You Need To Know

On December 9, 2021, a researcher from the Alibaba Cloud Security Team dropped a zero-day remote code execution exploit on Twitter, targeting the extremely popular log4j logging framework for Java. Since then, the trivially exploitable (weaponized PoCs are available publicly) and extremely popular library has reportedly been massively exploited and has gotten wide coverage on media and social networks.

Kroger Uses JFrog Xray for Software Security and License Compliance

Kroger leverages the JFrog platform to give developers visibility into their software vulnerabilities and make informed decisions on what to fix. See how Kroger has implemented secure DevOps processes with automated vulnerability scanning and open-source software (OSS) license compliance capabilities to support their development and security teams.

Slack DLP Case Study with Bluecore - Best Practices for Maintaining Slack Data Security (Part 5)

In this segment from one of our previous webinars on Slack data loss prevention (DLP), Nightfall product specialist Michael Osakwe discusses the changing role SaaS applications play in modern organizations with input from Bluecore CISO Brent Lassi about how the pandemic has changed his employees' behavior.

Slack DLP Case Study with Bluecore - Data Leakage in the Context of Slack (Part 1)

In this segment from one of our previous webinars on Slack data loss prevention (DLP), Nightfall product specialist Michael Osakwe discusses the changing role SaaS applications play in modern organizations with input from Bluecore CISO Brent Lassi about how the pandemic has changed his employees' behavior.

Slack DLP Case Study with Bluecore - Evaluating Data Exposure Risk in SaaS Tools (Part 2)

In this segment from one of our previous webinars on Slack data loss prevention (DLP), Nightfall product specialist Michael Osakwe discusses the changing role SaaS applications play in modern organizations with input from Bluecore CISO Brent Lassi about how the pandemic has changed his employees' behavior.

Slack DLP Case Study with Bluecore - The Consequences of Data Exposure in Slack (Part 4)

In this segment from one of our previous webinars on Slack data loss prevention (DLP), Nightfall product specialist Michael Osakwe discusses the changing role SaaS applications play in modern organizations with input from Bluecore CISO Brent Lassi about how the pandemic has changed his employees' behavior.