Resources
Analyst Reports, eBooks, On-Demand Webinars, White Papers & more.
- Show All
- Case Study
- eBook
- White Paper
- Reports & Solution Briefs
- Videos and Webinars
- Contrast Labs
- Podcast
- Datasheet
- Infographics
AppSec noise and fatigue by the numbers
February 16, 2022
Ensuring the AppSec and API security strategy meets the moment
February 16, 2022
Why financial services organizations need Runtime Security
February 16, 2022
The anatomy of a modern application attack
February 16, 2022
The Transformations Needed to Scale DevSecOps
February 16, 2022
The limitations of existing Application Security (AppSec) approaches
February 16, 2022
Application Detection and Response (ADR): Helping SecOps teams address NIST CSF
February 16, 2022
See how Application Detection and Response (ADR) can enhance your SecOps by addressing NIST CSF guidelines. Gain visibility into the application and API layer to protect against threats that bypass traditional controls.
Contrast Application Detection and Response (ADR)
February 16, 2022
Are you ready for DORA?
February 16, 2022
What is a vulnerability?
February 16, 2022
Strategic evolution of DevSecOps: Interview with Larry Maccherone at RSA Conference 2024
February 16, 2022
The value of Runtime Security for the financial sector: Why current Application Security approaches too often fall flat
February 16, 2022
Overview of Contrast Runtime Security Platform
February 16, 2022
The radical future of application and API testing
February 16, 2022
Building a successful security culture
February 16, 2022
Overview of the application security industry today
February 16, 2022
What you need to know about Application Security observability
February 16, 2022
Fear and Loathing in the SDLC
February 16, 2022
Developers are drowning in vulnerability reports, security teams are overwhelmed, and projects are delayed. It's time for a new approach to AppSec that empowers developers instead of hindering them.
In this article, Paul Senkel explores why traditional AppSec tools are failing in the face of modern development and how a sensor-based runtime security approach can bring back the joy of coding while keeping your applications secure.
The Case for Application Detection and Response (ADR)
February 16, 2022
Quickly scale anomaly detection across applications hosted in your AWS environment
February 16, 2022
Enhance your application security with AWS and Contrast Security. Gain real-time detection and faster vulnerability management to safeguard customer data and applications.
Executive Brief: 5 must-know facts about protecting production applications
February 16, 2022
Implementing the Gartner DevSecOps Toolchain
February 16, 2022
Application security: Five principles for 'Shifting smart'
February 16, 2022
Contrast Protect your RASP solution
February 16, 2022
Who’s Watching Your Applications and APIs Right Now?
February 16, 2022
The Value of Runtime Application with Self-Protection
February 16, 2022
Read this solution brief to learn how Contrast Protect runtime application self-protection (RASP) enhances application security. Experience real-time, precise visibility and proactive vulnerability prevention with our DevOps-native solution. Straighten your security measures without overburdening your team.
WAF and RASP: Raising the bar for application protection
February 16, 2022
The 2023 Gartner® Peer Insights™ Voice of the Customer for Application Security Testing
February 16, 2022
Contrast Security was recognized with an overall customer rating of 4.7 out of 5.0 out of 37 reviews as of August 2023 and a 94% willingness to recommend the product.
Observability: Illuminate Your Application Security
February 16, 2022
Runtime security isn’t an afterthought with Security Observability; it’s a core component. By delivering real-time visibility into the behavior of your applications and APIs while they’re in operation, potential threats are detected and neutralized before they can cause significant damage.
Contrast Assess: Revolutionizing Application Security in Modern DevOps
February 16, 2022
Contrast Named Leader in G2 Fall 2023 Grid Report for IAST, SAST and RASP
February 16, 2022
Contrast Security and Zero Trust
February 16, 2022
Implementing zero trust begins with the assumption that networked IT systems are compromised.
Whitepaper: Defense-in-depth web AppSec: The case for having both RASP and WAF
February 16, 2022
This white paper explores the value of having both RASP and WAF for web AppSec and how they can work together to provide a more comprehensive and effective approach.
Contrast Security and AWS On-Air Episode: Shift Smart
February 16, 2022
Heist to Hostage Situation: Attack Trends in the Financial Sector
February 16, 2022
Customer Spotlight: Snap Finance
February 16, 2022
In a recent video at the RSA Conference, Kiran Sharma, Senior Privacy Program Manager at Snap Finance, highlighted the significant impact of Contrast’s platform on their security initiatives. Sharma has played a pivotal role in driving the organization’s DevSecOps and security programs. Recognizing the need for a unified solution to address vulnerabilities sourced from various tools, he emphasized the significance of a consolidated platform for streamlined management and increased visibility. The Contrast Secure Code Platform emerged as the ideal solution, providing Snap Finance with comprehensive insights and actionable information to tackle vulnerabilities effectively.
Contrast Security Overview with Jeff Williams
February 16, 2022
Contrast Named #1 Leader in 2023 Summer G2 Grid Report for IAST
February 16, 2022
The Evolution from DAST to IAST: Take AppSec Testing to the Next Level
February 16, 2022
Revolutionizing DAST with IAST: A New Era in Application Security
February 16, 2022
2023 Gartner® Magic Quadrant for Application Security
February 16, 2022
3 Ways to Recession-Proof your AppSec Program 2023
February 16, 2022
Navigating Turbulent Times
February 16, 2022
Contrast SCA
February 16, 2022
Contrast Scan
February 16, 2022
What's your Zero Trust Strategy? What's your Pillar 4 Solution?
February 16, 2022
Customer Spotlight: How an American Financial Technology Company Embeds Application Security
February 16, 2022
Fireside Chat with Trace3: State of DevSecOps in 2023
February 16, 2022
Contrast Security and Trace3 discuss observations from the field for the State of DevSecOps in 2023 and how you can kickstart or enhance your existing program
On-Demand: Cyber Bank Heists
February 16, 2022
Learn the difference between active and passive IAST
February 16, 2022
This white paper explains the two main approaches of IAST — active and passive — and how you need to be able to leverage the best outcomes. It outlines the advantages and disadvantages of each approach and how they can be used in combination.
Cyber Bank Heists
February 16, 2022
Security is top-of-mind amid rising geopolitical tensions, increased destructive attacks utilizing wipers, and a record-breaking year of zero-day exploits. Learn what financial leaders revealed about security trends like notable cyberattacks, e-fraud, and cyber defense.
The U.S Department of Defense is Expanding its Security Framework to Include Continuous Monitoring Controls
February 16, 2022
Demystifying OMB M-22-18: 5 Things You Need to Know
February 16, 2022
A Complete Guide to Contrast Security’s Localized Developer Tools
February 16, 2022
Download this white paper to learn about the testing challenges developers face, Contrast's free security tool, CodeSec and how CodeSec tools can help developers fix code vulnerabilities without having to navigate a whole new system.
Threats Facing the Financial Sector: From Heist to Hostage Situation.
February 16, 2022
Financial institutions face evolving cybercrime conspiracies coordinated by international cyber cartels. Tom Kellermann, Contrast's SVP of Cyber Strategy, shares his unique perspective on how cyberattacks are evolving in the financial sector, what significant new e-fraud trends are occurring and a discussion of effective mitigation strategies.
Customer Testimonial: BMW
February 16, 2022
The Ripple Effect: Impact of the Cybersecurity Executive Order on Transparency and Security in the Software Market
February 16, 2022
FedTalks Interview with Jeff Williams
February 16, 2022
Contrast SCA: Automated Software Composition Analysis Software and Compliance
February 16, 2022
Open Source Software (OSS) affords developers many freedoms to build feature-rich applications on aggressive timelines. However, reliance on OSS adds layers of complexity across an organization’s software supply chain.
Contrast Platform for Federal Agencies
February 16, 2022
Contrast Security is the only continuous secure coding platform that natively integrates into all stages of the software development life cycle, from development to production.
Contrast Scan: Pipeline-Native Static Application Security Testing
February 16, 2022
Contrast Scan’s pipeline-native static analysis engine is built to run in modern CI/CD pipelines with industry-leading speed and accuracy, making security testing as routine as committing code.
The Future of API Security
February 16, 2022
IDC Link: Contrast Security Targets Developers with Free DevSecOps Solution
February 16, 2022
Contrast Assess Market-Defining Application Security Testing for Modern Agile and DevOps Teams
February 16, 2022
2022 IDC MarketScape Report
February 16, 2022
Securing the Software Supply Chain in Modern Development Pipelines
February 16, 2022
Transforming the Role of the Security Analyst
February 16, 2022
ESG analyst discusses how to move from gatekeeper to developer enabler.
Developers: Own Your Security Destiny
February 16, 2022
ESG analyst discusses how to ship secure, tested code and rapidly remediate issues without headaches.
2021 Application Security Observability Report
February 16, 2022
A "Can't Miss" report based on real-world data from thousands of applications that highlights vulnerability and attack trends, security debt, benchmarks on the vulnerability escape rate, and much more.
Preparing for the Next Zero-Day Vulnerability
February 16, 2022
Join Larry Maccherone, DevSecOps Transformation lead at Contrast Security, and Farshad Abasi, Chief Security Officer at Forward Security for an interactive discussion about how to future-proof against emerging threats on the horizon so your organization is prepared to respond instantly to zero-day vulnerabilities like Log4Shell.
How To Keep Up With the Rapidly Expanding Scope of the OWASP Top Ten
February 16, 2022
Read this eBook to learn how to use out-of-the-box policy management and reporting in the Contrast application security platform.
Pipeline-Native Scanning for Modern Application Development
February 16, 2022
Read this White Paper to learn why organizations have been slow to move off of legacy SAST approaches and how Contrast Scan offers a transformative alternative with demand-driven static analysis.
3 Ways Contrast Helps Safeguard the Software Supply Chain
February 16, 2022
Read this eBook to learn how Contrast enables organizations to secure and protect their software supply chain.
Pipeline-Native Static Analysis: Why It is the Future of SAST
February 16, 2022
Read this eBook to learn the benefits of a pipeline-native static analysis approach and what it entails.
State-Of-The-Art Protection And Observability Is Appsec Exactly Where It Is Needed— In Production Runtimes
February 16, 2022
This eBook examines how runtime application protection and observability delivers a state-of-the-art approach to application security. Readers will gain the information needed to evaluate runtime application protection and observability solutions and how they augment perimeter defenses (such as WAFs).
Lack of Security Observability Thwarts Application Security
February 16, 2022
Read this white paper to discover how reliance on outdated application security tools clouds observability that is critical to spotting and remediating vulnerabilities in applications.
Perimeter Security Noise leaves Applications Vulnerable to Attacks
February 16, 2022
Read the White Paper to learn how traditional perimeter security lacks sufficient visibility to differentiate which attacks can impact a running application.
American College of Radiology
February 16, 2022
American College of Radiology selected Contrast, because it was providing really good information about the findings of vulnerabilities and context on how to fix them. Contrast has assisted in educating American College of Radiology’s developers to not just fix the issues but also to prevent them from happening again in the future.
Zero Trust for Application Workloads
February 16, 2022
Watch this On-Demand session from ATARC’s Zero Trust Virtual Summit. Erik Costlow, Sr Director at Contrast focuses on the Zero Trust Maturity Model, Pillar #4 that hones in on Application Workloads.
Outdated Application Security Tools Put Federal Agencies at Risk
February 16, 2022
Read this White Paper to discover how Federal agencies are challenged to accelerate development cycles due to legacy application security approaches.
Log4j Vulnerability Demo
February 16, 2022
Watch this simple demo from Jeff Williams, Contrast CTO, showing how the Log4j vulnerability and exploit work.
Log4j Vulnerability: What you can do now
February 16, 2022
The most serious of vulnerabilities was just found in the most used logging framework, but DevSecOps teams can quickly identify what’s impacted and where they focus their time.
Contrast Community Edition Product Brief
February 16, 2022
Contrast CE is a free, full-strength application security platform that provides "always-on" IAST, RASP, and SCA for Java and .NET Core applications and APIs. Contrast Community Edition delivers the power of Contrast Assess and Contrast Protect and is used by all sizes of an organization - from large global enterprises to one-person development teams.
The Case for Application Security Monitoring
February 16, 2022
Contrast Security And Secure Code Warrior Solution Brief
February 16, 2022
Read this Solution Brief to learn how Contrast and Secure Code Warrior combine to deliver just-in-time learning for developers.
ESG: Transforming the Role of Security Analyst From Gatekeeper to Developer Enabler
February 16, 2022
ESG: Developers: Own Your Security Destiny
February 16, 2022
Contrast Assess Market-Defining Application Security Testing for Modern Agile and DevOps Teams
February 16, 2022
Contrast is a revolutionary application security solution that transforms an organization’s ability to secure their software by making applications self-protecting. This whitepaper covers how Contrast Assess’ unique Application Security Testing solution, sometimes referred to as Interactive Application Security Testing (IAST), makes software capable of assessing itself continuously for vulnerabilities, while providing the highest accuracy, efficiency, and coverage
Contrast Security and The Digital Operational Resilience Act (DORA)
February 16, 2022
Interactive Application Security Testing (IAST)
February 16, 2022
American College of Radiology
American College of Radiology has agile methodologies in their SDLC, which means security tools have to shift left, allowing developers to have access to security tools. Learn how Contrast enabled American College of Radiology to leverage technology for security by finding errors as they run.
Financial Services
Read this Case Study to learn how this North American insurance subsidiary increased awareness among developers about application security risk and safe-coding practices.
Unit 4
See how Unit4 streamlined its AppSec with Contrast Assess, achieving faster remediation, reducing false positives by 50%, and saving 72 hours on reporting. Unit4's automated solution supported their digital transformation and improved security across teams.
CM.com
Improves Security and Efficiency While Reducing Risk.
Go Agent Demo
A demonstration of how the Go agent helps teams find vulnerabilities in their custom code, with an explanation of how the technology works.
Kaizen Gaming
See how Kaizen Gaming improved application security by shifting left with Contrast Assess, reducing MTTR by 15 days, cutting false positives, and saving up to 1.5 days on reporting. Discover how they accelerated releases, streamlined vulnerability management, and reduced security debt.
Contrast CEO, Alan Naumann, on Contrast
Our CEO discusses how software is affecting business transformation, the growing risks inherent in the pace of modern development, how security can evolve to scale, and why Contrast is uniquely positioned to deliver an application security posture that is effective.
Envestnet | Yodlee
Business and technology innovation was being hampered by traditional legacy security and infrastructure tools. This digital healthcare company required a solution that could quickly and seamlessly accelerate the company’s digital future by migrating securely to a cloud infrastructure.
GreenSky
In terms of multi-tasking, GreenSky had “multiple irons in the fire” across their DevOps environment. The company was facing the standard technology growing pains and realized they needed greater flexibility and scalability. Contrast Security was able to secure over 150 of their applications migrated from on-premises to an AWS cloud platform.
Regional Credit Union
Read how Contrast Assess helped this regional credit union identify vulnerabilities in custom code and instruct developers on how to remediate them. Additionally with Contrast Protect, this company can accurately block attacks in real-time, across all environments.
Banking Financial Services
See how one of the world's largest banks enhanced security and agility during its Digital Transformation by integrating an automated AppSec solution. The bank improved code quality, reduced pen testing costs, and seamlessly embedded security into Agile and DevOps, all while mitigating software risk.
Retail E-commerce
See how a leading E-commerce company accelerated innovation by integrating Contrast Assess into its Agile development process. The company reduced security delays, eliminated bottlenecks, and gained real-time visibility into vulnerabilities, enabling faster, more secure releases and enhancing overall efficiency.
OWASP Co-Founders Discuss the OWASP Top 10 2021
Organizations will recalibrate how they measure application risk and reevaluate strategies based on the OWASP Top 10 2021. Hear two of the original co-founders of OWASP assess the new Top 10 and provide their perspectives.
Key Insights and Benchmarks from Contrast's 2021 Application Security Observability Report
Hear our panel of experts discuss the second annual 2021 Application Security Observability Report. We will cover key insights and industry benchmarks on an array of different application security areas.
Key Takeaway from the Kaseya Software Supply Chain Attack
Hear a panel of experts discuss how bad actors were able to hack the Kaseya application, and get recommendations on what you can do to avoid becoming victims to software supply chain attacks.
The Future of SAST: Pipeline-Native Static Analysis
One of the “can’t miss events” in 2021. Join this webinar to learn how pipeline-native static analysis is a major breakthrough—delivering exponential improvements in scan times, accuracy, and more without compromising development speed.
4 Dimensions of Modern Application Security
Application security is no longer one- or two-dimensional. Join our expert panel on this webinar and learn about the four dimensions of modern application security.
What True DevSecOps Controls and Metrics Look Like
Join this webinar to learn what controls and metrics you need in place to implement a successful DevSecOps program.
How to Determine What Your Open-Source Risks Look Like
Join us as we discuss key findings in Contrast Labs’ newly released “2021 Open-source Security Report.” Learn what percentage of libraries contain vulnerabilities, how many CVEs are in an application, and much more.
U.S. Air Force’s Chief Software Officer Shares Perspectives on Application Security
60% of Public Agencies Use DevOps and Agile But It Takes An Average of 500 Days to Complete a Federal IT Project. Something is amiss! Join us for our two subject-matter experts for this Fireside Chat and discover why modern DevSecOps is the answer for federal agencies.
Unleashing Software's Potential with an Application Security Platform
Join us to discover why security roadblocks inhibit developer efficiencies while slowing down development cycles. A platform approach to application security solves these challenges, collapsing the different silos between application security tools for full observability across applications and application programming interfaces (APIs).
Security Observability Summit
Contrast Security hosted the industry's first Security Observability Summit. You will experience one inspiring keynote, two comprehensive breakouts, and nine eye-opening sessions.
From the Inside Out
Contrast Security held a virtual event with a panel of AppSec experts for an exclusive inside look on how you not only can get control of runaway security debt, but can actually reduce it dramatically. This moderated panel of AppSec pros shared stories about their own experiences and the strategies they employed to reduce security debt permanently. You will come away with key insights and tactics about how you can overcome security debt within your own organization.
Bringing an End to Security Roadblocks
Most traditional application security (AppSec) requires a slew of tedious manual processes that are failing modern DevOps teams in both efficiency and effectiveness. Since these legacy AppSec tools cannot keep pace with modern DevOps, security teams have long struggled to control and limit the amount of serious application vulnerabilities. Watch this webinar to learn how a modernized approach to AppSec can meet the needs of both security and DevOps teams.
Assessing the Risk from the Confluence of an Expanded Application Attack Surface and Advanced Threat Landscape
Join us to gain insights on how the confluence between the rapidly expanding application attack surface and the evolving threat landscape poses serious risk. After mapping out the challenges, our expert panel will share insights around strategies and tactics that organizations can tap to bolster their application risk postures and ensure their applications are protected.
Application Security Jumps to the Top of the CISO's List of Priorities
As the modern-day CISOs role continues to expand, CISOs must mitigate both business risk and execute successful cybersecurity strategies. This is especially true when it comes to the risk of application development vulnerabilities that can result in dire financial consequences—ranging from diminished brand reputation to severe financial loss. Tune in for a special moderated webinar that will feature insights from a seasoned executive recruiter and CISO practitioner about what it takes to manage an effective application security strategy.
RASP for Attack Visibility, Web Application Observability, and Simple Scaling
Let’s face it—traditional web application firewalls (WAFs) simply can’t keep pace with the demands of digital transformation in DevOps environments. Applications are deployed faster and leaner than ever before and AppSec professionals need protection that moves beyond the traditional and simplistic perimeter defenses a WAF can offer. Join this webinar for a discussion about how RASP delivers an innovative application security alternative that adapts and reacts in real time. With RASP, teams gain the necessary attack visibility, application observability, and scalability they require.
Defining and Stopping the "Plague" of Application Security False Positives
False positives in application security are the kiss of death. They kill time, confidence, and ultimately, the application if they detract from security’s ability to focus on the critical vulnerabilities. Attend this webinar to get a better perspective on how pervasive the issue of false positives is, and the impact these erroneous alerts have on an organization—from the effects of alert fatigue to the impediments on a company’s digital transformation.
DZone Webinar: Securing APIs At Devops Speed
With attack-automation tools working around the clock, there’s no REST for the wicked. The increasing speed of DevOps and continuous deployment paves the way for teams to obtain security through on-demand self-service – securing APIs from the inside rather than the outside. Watch this on demand webinar if you are a Developer who wants to push code faster by removing the obstacles of securing APIs as mandated by your security teams.
Security Instrumentation is the Future of All Software
Uncompromised code. Imagine it. Well, a technology exists that can make it a reality: Instrumentation. The state of Application Security is in a flux, and it is for good reason. After literally decades of attempts to improve software security, the proverbial needle has barely moved. Join Jeff Williams, Contrast Security's CTO and co-founder of OWASP for a webinar to learn how AppSec professionals can benefit from instrumenting applications.
SAP Concur Cloud Journey
The journey of cloud migration isn’t a straight and narrow path, and enterprise DevSecOps teams generally use a variety of tools to reach their goal. In this webinar, we will deep dive into SAP Concur’s journey, and how they are leveraging Contrast Security’s embedded application security model and AWS in tandem to “shift left”, create a seamless developer experience, and deliver secure application workloads on the cloud.
What the WAF: Understanding and Augmenting What the WAF Cannot See
A Web Application Firewall (WAF) has limited capabilities to secure your code during production. Using a Runtime Application Self-Protection (RASP) tool will work from within the application via instrumentation and easily deploys in your DevOps, Cloud and Container environments. We’ll highlight what WAFs can and cannot see and why they require RASP to function at its fullest.
Cloud-Native Security: Processes and Tools for Real-World Transformation
Cloud-native platforms not only make it easier to support the kind of cultural shift necessary for continuously shipping software, they make it easier to practice good security and reduce the available attack surface. But an attack on the application itself can undermine all platform controls. Learn to secure your code in runtime at scale for cloud-native production applications.
Cloud-Native Security: Understanding the Why & How
Join Jeff Williams, Co-Founder & CTO of Contrast Security, and David Zendzian, CTO of Compliance and Security at Pivotal, for a discussion on best practices to ensure an organization's Cloud-Native Transformation is secure at the speed of DevOps.
Modern Software Assurance Strategies for Government Agencies
Join in to discuss the principles of DevOps with an innovative approach of IT security known as DevSecOps. DevSecOps introduces automated security much earlier in the Software Development Life Cycle (SDLC) to minimize vulnerabilities and bring security closer to IT and govrnment business objectives.
Embedding Security in a Modern DevOps Pipeline – A Customer Perspective
Hear directly from a customer's perspective on how Beeline, the world leader in contingent workforce solutions, aligned their Development, Operations, and Security practitioners to set up a fully automated continuous integrated and continuous delivery (CI/CD) pipeline and incorporated application security early in the process.
Targeted Defense: The Future of Defending Applications in Production
Development teams have struggled with a massive security backlog for how rapid they need to work to release software. Protecting your legacy applications is critical to your business and therefore necessary for your organization to have better production controls. Listen in to learn Contrast Security's new Targeted Defense Platform using RASP technology to defend your applications in production.
Contrast Security Demo & Overview
Watch a demo presented by Jeff Williams, CTO and Co-Founder of Contrast Security, and Ed Amoroso, former CISO at AT&T and Founder of TAG Cyber.
Next Generation Application Security
See how Contrast Security works with Agile & DevOps processes to accomplish maximum security at maximum speed for all application deployments.
DevOps Ready Security
Short video to learn how Contrast Security enables development and operations teams to deliver secure code while working at DevOps speed.
Introduction to Contrast Assess
Learn how Interactive Application Security Testing (IAST) uses instrumentation to find and remediate vulnerabilities and insecure libraries. We will compare Contrast Assess to other legacy security testing methodologies.
Contrast Assess as Part of the SDLC
Contrast Assess deploys an intelligent agent that instruments the application with smart sensors to analyze code in real-time from within the application. No need to disrupt and change the way you work.
The Contrast Advantage
Jeff Williams, CTO and Co-Founder of Contrast Seucurity, explains what it means to have "self-protecting" software.
Contrast Protect Advantages Over WAF
Watch first hand how Contrast Protect (RASP solution) avoids the need for WAF's by working from the inside of a running application to provide better visibility and accuracy to find and block attacks.
The Challenge of Secure Coding
Nick Holland, Director of Banking & Payments at the Information Security Media Group, and Jeff Williams, CTO and Co-founder of Contrast Security, discuss the challenges of writing secure code.
Realistic Approaches to AppSec & the Future of Cyber Security
Hear a conversation with Contrast Security's Co-Founder & CTO, Jeff Williams and former CISO of AT&T, Ed Amoroso, as they discuss how to approach application security and what the future of cyber security looks like. (10:18)
Continuous Application Security with Tim Chase from Nielsen
In this brief video, hear Tim Chase, Director of Application Security and Architecture at Nielson, discuss the importance of continuous application security and what he thinks the future will hold for security testing, including DevSecOps. (02:15)
Key Insights on Application Vulnerabilities and Attacks (New Report) – Part 2
Hear our two guests discuss key findings in the 2021 AppSec Observability Report and how the RiskScore Index, which catalogues 19 different vulnerability types, enables organizations to pinpoint which vulnerabilities post the highest risk by combining vulnerability and attack data.
Digital Transformation in Financial Services Accelerates, Application Security Struggles to Keep Up
In this Inside AppSec Podcast with Contrast’s CISO David Lindner and Director of Developer Relations Erik Costlow, we explore key findings in Contrast Security’s 2021 State of Application Security in Financial Services Report.
Contrast Labs Researcher Finds Dependency Confusion Vulnerability in Microsoft Teams
In this Inside AppSec Podcast, Contrast Security's Director of Security Research Matt Austin discusses how he found the dependency confusion vulnerability in Microsoft Teams and what risk it posed.
ASG Technologies
See how ASG, a global technology solutions provider, enhanced its security posture and accelerated growth through acquisition with Contrast. By integrating on-premises and cloud-based solutions, ASG reduced false positives, improved TCO, and accelerated time-to-market, all while strengthening compliance and governance.
Tillster
See how Tillster, a global leader in digital ordering for major restaurant brands, enhanced security and efficiency by integrating Contrast Assess into their SDLC. With real-time monitoring, vulnerability tracking, and a scalable security solution, Tillster ensures a secure, seamless customer experience across all platforms.
Insurance
See how a leading North American insurance provider enhanced its application security by deploying Contrast Assess, fostering a cultural shift among developers, and prioritizing vulnerability remediation. With real-time insights and active developer participation, the company significantly improved its security posture and reduced risk.
How to Scale Governance, Compliance, and Security through GitHub Actions
Watch this On-Demand webinar to learn how to scale aspects of governance, compliance and security across different application teams, codebases and microservices architectures.
Shift Left: Easier Said than Done
Shift Left. A phrase that is easy to say, but a strategy that many organizations struggle to effectively implement. Watch this talk, presented by industry expert Larry Maccherone, to learn how to overcome the top 5 reasons that “shift left” is hard.
How to Win the DevSecOps Transformation
World class Application Security programs were not built in a day. The journey to success and meeting the new normals of code velocity require a coordinated effort between Engineering, DevOps and Security. Hear from Forrester's Sandy Carielli and Contrast Security's Larry Maccherone on how to quickly align goals, incentives and remove friction in better securing code across the entire SDLC.
CloudBee & Contrast Security
Two technical experts from Contrast and Cloudbees discuss governance, compliance, and security across different aspects of the SDLC. Watch this webinar to learn how automation enables organizations to realize the full potential of digital transformation, enforce compliance consistency, and enable developers to deliver secure code faster than before.
How To Unearth Application Vulnerabilities Hiding in Custom and Third Party Code
Today’s IT environments are increasingly complex and layered, jampacked with new collaboration applications, operational management platforms, authentication tools, malware protection software, the list goes on. With so many apps, it’s all too easy to focus your vulnerability remediation efforts on third-party software libraries and published CVEs and call it done.
5 Ways to Rapid DevSecOps Adoption
Teams that are working to develop and ship code fast are running into barriers when it comes to security. Solving this takes a combination of best practices and automation technology and should help them build secure code from the start vs trying to bolt it on later. In this panel discussion, Forrester principal analyst Chris Condo along with Larry Maccherone, DevSecOps Transformation, Contrast Security and Erik Costlow, Developer Relations, Contrast Security discuss 5 best practices that leading companies use to go fast while remaining secure.
Best Practices for Securing the Proliferation of APIS
Hear a panel of experts discuss the importance of API security and why traditional solutions fall short. Learn how APIs are designed and how design decisions impact security.
Learn How to Stop SQL Injection and Other Common Application Attack in Their Tracks
In response to the cascade of successful cyber exploits, President Biden issued an executive order that mandates the need for strengthening cybersecurity. Contrast Protect does just that for production applications.
Why Interactive Security Analysis for GO Application is Needed
Learn how Contrast can help application security teams improve the security of Go applications with the industry’s first interactive application security analyzer for the Go language.
New Report Highlights Digital Acceleration in Financial Services Is Creating Application Cyber Risks
Get insights and recommendations from a guest panel of Contrasters and GuidePoint Security on new survey findings published in a just-released State of Financial Services and AppSec Report.
How To Streamline AppSec With Interactive Pentesting
Discover what next-generation pentesting looks like when combined with interactive application security testing (IAST).
How Dependency Confusion Poses a Serious Risk in the Software Supply Chain
Join us as we discuss how a new dependency confusion vulnerability can wreak havoc and create widespread risk across the software supply chain.
What to Include in a New Risk-Scoring Model-and How to Use It
Join us as we discuss why simply assigning a severity rating is inadequate and how Contrast is developing an open-source risk-scoring algorithm that will be used as the basis for its RiskScore.
New Open-Source Dependency Confusion Vulnerability Threatens Software Supply Chain
In this Inside AppSec Podcast, Contrast Labs discusses why dependency confusion poses a serious threat and how Contrast developed and added new capabilities to its command-line interface so that customers can detect and remediate the vulnerability before bad actors exploit it.
Kaizen Gaming Embraces Application Security Instrumentation, Sees Tangible Returns
Hear Kaizen Gaming's Technical Security Manager Aggelos Karonis discuss why he and his team turned to application security using instrumentation based on Contrast Security.
State of DevSecOps Report: 95% of Organizations Experienced a Successful Application Exploitation in the Past Year
Hear Contrast Security's CTO and Co-Founder Jeff Williams discuss key findings in Contrast's 2020 State of DevSecOps Report.
Serious Vulnerabilities Increase, .NET Applications Targeted by 4 of 5 Top Attack Types
In this Inside AppSec podcast, Contrast Security's CISO and Data Scientist discuss findings from the September–October 2020 Application Security Intelligence Report from Contrast Labs.
Developers and Application Security Practices in the Technology Sector
Hear Contrast Security’s CTO and Co-Founder Jeff Williams discuss the survey findings from a recent report and provide his unique perspective on what they mean—from challenges to opportunities.
Contrast-on-Contrast Case Study and Business Value Analysis: Key Insights and Learnings
Hear the Contrast VP of engineering discuss how his team has used the Contrast Application Security Platform to secure and protect TeamServer, the UI, and analytics engine for the Contrast platform. Learn about the business value his team has achieved using the Contrast platform over a legacy application security approach.
DevSecOps Consultant Discusses AppSec Trends and Provides Career Insights and Recommendations
Hear EVOTEK's IT Strategist Greg Sternberg discuss how DevOps and AppSec must be thought of together and key trends that he sees taking place in DevSecOps.
SQL Injection Vulnerability and .NET Application Attacks Spike
Contrast Security’s CISO David Lindner and Data Scientist Katharine Watson discuss key highlights and insights from the May-June bimonthly “Application Security Intelligence Report” from Contrast Labs.
Key Takeaways from Contrast’s “2020 Application Security Observability Report”
Listen to Contrast’s CTO and Co-Founder Jeff Williams discuss key highlights and explore actionable insights, including how time to remediate directly ties to risk management, from the “2020 Application Security Observability Report.”
Serious Vulnerabilities Increase 23% Per New Bimonthly AppSec Intelligence Report
Hear Contrast Security’s Data Scientist Katharine Watson and Union University’s Assistant Professor of Computer Science Brian Glas discuss key findings from the March-April Bimonthly AppSec Intelligence Report.
Instrumentation Disrupts Application Security—from Development Through Production
Hear Contrast’s CTO and Co-Founder Jeff Williams discuss instrumentation and why it offers a much more efficient, effective application security model.
When Application Vulnerabilities Are First Reported on Social Media: Strategies and Recommendations
Listen to Erik Costlow from Contrast Security discuss the implications of posting newly discovered software vulnerabilities on social media and how it impacts security and development teams.
What It Takes to Be a Winning CISO/CSO Candidate (Part 1)
Listen to this Inside AppSec podcast with André Tehrani, a partner at Recrewmint, on what skills and experience organizations are looking for in a CISO/CSO
The Risky Business of Open Source (Part 1)
Listen to this Inside AppSec podcast with Contrast Security’s Sr. Product Marketing Manager for Contrast OSS, Joe Coletta, about the trends in OSS and the risks of OSS.
A Look at the AppSec Marketplace and Contrast Security in 2020
Listen to this podcast on Contrast Security’s AppSec paradigm shift: we embed security instrumentation in software and automate vulnerability identification and remediation verification.
Defining What Is Needed—and Why—in Runtime Application Self-Protection (RASP) (Part 2)
Listen to this podcast with Contrast Security’s Head of Product Marketing for Contrast Protect, Derek Rogerson, on how RASP addresses the failings of perimeter security.
Findings on Vulnerabilities and Attacks from the Latest Contrast Labs AppSec Intelligence Report
Listen to this podcast that discusses findings and takeaways from Contrast Lab’s bimonthly report for January-February 2020.
Integrated Security Instrumentation Is the Future of AppSec
Listen to this podcast about the AppSec paradigm shift: security sensors integrated into application routes enable developers to manage vulnerabilities as they write code.
What Security and Development Teams Need to Know About the New NIST 800-53 IAST and RASP Standards
Listen to this podcast about the latest release from NIST that spells out new requirement for instrumentation in IAST and RASP.
Mapping the Benefits of Route Intelligence
Listen to this Inside AppSec Podcast that explores Route Intelligence and what it means for developers and security professionals with three experts from Contrast Security.
How to Secure APIs at DevOps Speed
Read this eBook to understand why APIs are difficult to secure and what AppSec approach is needed to identify and remediate API vulnerabilities.
Bringing An End To Security Roadblocks
Read the eBook to discover how AppSec still requires many manual processes, which slows Agile and DevOps CI/CD pipelines and frustrates developers.
How Manual Application Vulnerability Management Delays Innovation and Increases Business Risk
Read the eBook to learn how legacy AppSec approaches lack visibility across an application’s attack surface, yielding both false negatives and false positives.
A Comprehensive Approach to Analyzing and Protecting Software
Read the eBook to learn how traditional approaches to AppSec add more noise than protection, as they rely on a patchwork of disparate tools and processes.
March - April 2021: Contrast Labs' Application Security Intelligence Report
This report is based on aggregate vulnerability and attack telemetry for custom code from customers whose applications are covered by Contrast Assess and Contrast Protect
July - August 2020: Contrast Labs' Application Security Intelligence Report
This report analyzes composite data from Contrast Labs to update readers on vulnerability and attack trends as observed with applications covered by Contrast Assess and Contrast Protect.
March - April 2020: Contrast Labs' Application Security Intelligence Report
This report leverages aggregate data collected by Contrast Assess and Contrast Protect for insights around both application vulnerabilities and targeted attacks.
Jan - Feb 2020: Contrast Labs' Application Security Intelligence Report
This report analyzes composite data from Contrast Labs to update readers on vulnerability and attack trends as observed with applications covered by Contrast Assess and Contrast Protect.
Contrast Scan Is Faster, More Accurate, and More Efficient
Read this white paper to learn how Contrast Scan uses pipeline-native static analysis to transform legacy SAST with faster speed and dramatically better accuracy.
Protecting APIs: An Uphill Battle
Read Contrast Security’s White Paper, “Protecting APIs: An Uphill Battle,” to understand the increased risk organizations face when they try to use legacy application security tools and processes to protect their Application Programming Interfaces (APIs).
How Legacy Application Security Requires Experts, Time, and Cost That Degrade DevOps Efficiencies
Read this White Paper to learn how legacy AppSec involves too many tools and requires too much time and too many experts to manage.
Why Lack of Application Security Skills and Experts Hamstrings Digital Transformation Initiatives
Read this White Paper to learn how the application security skills gap is affecting the ability of organization's to embrace digital transformation.
The Truth About AppSec False Positives
Read this White Paper to learn more about why AppSec false positives occur and how security and development teams struggle to address them.
Route Coverage through Instrumentation and Automated Vulnerability Management
Read the White Paper to find out how security instrumentation uses route intelligence to determine application route coverage—which ones have and have not been exercised.
Contrast Integrates into Kenna Security to Deliver Better Vulnerability Risk Management
Read this Solution Brief to learn how Contrast vulnerability and attack data integrates into Kenna. VM where it is combined with threat intelligence and advanced data science to help organizations prioritize risk remediation.
May - June 2021: Contrast Labs' Application Security Intelligence Report
Read this Bimonthly AppSec Intel Report to learn about key vulnerability, attack, and RiskScore trends during May-June 2021.
2021 Application Security Observability Report - Executive Summary
Read this Executive Summary to glean key insights and benchmarks from the 2021 Application Security Observability Report.
Contrast Scan: Modern Application Security Scanning
Read this Solution Brief to learn how Contrast Scan is pipeline native and improves scan times 10x and remediation times 45x.
Purpose-Built AppSec Integration with Microsoft Azure
Read this Solution Brief to learn how the Contrast Application Security Platform has built-in integration with Microsoft Azure and what the benefits look like for Contrast customers.
Contrast Application Security Platform
Read this Federal Solution Brief to understand how Contrast Security addresses critical requirements such as DOD Platform One, NIST, and much more.
Contrast Application Security Platform
Read this Solution Brief to learn how the Contrast platform delivers a comprehensive DevSecOps approach that makes security continuous and integrates seamlessly with modern software.
Contrast OSS Helps DevOps Manage and Triage Hidden Third-Party Library Risk
Read this Solution Brief to learn how third-party library risks can be detected and remediated with Contrast OSS.
AppSec Solution Guide for Complying with New NIST SP 800-53 IAST and RASP Requirements
Read this Solution Guide to learn what implications the new IAST and RASP guidelines in the NIST Cybersecurity Framework have on application security.
Contrast OSS Product Brief
Contrast OSS delivers automated open source risk management by embedding security and compliance controls into applications throughout their lifecycle. Read this product brief to learn that Contrast OSS is the only solution that can identify vulnerable open source component to prevent exploitation at runtime.
Why DevSecOps Is Challenged By Modern Software Development
Join us to discover key findings and insights on Contrast Security’s 2020 State of DevSecOps Report. Our panel of practitioners will share their insights and recommendations on the extensive findings in the report. Attendees will leave with an in-depth understanding of key DevSecOps trends and best practices.
Simplify Vulnerability Remediation with Runtime Library Usage
Far too many software composition analysis (SCA) tools serve up a slew of irrelevant vulnerabilities in open-source libraries and frameworks that aren’t actively used, leaving developers frustrated when it comes to securing open-source code. Join us with key insights from AppSec professionals and come away with a stronger understanding of how to deliver developers the data they need to fix vulnerabilities, fast.
Contrast-on-Contrast Case Study: How We're Using Our Application Security Platform from Development to Production
At Contrast Security, we’ve been “eating our own cooking” to secure and protect TeamServer—the assessment analysis engine and UI that powers the Contrast Application Security Platform. Join this webinar and we will share some tangible business value outcomes that we've achieved using the Contrast Application Security Platform. Join the List Now!
How To Transition To A Modern Software Security Model
Medtronic embraced a modern application development approach to DevSecOps; increasing scale, eliminating noise from false positives, and bridging the gap between development and security teams. Watch this webinar to hear how Medtronic accelerated cloud migration and increased software delivery.
A Five-Step Plan to Vulnerability Management Success
Join us to discover a new approach for effective vulnerability management. Observability is key when it comes to the five-step plan that security and development teams need to implement for effective vulnerability management. By implementing this five-step plan, attendees will drive more effective threat prevention and achieve better risk management.
Digital Transformation Thwarted: When Your AppSec Tools, Scanning, and Resources Become Your Mr. Hyde
Join us to understand how Dr. Jekyll AppSec has turned into Mr. Hyde—not only in terms of the productivity of security teams but in the risk applications pose. Key takeaways include why traditional tools drive operational inefficiencies, how old security tools generate huge volumes of alerts that are inaccurate and often meaningless, and why old scanning and testing tools require AppSec professionals with highly specialized expertise and skills that are in high demand.
Managing Open-Source Security for Modern-Day DevOps
Is managing open-source software (OSS) with legacy tools causing more harm than good? This is often the case when it comes to outdated software composition analysis (SCA) tools that bury teams with false positives and require a series of tedious manual processes that waste valuable time. Tune in with us for a webinar that will explain how these SCA tools fall short when it comes to managing OSS risk, as well as how to untangle the confusion and find a security strategy that doesn’t stop DevOps in its tracks.
Assessing Custom and Open-Source Risk with Vulnerability and Attack Data
Get a sneak peek at our latest Contrast Labs findings, in this webinar you’ll learn what vulnerabilities and attacks in custom and open-source coded applications are the critical causes for concern. Effective web application security isn’t only about identifying vulnerabilities and attacks, as a matter of fact, that leads to alert fatigue. Today it’s about prioritizing and focusing and identifying what matters—sifting out the chaff from the wheat. Attend this webinar to get that leg up in your efforts.
The Best Route To AppSec Automation
In this webinar, our panel discusses how modern software development is the driver of an organization’s digital transformation and how application security is transforming to meet the modern demands. Learn how to empower faster code releases and scale application security through automation.
Why Agile & DevOps Demand New Approach to Securing Applications.
This moderated webinar panel tells you why Agile and DevOps requires a new approach to application security. This includes a cultural transformation that touches on everything that is needed for today’s modern software development environment—from strategies for building a strong security posture, to continuous protection through the software development life cycle, to automating workflows.
Security in a DevOps World: Unlocking Velocity and Innovation
Learn how to leverage application security instrumentation techniques in DevSec and SecOps (DevSecOps) to increase both developer and security productivity. Watch this webinar today to understand how the combined benefits of Microsoft and Contrast Security can help you accelerate innovation with Security in a DevOps world.
Securing APIs at DevOps Speed
Development teams and leaders want to push code faster and write good code while reducing interference from security teams. The only way to achieve these objectives is to rethink AppSec by integrating it into the DevOps pipeline. Attend this webinar if you are a Developer who wants to push code faster by removing the obstacles of securing APIs as mandated by your security teams.
A Comprehensive Approach to Application Security
Traditional approaches to AppSec have relied on a patchwork of separate disconnected tools and processes that add more friction than value by spending far too much time on scans and pentesting. We have a better idea. This talk will present our unified platform that provides continuous and comprehensive AppSec across the SDLC by seamlessly weaving AppSec into your applications themselves, protecting applications from cradle to grave.
Embracing DevSecOps with Embedded Application Security
Traditional approaches to application security create unacceptable drag and scaling problems for DevOps, while security staffing and tooling requirements to support “more code, faster” create untenable economics. This webinar will be a discussion and hands-on workshop showing the transformative impact of embedding application security into applications themselves.
Building a Modern, Scalable, and Effective Application Security Program
Over the past 20 years, there have been a dozen different major theories on how you should implement an application security program. The answer is a new modern approach to achieving application security that directly measures security outcomes instead of indirect measurements of processes or teams.
Key Application Security Strategies for Your Cloud Migration
Organizations are migrating from traditional legacy technologies to embracing today's Digital Transformation with modern cloud computing. These activities, in turn, are driving the need for stronger security. This webinar will help you understand how Contrast solves this problem by using instrumentation within the application to protect wherever they are deployed and automatically report and block attacks.
Securing Java Web Applications and APIs in minutes...for FREE...Seriously!
We've all suffered from a difficult, inaccurate, and frustrating security tool. What if there was a security tool that was as easy and powerful to use as AppDynamics? In this webinar, we will help you get up and running with Contrast Security's Community Edition FREE and full-strength tool for anyone to use. Start securing your code, lock down open source libraries, identify attacks, and prevent exploits using our free AppSec solution.
Scaling Rugged DevOps to Thousands of Applications
Tim Chase, Director of Application Security and Architecture at Nielsen, discusses how he scales Rugged DevOps and achieves continuous protection during development and operations by instrumenting the software application portfolio, assessing and protecting applications in parallel, and deploying integrations that provide instant notifications.
Contrast Security Advantages Over WAF – SQL Query Example
Watch this short video to see how Contrast Security protects applications and blocks SQL injections attacks better than WAF's.
Securing Government Applications with Contrast Security
Listen to Contrast CTO, Jeff Williams, discuss how Contrast is modernizing government agencies approach to application security.
The Time is Now for Contrast
Businesses are transforming. Innovation is being driven by software development. Learn how Contrast is leading the security evolution to ensure that innovation is secure.
Contrast Demo for Applications Running in AWS
Watch a step-by-step demo of how developers can reduce false positives, manual processes, and security roadblocks by embedding security directly into software through instrumentation.
Contrast Security Product Highlights
Watch a short high-level overview of Contrast Assess and Contrast Protect to see how we make software self-protecting to prevent vulnerabilities and block attacks.
Contrast High-level Overview
A short explanation to learn how Contrast Security uses instrumentation to deploy and accurately identify application vulnerabilities in minutes without experts or legacy SAST and DAST tools.
Introduction to Contrast Protect
Contrast Protect leverages Runtime Application Self-Protection (RASP) and patented deep security instrumentation to protect applications against cyber attacks in real-time, making it the most accurate, fastest and scalable application security solution.
Boost Application Security with Self-Protecting Software
Terry Sweeny, Editor at DARKReading, and Jeff Williams, CTO and Co-founder at Contrast Security, discuss the need for a modern approach with more accurate tools to help development teams code without the need to stop and scan.
Cybersecurity and Digital Transformation
Contrast Security CEO Alan Naumann chats with former CISO of AT&T Ed Amoroso on the importance of software security, DevOps initiatives, and the future of digital transformation.
Instrumenting Application Security
In this video, hear Scott Parson, Senior Enterprise Security Architect of a Fortune 500 Financial Company, discuss the importance of continuous application security and how automation and cloud infrastructure has impacted his organizations approach to application security. (02:25)
Investing in the AppSec Market
In this video, Jeff Williams, Co-Founder & CTO of Contrast Security, talks with John Monagle of General Catalyst, in regard to investing in application security, how the DevOps movement is changing the market, and Contrast Security's role in this transformation. (03:15)
Dark Reading Interview with Jeff Williams
Hear Brian Gillooly, VP of Events Content & Strategy, at Dark Reading in an in-depth conversation with Jeff Williams, Co-Founder & CTO of Contrast Security. Topics included revolutionary changes taking place in both application security and DevOps as well as Jeff’s prestigious nomination as one of the three finalists in the "Most Innovative Thought Leader" category for his work as a cyber security innovator. (12:57)
What does IAST mean to you?
Watch this short video and hear from Director of Test, John Scarborough on how he defines Interactive Application Security Testing (IAST). (00:39)
DevOps teams and AppSec?
Establishing a DevOps-ready security program is possible. In this video, hear from three folks who have successfully built and scaled the DevOps functions within their organizations. (01:31)
What does RASP mean to you?
Watch this short video and hear how Steve Herrod, Managing Director of General Catalyst Partners, defines and uses RASP technology as a decision-making tool. (00:35)
Behind-the-Scenes Perspectives on the Compilation, Analysis, and Publication of the 2021 OWASP Top Ten
Hear OWASP Top Ten Co-Lead and Union University Professor Brian Glas discuss how the data was compiled and analyzed for the new 2021 OWASP Top Ten categories.
Why More Isn't Better When It Comes to AppSec and Why Less Is Better
Hear Contrast's Chief Scientist and Co-founder Arshan Dabirsiaghi and Head of Product Marketing Mahesh Babu discuss why the assumption that more is better is misguided and why a completely new #AppSec approach is needed.
Key Takeaways and AppSec Recommendations From the 2021 OWASP Top Ten
This Inside AppSec Podcast features Contrast Security's CTO and Co-founder Jeff Williams and CISO David Lindner who explore changes and additions to the Top Ten and how organizations should use the Top Ten to manage their application risks.
Serious Vulnerabilities Per Application Jump in Latest Bimonthly AppSec Intelligence Report
This Inside AppSec Podcast discusses what vulnerability types saw the biggest increases and which ones are the most concerning.
Key Insights on Application Makeup: Custom and Open-source Code (New Report) – Part 3
Special guests explore findings in Contrast Security's 2021 Application Security Observability Report on application code composition. While the average application contains 80% open-source code, only 6% of that code is exercised.
Key Insights on Security Debt and Vulnerability Escape Rate Trends (New Report) – Part 1
This episode of Inside AppSec showcases the importance of just-in-time security training, which is confirmed via findings in Contrast’s newly formulated vulnerability escape rate—the average number of new vulnerabilities introduced each month in an application over the past year.
Java Applications Under Attack Barrage in Latest Contrast Labs Bimonthly AppSec Intel Report
Listen to this Inside AppSec podcast interview with Contrast Security CTO and Co-founder Jeff Williams and Sr. Data Analyst and Scientist Katharine Watson to get more details on the key findings in the March–April 2021 Bimonthly AppSec Intelligence Report from Contrast Labs.
CVE-2020-17091: Remote Code Execution Vulnerability in Microsoft Teams Found by Contrast Labs
Listen to this Inside AppSec podcast and hear Contrast Labs’ Director of Security Research Matt Austin discuss how he discovered a Remote Code Execution (RCE) vulnerability in Microsoft Teams and worked with Microsoft to confirm it.
Contrast DevSecOps Platform Now Includes Pipeline-native Static Analysis
Hear Contrast Security's Chief Strategy Officer Surag Patel and Sr. Product Marketing Director Mahesh Babu discuss the addition of Contrast Scan to the Contrast Application Security Platform in this Inside AppSec Podcast.
Navigating Open-source Security Obstacles and Mapping Out Solution Requirements
In this Inside AppSec Podcast, Contrast open-source subject-matter experts Joe Coletta and Pauline Logan take a look at some of the key findings in the Open-source Security Report and examine core capabilities in Contrast OSS and the Contrast Application Security Platform.
Open-source Library Risks Expose the Software Supply Chain
Listen to this Inside AppSec Podcast with Contrast Security subject-matter experts Joe Coletta and Pauline Logan to learn about the risks of open-source code and why you must heed the risk signals to avoid exposing applications to malicious attacks.
Software Supply Chain Is a Priority in the Latest Contrast Security Bimonthly AppSec Intel Report
In this Inside AppSec podcast, Contrast Security's CISO David Lindner and Sr. Data Analyst and Data Scientist Katharine Watson discuss highlights and key takeaways in the report.
Modern Application Security Now Available for Golang Applications
n this Inside AppSec podcast, learn how the industry’s first interactive security analyzer for Go applications virtually eliminates false positives and dramatically improves the efficiency of both application security and development teams.
Right and Wrong DevSecOps Metrics: Measuring What Counts
In this Inside AppSec podcast, listeners will learn what DevSecOps metrics matter—and which ones don’t—and how the Contrast Application Security Platform empowers security teams to build data-driven application security programs that reduce risks and improve efficiency.
Recommendations for Protecting Applications in Production from Known and Unknown Attacks
In this Inside AppSec podcast, we discuss how perimeter-defense approaches are ineffective in blocking many types of threats and are highly inefficient to deploy and manage—often stretching SecOps teams to breaking points.
Breaking Down Findings & Insights From Contrast Security's 2021 State of Open-source Security Report
Hear Contrast Security experts discuss findings and insights from the new 2021 State of Open-source Security Report by Contrast Labs.
Application Security Findings and Insights From Kenna Security's Latest Research Report
This Inside AppSec Podcast interview with Kenna Security CTO and Co-founder Ed Bellis explores application security findings and insights from the Prioritization to Prediction Volume 6 report.
Vulnerabilities Continue To Plague .NET Applications, Injection Attacks Ratchet Up in Concern
In this Inside AppSec Podcast, Contrast Security's CISO David Lindner and Sr. Data Analyst and Data Scientist Katharine Watson discuss these and other findings from the November–December 2020 report
Building a Risk-Scoring Model for Applications: Initial Algorithm and the Underlying Data Elements
In this Inside AppSec podcast episode, our expert panel explores the reasons Contrast developed an algorithmic RiskScore, and how it plans to release it as an open-source project, and how organizations can contribute and leverage it.
Reexamining Application Security Following the SolarWinds Hack
Hear Contrast Security’s CTO and Co-Founder Jeff Williams discuss emerging details around the SolarWinds hack and implications for application security.
What It Takes To Get a 4.8/5.0 Score for Gartner Peer Insights Customers' Choice
Contrast Security scored the highest in the Gartner Peer Insights Customers' Choice for Application Security Testing category. Hear our panel discuss what Contrast does to ensure customers have great experiences and support using its technology.
DoD Officer Builds a Successful InfoSec Career, Including Transition to the Private Sector
Hear Jimmy Xu from Trace3 discuss how he became interested in InfoSec and how he built a successful career in the DoD that set the stage for a transition into the private sector. He also provides insights into key cloud and application security trends.
Serious Vulnerabilities Increase While Overall Vulnerabilities Decrease in July-August
In this Inside AppSec podcast episode hear Contrast Security’s CISO David Lindner and Data Scientist Katharine Watson discuss Contrast Labs’ latest bimonthly research findings.
Application Security Through the Lens of Risk Management
Hear award-winning author and risk assessment and policy development expert Doug Landoll discuss strategies that can be deployed to assess application risk, how security frameworks can be used to mitigate and manage that risk, what the future of application risk management may look like, and more.
An Interview with New Contrast Board Member and Industry Cybersecurity and APM Pioneer Joe Sexton
Hear new Contrast Security Board Member Joe Sexton discuss application security from the perspective of the board and the opportunities security instrumentation offers to security, development, and operations leaders.
“DevOps Trends and Best Practices: A Perspective from the Trenches”
Hear JJ Asghar, Developer Advocate at IBM, discuss what is trending in DevOps and what tips and tactics DevOps leaders and professionals can use to eliminate or minimize the hurdles they face.
Exploring the Risks of Python in Applications and How to Protect Your Applications from Them
Listen to this Inside AppSec podcast about the growing number of developers using Python programming language and the need for modern AppSec to secure Python-based applications.
Strategies and Tactics Managing Open-Source Risk (Part 2)
Listen to this Inside AppSec podcast with Contrast Security’s Sr. Product Marketing Manager for Contrast OSS, Joe Coletta, on what organizations need to do when securing OSS.
How Culture Defines a Company and Enables a Laser Focus on Customers
Listen to this podcast with Babak Dehnad, VP of People at Contrast, on Contrast as an Inc. magazine Best Workplace and some of the key reasons why Contrast was selected as a winner.
API Security Requirements: Mapping Vulnerabilities That Matter
Listen to this podcast with Contrast Security’s Director of Developer Relations, Erik Costlow, on API vulnerabilities and how DevSecOps professionals can tackle them.
Building a Business Case to Get Beyond the Application Perimeter Defense (WAF) Status Quo (Part 1)
Listen to this podcast with Contrast Security’s Head of Product Marketing for Contrast Protect, Derek Rogerson, on how WAFs run on the perimeter and lack the context to identify risks.
Developers Need Integrated Application Security Tooling
Read this eBook to learn how application security can become a shared, collaborative concern that unites development, operations, and security teams without inhibiting aggressive deliver schedules.
Federal Agencies Must Transition to Instrumentation Based Application Security
Read this eBook to discover what federal agencies need to look for in application security in order to fully embrace and realize digital transformation--including Agile and DevOps.
The DevSecOps Guide to Managing Open Source Risk
Read the eBook to learn how organizations need to manage OSS risks using AppSec powered by security instrumentation that unlocks automation.
Using Security Instrumentation to Analyze and Protect Software
Read the eBook to discover how most companies forego robust security testing to accelerate time to market—leaving their organizations at risk.
May - June 2020: Contrast Labs' Application Security Intelligence Report
This report leverages aggregate data from Contrast Security customers to provide insights about the vulnerabilities in software that we protect—and attacks on those applications.
Contrast Delivers Pipeline-native security for federal developers
Read this White Paper to learn how development teams with Federal agencies can use pipeline-native security from Contrast.
Advanced Threat Landscape and Legacy Application Security Ratchet Up Risk
Read this White Paper to learn how advances in the threat landscape create new application security challenges.
Understanding the Risks of Open-Source Software
Read the White Paper to find out how increased use of third-party OSS accelerates time to market but also increases software risk.
A Major Roadblock to Business Innovation
Read the White Paper to learn how AppSec tools and processes are a big drag on DevOps, as they are unable to keep pace with modern software development.
Contrast Security and Secure Code Warrior
Read this Solution Brief to learn how Secure Code Warrior integrates with the Contrast Application Security Platform to deliver just-in-training security to developers.
How Contrast Protect Integrates With Microsoft Azure Sentinel And Amplifies Enterprise Defenses
Read this Solution Brief to understand how the Contrast Application Platform integrates with Azure Sentinel to deliver consolidated security views to security practitioners
Contrast Application Security Platform Solution Brief
The Contrast Application Security Platform is designed to integrate with Agile and DevOps processes by operating within the application itself. Contrast leverages instrumentation to embed security within the application runtime that solves the challenges legacy application security tools present in modern software environments.
Contrast Oss: Automated Open-Source Security Without The Noise
Read this Solution Brief to learn how Contrast OSS offers a new approach to SCA by prioritizing the risk that matters most and streamlines remediation by analyzing which libraries are actually in use during application runtimes.
2021 State Of Application Security In Financial Services Report
Read this Report to discover how application security in financial services is failing to keep pace, incurs huge inefficiencies, and fails to stop successful attack exploits.
Jan - Feb 2021: Contrast Labs' Application Security Intelligence Report
Read the January-February 2021 AppSec Intel Report from Contrast Labs to learn about the hottest trends in application security based on real-world data.
Contrast Protect: Runtime Application Protection And Observability
Read this Solution Brief to learn how Contrast Protect delivers runtime application protection and observability.
Contrast Security Integration With Devops Chat Tools
Read about Contrast's integrations with common chat tools such as Slack and Microsoft Teams to help improve workflow orchestration and accelerate application delivery.
Contrast Security Integration with DevOps Ticketing Systems
Read this Solution Brief to learn how the Contrast Application Security Platform integrates with ticketing systems.
Contrast Security Integration with CI/CD Pipelines
Read this Solution Brief to learn how Contrast integrates security testing with existing tools and workflows that developers use in their DevOps and Agile environments.
The State of DevSecOps Report
Read Contrast Security’s “The State of DevSecOps Report” to learn how global organizations are addressing DevSecOps, what benchmarks exist, and how they are overcoming the challenges.
Locking Down Docker Security with Instrumentation in the Contrast Platform
Read this Solution Brief to learn how Contrast helps secure and protect Docker containers.
How Contrast Security Supports and Improves Government Reference Designs
Read this Solution Brief to understand how Contrast Security supports and improves government reference designs.
Keeping Kubernetes Secure with Instrumentation
Read this Solution Brief for an overview of why and how the Contrast Application Security Platform enables organizations to secure and protect applications running in Kubernetes-enabled containers.
Facilitating Secure Journeys to the Cloud with the Contrast Application Security Platform
Read this Solution Brief to understand how the Contrast Application Security Platform helps facilitate secure journeys to the cloud.
Contrast Assess with Interactive Application Security Testing (IAST)
Read the solution brief to learn how Contrast Assess uses instrumentation to embed security directly into the development pipeline.
Automatically Identify Software Vulnerabilities and Verify Their Remediation with Route Intelligence
Read the solution brief to learn how adding Route Intelligence capabilities to Contrast Assess delivers comprehensive security visibility while automating the workflows.
Contrast Protect Product Brief
Contrast Protect's instrumentation enables our agent to perform attack detection and response with more insight, at a deeper level than other solutions. We take a seven-step approach that is more robust and comprehensive to improve the likelihood of blocking zero-day attacks and detecting probe attempts.
Snap Finance
Experience Contrast today
See how you could get secure code moving on the Contrast Secure Code Platform