Skip to content

AppSec Observer

Contrast's application security blog provides the latest trends and tips in DevSecOps through instrumentation and security observability.

Subscribe Now
    Topics
    It’s SBOM time!

    It’s SBOM time!

    A new memo (PDF) from the Office of Management and Budget (OMB) — M-22-18, published last month — is clear in setting..

    Does Cybersecurity Awareness Month matter?

    Does Cybersecurity Awareness Month matter?

    This year, as Contrast Security Chief Information Security Officer David Lindner announced last week, Contrast was once..

    CVE-2022-42889: Don’t panic, do patch

    CVE-2022-42889: Don’t panic, do patch

    There’s a new Common Vulnerability and Exposure (CVE) getting some buzz: Apache Commons Text, which is exploitable via..

    Contrast's MTTR is 37x faster than the competition

    Contrast's MTTR is 37x faster than the competition

    Security debt — the backlog of known and unresolved vulnerabilities in an organization’s applications — is a drag,..

    Cybersecurity Insights with Contrast CISO David Lindner | 10/14

    Cybersecurity Insights with Contrast CISO David Lindner | 10/14

    Insight #1 " The White House says “Energy Star” security labels for Internet of Things (IoT) devices are coming! This..

    Contrast Security expands its GitHub security coverage with new SCA GitHub Action scan

    Contrast Security expands its GitHub security coverage with new SCA GitHub Action scan

    There are more than 73 million developers currently utilizing GitHub, and rightfully so, since GitHub has become a..

    Cybersecurity Insights with Contrast CISO David Lindner | 10/7

    Cybersecurity Insights with Contrast CISO David Lindner | 10/7

    Insight #1 " Detecting and reporting phishing is very important for any organization. The easiest way for users to..

    Scaling security with the speed of modern software development

    Scaling security with the speed of modern software development

    What if you could instantly prevent 95%* of the vulnerabilities in your running applications from being exploited? With..

    Find JavaScript security vulnerabilities for free with CodeSec vulnerability scanner

    Find JavaScript security vulnerabilities for free with CodeSec vulnerability scanner

    According to a 2022 Stack Overflow survey of more than 50K professional developers, JavaScript is the top programming..