Skip to content

AppSec Observer

Contrast's application security blog provides the latest trends and tips in DevSecOps through instrumentation and security observability.

Subscribe Now
    Topics
    0-Day Detection of Log4j2 Exploit Vulnerability

    0-Day Detection of Log4j2 Exploit Vulnerability

    The world’s most used logging framework was just hit by the Log4j2 exploit, but DevSecOps teams can quickly identify..

    Contrast SECURITY VULNERABILITY DETECTION vs the Log4J2 CVE - A demonstration

    Contrast SECURITY VULNERABILITY DETECTION vs the Log4J2 CVE - A demonstration

    This week, Contrast Security proved that we could detect the Log4j2 vulnerability that caused CVE-2021-44228 and stop..

    Detecting a New Grafana Exploit in Go

    Detecting a New Grafana Exploit in Go

    A new Grafana vulnerability has been discovered that enables arbitrary file reads off the system. This vulnerability..

    Navigating (and Responding) to the Federal Binding Operational Directive 22-01

    Navigating (and Responding) to the Federal Binding Operational Directive 22-01

    The Directive Just over two weeks ago, on November 3rd, the Cybersecurity and Infrastructure Security Agency (CISA), a..

    The Trojan Source is Not Your Mane Problem

    The Trojan Source is Not Your Mane Problem

    A recently published paper provides a logo and slick polish for an old vulnerability about the ability of certain..

    Automating .Net 6 Application Protection

    Automating .Net 6 Application Protection

    Microsoft will officially release the next LTS version of .NET this week at .NET Conf on November 9th. Contrast is a..

    Contrast Security named a 2021 Gartner Peer Insights Customers’ Choice for the 3rd year in a row for Application Security Testing

    Contrast Security named a 2021 Gartner Peer Insights Customers’ Choice for the 3rd year in a row for Application Security Testing

    Contrast Security receives 94% willingness to recommend based on 74 customer reviews As Contrast Security continues to..

    SECURING THE SOFTWARE SUPPLY CHAIN STARTS WITH A SOFTWARE BILL OF MATERIALS (SBOM)

    SECURING THE SOFTWARE SUPPLY CHAIN STARTS WITH A SOFTWARE BILL OF MATERIALS (SBOM)

    As readers of the AppSec Observer blog are aware, application attacks have continued unabated throughout the massive..

    Understanding Software Supply Chain Risks and How to Mitigate Them

    Understanding Software Supply Chain Risks and How to Mitigate Them

    As demand for new applications continues to rise, developers are adapting new tools and techniques to accelerate their..