Skip to content

AppSec Observer

Contrast's application security blog provides the latest trends and tips in DevSecOps through instrumentation and security observability.

Subscribe Now
    Topics

    The WikiLeaks CIA Dump Dominates AppSec News Coverage

    WikiLeaks has been dominating recent news when it released "Vault 7", a new series of leaks it claims came from the..

    Crash Testing your Connected Stuff — Before you Get Hacked!

    Crash Testing your Connected Stuff — Before you Get Hacked!

    People have to pay to subscribe to Consumer Reports. But you may benefit from a new wave of security testing — for..

    CVE-2017-5638 – Struts 2 S2-045 Exploit Released – Protection Offered

    On March 6, a new remote code execution vulnerability was disclosed1 against Struts 2 (2.3.5-2.3.31 and 2.5-2.5.10.)..

    Jeff-Williams-Contrast-Security.jpg

    3/16 WEBINAR: Scaling Rugged DevOps

    Attend a live webinar on Thursday, March 16th and hear how Tim Chase of Nielsen is scaling their DevOps function by: •..

    It’s Still Flu Season: Get a Flu Shot! Masks Won’t Help — Same Goes for AppSec — Read a WAF Comparison

    It’s Still Flu Season: Get a Flu Shot! Masks Won’t Help — Same Goes for AppSec — Read a WAF Comparison

    Come flu season, you have two options – cover your face with a mask and hope you don’t catch anything. Or, do the..

    owasp-logo-vert.png

    What is OWASP, and Why it Matters for AppSec

    Vulnerability research conducted by Contrast Labs was referenced in an article "What is OWASP and Why it Matters for..

    A Word About Security in Application LifeCycle Management (ALM)

    Agile development and DevOps are fueling the evolution of application lifecycle management (ALM) as delivery cycles..

    Cybersecurity Execs Voice Concern over Trump Travel Ban

    Cybersecurity Execs Voice Concern over Trump Travel Ban

    Last Friday President Trump signed executive orders that banned nationals of seven countries that included all people..

    DevOps Security: Turn Security into Code [RSA Preview]

    DevOps Security: Turn Security into Code [RSA Preview]

    The San Francisco edition of the annual RSA security conference is just around the corner. DevOps security is a hot..