Insights from experts shaping secure development
Access expert content on secure coding, AI governance, and software risk management.

Gartner Security & Risk Management Summit 2026
Excited to sponsor the Gartner Security & Risk Management Summit in London, September 22–24, 2026! Come connect with our team to see how Secure Code Warrior is helping organizations govern AI-generated code and build lasting security skills across the SDLC. See you there!

La puerta trasera de XZ Utils en Linux apunta a un problema de seguridad de la cadena de suministro más amplio, y necesitamos algo más que un espíritu comunitario para mantenerlo a raya
Se descubrió una vulnerabilidad crítica, la CVE-2024-3094, en la biblioteca de compresión de datos XZ Utils utilizada por las principales distribuciones de Linux, introducida a través de una puerta trasera por un actor de amenazas. Este problema de alta gravedad permite la posible ejecución remota de código, lo que supone un riesgo importante para los procesos de creación de software. La falla afecta a las primeras versiones (5.6.0 y 5.6.1) de XZ Utils en Fedora Rawhide, y es urgente que las organizaciones implementen parches. El incidente subraya el papel fundamental de los voluntarios de la comunidad en el mantenimiento del software de código abierto y pone de relieve la necesidad de mejorar las prácticas de seguridad y el control de acceso durante el ciclo de vida del desarrollo del software.

Aprovechar los beneficios de la innovación de la IA depende de empezar con un código seguro
La IA generativa ofrece a las empresas de servicios financieros muchas ventajas, pero también muchos riesgos potenciales. Capacitar a los desarrolladores en las mejores prácticas de seguridad y combinarlas con modelos de IA puede ayudar a crear código seguro desde el principio.

Aprovechar la inteligencia artificial y las medidas proactivas para una gestión eficaz de las alertas de vulnerabilidad
Secure Code Warrior y Mend.io analizan los impactos de la IA en la seguridad, los enfoques de seguridad proactivos y la gestión eficaz de las alertas de vulnerabilidad.

Kamer van Koophandel Sets the Standard for Developer-Driven Security at Scale
Kamer van Koophandel shares how it embedded secure coding into everyday development through role-based certifications, Trust Score benchmarking, and a culture of shared security ownership.
Going for Gold: Soaring Secure Code Standards at Paysafe
See how Paysafe's partnership with Secure Code Warrior led to a 45% boost in developer productivity and a major reduction in code vulnerabilities.

DigitalOcean Decreases Security Debt with Secure Code Warrior
DigitalOcean's use of Secure Code Warrior training has significantly reduced security debt, allowing teams to focus more on innovation and productivity. The improved security has strengthened their product quality and competitive edge. Looking ahead, the SCW Trust Score will help them further enhance security practices and continue driving innovation.

The Register: curl vulnerabilities ironed out with patches after week-long tease
After a week of rampant speculation about the nature of the security issues in curl, the latest version of the command line transfer tool was finally released today. Described by curl project founder and lead developer Daniel Stenberg as "probably the worst curl security flaw in a long time," the patches address two separate vulnerabilities: CVE-2023-38545 and CVE-2023-38546.

Security Boulevard: Why Are APIs so Easy for Threat Actors to Exploit?
Enterprises run an average of 15,564 APIs within their organization. That’s far too many to track without a plan, and the general lack of ownership surrounding API security has created the ultimate white elephant.

Secure Code Warrior to Host 3rd Annual Devlympics Competition
Secure Code Warrior, the global, developer-driven security leader, today announced that it will host its third annual Devlympics secure coding competition on October 17-18, 2023.

Citizen AI by Secure Code Warrior
AI risk doesn't stop at engineering. Get the one-pager on Citizen AI — build AI literacy and safe habits across your whole workforce.

Understand how AI is transforming software development—and how security must evolve with it.
From AI autocomplete to autonomous agents—explore how software development is evolving and what it means for security, governance, and your team.






