Insights from experts shaping secure development
Access expert content on secure coding, AI governance, and software risk management.
사이버 회복력 법안(Cyber Resilience Act) 대비에 SBOM이 중요한 이유
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
대형 의료 제공업체가 개발자 중심 접근 방식으로 보안 문화를 혁신한 방법
Contrast Security의 공동 설립자 Jeff Williams와 Secure Code Warrior의 Matias Madou가 안내하는 의료 기관의 보안 문화 혁신 사례를 들어보세요.
임베디드 시스템과 팀 역량 강화
사물 인터넷, 생산 시스템의 자동 제어 및 관리는 임베디드 시스템 개발을 촉진하는 몇 가지 요소에 불과합니다. 임베디드 소프트웨어의 보안 취약점이 미치는 영향과 이를 완화하는 방법은 무엇일까요?
컴플라이언스를 넘어: 흥미진진한 애플리케이션 보안을 제공하는 팁
개발 팀이 애플리케이션 보안 교육을 단순한 체크박스 채우기로 취급하나요? 개발자가 스스로 찾아오는 교육 프로그램을 만드는 실용적인 팁을 확인하세요!
훌륭한 SOC 2 보고서 달성을 위한 모범 사례
SOC 보고서 프로젝트에 직면하면 때로는 매우 막막하게 느껴질 수 있습니다. 업계 전문가들과 함께 SOC 2 보고서 획득을 위한 핵심 팁을 나눕니다.

2021 HMG Live! 실리콘밸리 CISO 최고경영자 서밋
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
웨비나: DevOps에서 DevSecOps로: 처음부터 품질과 보안이 확보된 개발 제공
전문가들이 SDLC에 보안 교육 및 애플리케이션 보안을 구현하기 위한 핵심 고려 사항, 게이미피케이션 학습을 통해 개발자를 참여시키는 방법, 다운타임이나 비용 부담 없이 보안 테스트를 통합하는 방법을 설명합니다.
코스 내 튜토리얼(Walkthroughs) 심층 탐구
새로운 Walkthrough & Missions 몰입형 실습 교육 활동이 개발자의 참여를 유도하고 입증된 단계별 학습 방식으로 개발자 역량을 단계적으로 향상시키는 방법을 알아보세요.
업스킬링, AppSec 보안 격차를 줄이기 위한 마지막 열쇠
Zip의 보안 총괄 Peter Robinson과 Secure Code Warrior의 공동 설립자이자 AppSec 트레이너인 Jaap Singh으로부터 보안 격차를 줄이기 위해 임직원의 사이버 보안 기술 향상이 필수적인 이유에 대한 심도 있는 논의를 들어보세요.
개발자 주도 보안의 ROI
테크 스택이나 추가 교육 프로그램에 투자할 때 누구나 투자 대비 좋은 수익률(ROI)을 원하지만, 보안에 있어서는 단순한 ROI 계산을 넘어 장기적인 안목으로 접근해야 합니다. 개발자 주도 보안 투자가 비싼 보안 침해 비용과 생산성 손실을 줄이는 방법과 비용 효율적인 전략을 배우세요.
시큐리티 챔피언으로 가는 길
Workday가 개발자 역량 강화를 위해 애자일 보안 학습을 활용한 방법입니다.

코드 아웃 오브 더 케이스: 보안 개발자가 제한 없이 출시할 수 있는 이유
핵심 인프라, 자동차, 의료 기술 및 그 사이의 모든 것을 지원하는 코드를 개발하는 대부분의 개발자가 보안 능력을 먼저 확인하지 않고 작업을 한다는 것은 당혹스러워 보입니다.반면에, 안전하게 구축하는 방법을 이해하고 있다는 것을 수차례 입증한 보안 전문 개발자들이 모든 보안 게이트 때문에 계속 느려지는 개발 파이프라인에서 다른 사람들과 함께 줄을 서야 하는 이유는 무엇일까요?

애자일 학습 플랫폼의 ROI
코드 취약성과 기술적 부채를 해결하는 데 드는 비용은 높으며 소프트웨어 개발 팀의 생산성을 지속적으로 저해하고 있습니다.보안 코드용 애자일 학습 플랫폼을 구현하면 개발자에게 보안 코딩 기술을 더 효과적으로 교육하여 SDLC에서 더 빠르고 조기에 취약점을 수정하고 애초에 취약점을 방지하여 비용을 크게 절감할 수 있는 방법을 알아보십시오.이 블로그에서는 애자일 학습 플랫폼의 재정적 영향과 ROI에 대해 생각하는 방법을 간략하게 설명합니다.

보안 코딩의 기준 제고: 미래에 대비한 기업에 애자일 러닝 적용
우리는 Series-C 펀딩 라운드를 마감한다고 발표했습니다. Series-C 펀딩 라운드는 우리의 사명의 다음 단계, 즉 선구적인 조직이 개발 집단의 힘을 활용하여 일반적인 취약점을 차단할 수 있도록 지원하는 것입니다.

I guess this is growing up: Coming of age with CISA’s Secure-by-Design Guidelines
The recently released National Cybersecurity Strategy signals the need for a seismic cultural shift for most companies, with the most glaring recommendation coming in the form of security accountability falling primarily on software vendors. This is a positive step, though it is sure to cause teething problems, especially as many organizations struggle to accurately assess their security maturity across the board, particularly among the development cohort.

보안 코드를 위한 애자일 러닝으로 개발자를 사로잡는 방법
보안 코드를 위한 애자일 학습 플랫폼을 위한 개발자 워크플로 및 도구에 투자할 수 있는 방법을 알아보고 보안 코드 학습 구축하기 시작하세요.

PCI-DSS 4.0은 생각보다 빨리 출시될 것이며 조직의 사이버 복원력을 향상시킬 수 있는 기회입니다.
올해 초 PCI 보안 표준 위원회는 결제 카드 산업 데이터 보안 표준 (PCI DSS) 의 버전 4.0을 공개했습니다.2025년 3월까지 조직에서 4.0을 완벽하게 준수할 필요는 없지만, 이번 업데이트는 현재까지 나온 것 중 가장 혁신적인 업데이트이므로 대부분의 기업은 복잡한 보안 프로세스와 기술 스택의 요소를 평가 (그리고 업그레이드할 가능성이 높음) 해야 합니다.여기에는 개발자를 위한 역할 기반 보안 인식 교육 및 정기적인 보안 코딩 교육도 추가로 실시됩니다.

교육에서 애자일 학습까지: 보안 코드를 위한 애자일 학습 플랫폼이 보안 소프트웨어에 대한 접근 방식을 혁신하는 방법
보안 코드를 위한 애자일 학습 플랫폼이 SDLC에서 처음부터 시작하여 시간이 지남에 따라 개발자의 기술을 향상시키고 위험을 줄이며 기술적 부채를 줄이는 방법을 알아보세요.

조직 계층 구조에서의 소프트웨어 재검토
엄격한 계층 구조 내에서 앱과 소프트웨어의 책임을 정의하고 이러한 정책을 최소 권한으로 적용함으로써 위협 환경에도 불구하고 앱과 소프트웨어가 생존하고 번창할 수 있도록 할 수 있습니다.

사전 보호: 지능형 위협 방지를 위한 국가 사이버 보안 전략 활용
CISA의 국가 사이버 보안 전략은 소프트웨어 표준을 전반적으로 높이고 마침내 보안 기술을 갖춘 개발자의 새로운 시대를 열 수 있는 최고의 기회입니다.

MVC 요청/매처 스프링 취약점 자세히 살펴보기
2023년 3월 20일, 스프링 시큐리티 어드바이저리는 내부적으로 발견된 취약점인 CVE-2023-20860 취약점을 언급하는 블로그 게시물을 게시했습니다.'MVCMatchers' 사용과 관련된 액세스 제어 문제라는 점을 제외하고 자세한 정보는 공개되지 않았습니다.Spring 개발자들이 이 문제를 해결했으며 버전 업데이트가 권장됩니다.Secure Code Warrior에서는 보안이 주안점이기 때문에 MVCrequestMatchers의 취약점을 자세히 살펴보고 핵심 문제가 어디에 있는지 알아보기로 했습니다.

피터 다니유 (Pieter Danhieux), 시큐어 코드 워리어 (Secure Code Warrior) CEO 겸 공동 설립자: “모든 사람은 사이버 보안에서 자신이 하는 역할을 이해하고 수용해야 합니다.”
시큐어 코드 워리어의 CEO 겸 공동 창립자인 피터 다니유와의 사이버뉴스 Q&A.

SDLC의 생산성 가속화 및 비용 절감의 핵심
소프트웨어 개발 라이프사이클의 가장 큰 격차 중 하나는 개발자가 처음부터 코드 보안 방법을 배울 시간이 부족하다는 것입니다.개발자들은 재작업과 수정에 셀 수 없이 많은 시간을 허비하며, 그 결과 기회 손실 비용이 수백만 달러에 달합니다.빠른 보안 코딩이 이러한 격차를 줄이고 생산성을 가속화하는 데 어떻게 도움이 되는지 알아보십시오.

#시큐어 코드: 워리어의 새로운 기능: 교육, 과정, 가이드라인, 참여, 관리, 새로운 콘텐츠
시큐어 코드 워리어의 기능: 새로운 기능: 교육 과정을 통해 콘텐츠를 탐색하는 새로운 경험해 보십시오.

메타버스에서의 악의적: 새로운 국경에서 알려진 사이버 위협에 맞서기
현재 가장 사랑받는 디지털 플랫폼인 메타버스의 등장으로 코드 수준의 취약점과 소셜 엔지니어링 모두에 대한 새로운 공격 표면이 추가되었습니다.게다가 우리는 연기와 거울을 기반으로 하는 이 새로운 경기장에서 전투를 벌일 준비가 되어 있지 않을 뿐입니다.

개발자 주도 보안을 통한 기술적 부채 완화
안전하지 않은 코드와 그에 따른 기술적 부채를 해결하는 데 드는 비용은 오늘날 기술이 직면한 가장 큰 장애물 중 하나입니다.확장 가능한 보안 코드 교육 프로그램을 구현하여 소프트웨어 개발 주기 초기에 잘못된 코딩 패턴을 해결하고 취약성을 탐지하여 기술적 부채를 줄이는 데 어떻게 도움이 되는지 알아보십시오.

개발자는 “보안 코딩”을 어떻게 정의합니까?
보안 코딩 행위를 구성하는 요소에 대한 인식은 논쟁의 여지가 있습니다.에반스 데이터 (Evans Data) 와 공동으로 진행한 최근 연구에 따르면 이러한 감정은 흑백으로 드러났습니다.개발자 주도 보안 현황 2022년 설문조사에서는 1200명의 현역 개발자를 대상으로 한 주요 인사이트와 경험을 바탕으로 보안 영역에서의 태도와 과제를 조명합니다.

Coding Labs: Hands-on secure code for Developers
Learn how Coding Labs is like a personal trainer for developers- utilizing interactive, hands-on modules and intuitive feedback within a convenient in-browser IDE to help developers go from learning to doing faster than ever before.

시큐어 코드 워리어 8주년: 모두 로켓선에 탑승하세요
이번 주에는 공식적으로 시큐어 코드 워리어 탄생 8주년을 기념합니다.한 편으로는 아폴로 11호 임무 길이의 350배에 달하며, 축구 경기 45,000경기, 즉 슈퍼 마리오 오디세이를 끝까지 5696회 플레이한 것과 같습니다.다른 한편으로는 자이언트 토터스 수명의 1/3에 불과합니다 (궁금하시다면 250년).고성장 스타트업의 세계에서는 수많은 우여곡절, 교훈, 성취의 여정을 의미하는데, 그 중 상당수는 우리가 처음 사업 계획을 세울 때는 상상도 할 수 없었던 것들입니다.

2022년 리뷰 - 시큐어 코드 워리어를 최대한 활용하는 데 도움이 되는 하이라이트, 새로운 혁신, 리소스
Secure Code Warrior에서는 개발자와 조직이 오늘날의 끊임없이 변화하는 보안 문제를 해결하는 데 필요한 적절한 기술을 갖추도록 돕기 위해 끊임없이 혁신하고 있습니다.조직에서 소프트웨어 개발 주기가 시작될 때 개발자 중심 보안을 통해 소프트웨어를 보호할 수 있도록 올해 발표된 리소스 및 지침뿐만 아니라 플랫폼의 주요 기능 및 업데이트를 모아 놓았습니다.

개발자 기반 보안의 ROI
누구나 기술 스택이나 추가 교육 프로그램에 투자할 때 좋은 투자 수익을 원하지만 보안에 관해서는 단순한 ROI를 계산하는 것 이상의 긴 게임을 해야 합니다.개발자 주도 보안에 투자하여 비용이 많이 드는 보안 침해, 생산성 손실, 누적된 기술 부채로 인한 비용을 절감할 뿐만 아니라 오늘날의 위협 환경에 앞서 나갈 수 있는 사전 예방적이고 비용 효율적인 전략을 수립하는 방법을 알아보십시오.

개발자 주도 보안에 대한 일관된 접근 방식 확립
소프트웨어 업데이트 프로세스를 통해 주요 기업 및 정부 기관을 비롯한 인기 있는 Orion 관리 소프트웨어 사용자 18,000명 이상을 감염시킨 SolarWinds 캠페인과 같은 주요 보안 침해에 대응하여 보다 효과적인 개발자 주도 보안 노력에 대한 요구가 증가하고 있습니다.규모를 막론한 모든 조직에서 자사의 '소프트웨어 공급망'에 의문을 제기하기 시작하면서 소프트웨어를 만드는 개발자에게 검증된 보안 기술과 인식을 갖추도록 요구하고 있습니다.

SCW 통합: 마이크로 러닝으로 평균 문제 해결 시간 단축
견고한 테크스택의 중요성은 누구나 알고 있습니다.Secure Code Warrior의 통합 목표는 코드의 취약점을 찾아 수정하고, 평균 수정 시간을 단축하고, 신뢰할 수 있는 강력한 솔루션을 사용하는 것입니다.마이크로 러닝 모멘트를 개발자의 워크플로에 통합하는 것이 더 나은 학습과 더 빠른 해결의 핵심입니다.

반복 가능한 보안 체계 체계로 좌회전 (및 규정 준수)
오늘날 거의 모든 개발자 팀은 업계 프레임워크 또는 정부 규정의 범위를 벗어나는 데 도움이 되는 초기 인증 프로세스의 일부이자, 연간 요구 사항이나 검토의 일부와 관계없이 모두가 이해할 수 있는 서비스를 제공합니다.조직이 기본적인 규칙을 지키기 위한 요구 사항을 충족하지 못하도록 하기 위해 최선을 다합니다.

잘못된 코딩 패턴은 심각한 보안 문제로 이어질 수 있습니다... 그렇다면 왜 권장할까요?
개발자는 취약점이 작동하는 방식, 취약점이 위험한 이유, 취약점을 유발하는 패턴, 상황에 맞는 상황에서 취약점을 해결하는 설계 또는 코딩 패턴에 대한 기본적인 이해 없이는 취약성 감소에 긍정적인 영향을 미칠 수 없습니다.스캐폴디드 접근 방식을 사용하면 지식 계층을 통해 안전하게 코딩하고, 코드베이스를 방어하고, 보안을 생각하는 개발자로 우뚝 서는 것이 무엇을 의미하는지 전체적으로 파악할 수 있습니다.
Secure Code Warrior, 가트너 소프트웨어 엔지니어링 부문 우수 공급업체로 선정: 개발자 생산성 향상
개발자 보안 기술의 중요성은 2022년 Gartner 소프트웨어 엔지니어링 분야의 쿨 벤더 (Cool Vendors) 에서 강조되었습니다.자세한 내용을 읽고 전체 보고서를 받아보세요.

보안 코드 정의
디지털 비즈니스를 주도하는 소프트웨어, 애플리케이션 및 프로그램을 만드는 개발자는 많은 조직의 생명줄로 자리 잡았습니다.경쟁사의 애플리케이션 및 프로그램이 없거나 웹 사이트 및 기타 인프라에 24시간 액세스하지 않으면 대부분의 현대 비즈니스가 (수익성) 운영될 수 없습니다.

파이썬 타르파일 모듈의 경로 탐색 버그 이해하기
최근 보안 연구팀이 파이썬의 타르 파일 추출 기능에서 15년 된 버그를 발견했다고 발표했습니다.이 취약한 2007년에 공개되었으며, 처음 CVE-2007-4559 범주로 추적되었습니다.공식 파이썬 문서에 메모가 추가되었지만 버그 정보는 패치되지 않은 채 남아 있습니다.
.avif)
SCW의 새로운 기능: 코딩 랩, LMS 통합 등
Secure Code Warrior의 새로운 기능: Coding Labs에서 개발자 교육을 직접 체험하고, 보안 코드 교육 프로그램을 LMS와 통합하는 등 다양한 기능을 이용할 수 있습니다.

하드코딩된 자격 증명은 보안 위험을 초래할 수 있습니다.
Uber의 최근 보안 사고에 대해 알아보면서 하드코딩된 자격 증명 및 소셜 엔지니어링과 관련된 위험에 대해 자세히 알아보고 조직에서 탈피하여 개발자에게 보안 코딩 모범 사례를 최신 상태로 유지하는 것이 왜 그렇게 중요한지 알아보세요.

끊임 없는 공격 표면 시대의 예방
소프트웨어 개발은 더 이상 섬이 아닙니다. 클라우드, 어플라이언스 및 차량의 임베디드 시스템, 주요 인프라, 모든 것을 연결하는 API는 말할 것도 없고 모든 것을 포함하는 소프트웨어 기반 위험의 모든 측면을 고려할 때 공격 표면은 국경이 없고 통제 불능 상태입니다.

우리는 오픈소스 소프트웨어 보안 동원 계획에 충분히 성숙했는가?
오픈 소스 소프트웨어 보안 동원 계획은 개발자 주도 보안을 위한 긍정적인 단계입니다.하지만 우리 모두 최신의 가장 뛰어난 방어 전략을 구현할 수 있을 만큼 조직의 성숙도가 높은지, 그리고 개발 팀이 적절한 수준의 보안 인식과 기술을 갖추고 있는지 재고하고 정직하게 평가해야 합니다.

개발 팀의 보안 성숙도의 중요성
좌익으로 전환하려면 개발 팀 내에서 보안 지식과 기술을 집단적이고 지속적으로 개선해야 합니다.

API 보안: 미션 임파서블?
API 보안은 어렵지만 적절한 교육, 계획 및 모범 사례에 초점을 맞추면 가장 취약한 취약성도 완화할 수 있습니다.

신규: Okta 워크플로를 위한 SCW 커넥터
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
.avif)
시큐어 코드 워리어의 새로운 기능: 2022년 5월
더 쉽고 강력한 교육 과정 생성 흐름, 얼리 액세스 토글, SAP ABAP 교육 콘텐츠
신규: ABAP 교육 콘텐츠로 안전한 SAP ABAP 코드를 더 빠르게 출시하세요
ABAP 개발자를 위한 실용적이고 효과적인 보안 코딩 교육.

사이킥 시그니처 - 알아야 할 사항
Psychic Signature 취약점은 인증과 같은 중요한 작업을 위해 시스템을 보호하는 ECDSA 서명용 암호화에 있습니다.해커는 이 취약점으로 인해 모든 서명 검사를 우회할 수 있습니다.이 게시물에서는 이 문제의 정의 및 완화 방법에 대해 설명하겠습니다.

NGINX 및 마이크로소프트 윈도우 SMB 원격 프로시저 호출 서비스의 소프트웨어 취약점에 미리 대비하세요
최근 NGINX는 제로데이 취약점을 공개했습니다.비슷한 시기에 Microsoft는 또 다른 심각한 취약점인 Windows RPC RCE 취약점을 공개했습니다. 이 게시물에서는 이 두 가지 문제의 위험에 처한 사람과 위험을 완화할 수 있는 방법을 확인할 수 있습니다.

제로데이 공격이 증가하고 있습니다.방어 전략을 세워야 할 때입니다.
정의에 따르면 제로 데이 공격은 위협 행위자가 먼저 침입하기 때문에 개발자가 악용될 수 있는 기존 취약점을 찾아 패치할 시간을 전혀 주지 않습니다.피해를 입은 다음에는 소프트웨어와 비즈니스에 미치는 평판 훼손 모두를 해결하기 위한 광란의 난타전이 벌어집니다.공격자는 항상 우위를 점하기 때문에 최대한 우위를 점하는 것이 중요합니다.

개발팀의 우선 순위 목록에서 보안 위치는 어디입니까?
에반스 데이터 코퍼레이션 (에반스 데이터 코퍼레이션)과 파트너십 전 세계 개발자 커뮤니티를 대상으로 한 보안 관행에 관한 기술 인식, 행동, 그리고 소프트웨어 개발 라이프사이클 (SDLC) 에서의 영향력 및 관련성에 대한 설문조사를 실시했습니다.결과는 매우 놀라웠습니다.

Spring 라이브러리의 새로운 취약점: 위험에 처해 있는지 확인하는 방법과 대처 방법
최근 자바 커뮤니티에서 가장 인기 있는 라이브러리 중 하나인 스프링 라이브러리가 원격 코드 실행 (RCE) 과 관련된 취약점 2개를 공개했습니다.'Spring4Shell'과 'Spring Cloud Function'에 대한 알려진 세부 정보를 세분화하여 위험에 노출되었는지, 위험에 노출됐을 경우 어떻게 대처해야 하는지를 이해하는 데 도움이 됩니다.

2022년 무시할 수 없는 사이버 보안 문제
사이버 범죄자와 싸울 때는 예방적 사고방식으로 사이버 범죄자의 놀이터를 선점하여 가능한 한 그들과 보조를 맞춰야 합니다.이들이 내년부터 파장을 일으키기 시작할 수 있는 부분은 다음과 같습니다.

트로얀 소스란 무엇이며 소스 코드에 어떻게 스며들게 되나요?
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

최우수선수 vs 코치: 모든 개발팀에 이 두 가지가 모두 필요한 이유
사이버 보안 접근 방식을 목표로 삼고 있는 많은 팀
일반적인 Java 실수를 방지하는 방법
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

7년간의 시큐어 코드 워리어, 이제 현실처럼 느껴지기 시작했어요
우리의 생일 기념일은 우리의 노력의 결실을 되돌아보고, 팀을 축하하고, 자신감을 가지고 다가오는 한 해를 맞이할 수 있는 좋은 기회입니다.창립한 지 7년이 지난 지금, 궁금증이 남습니다. 과연 우리가 해냈을까요?이 회사가 아직 진짜 회사가 아닌가요?물론 우리는 성숙기에 다다랐지만 처음부터 가졌던 호기심, 열정, 괴짜스러움을 결코 잃지 않기를 바랍니다.

스캐폴드 러닝이 보안에 강한 개발자를 구축하는 이유
업계에서는 개발자가 보안 전문가가 될 것이라고 기대해서는 안 됩니다. 하지만 조직은 개발자 지원을 위한 새로운 표준을 채택하여 더 높은 품질의 소프트웨어를 생산할 수 있습니다.

Log4j 취약점 설명 - 공격 벡터 및 예방 방법
2021년 12월, 자바 라이브러리 Log4j에 심각한 보안 취약점 Log4Shell이 공개되었습니다.이 문서에서는 Log4Shell 취약점을 가장 간단한 형태로 세분화하여 기본 사항을 파악하고 이 취약점에 대한 지식을 바탕으로 시뮬레이션된 웹 사이트를 악용해 볼 수 있는 놀이터를 소개합니다.

사이버 보안 산업 분석: 우리가 수정해야 할 또 다른 반복되는 취약점
우리는 현대 사이버 보안이라는 끊임없는 맹공격에 맞서기 위한 현실적인 조언도, 가장 빠른 해결책도 얻지 못하고 있습니다.물론 각 보안 침해는 저마다 다르며, 취약한 소프트웨어에서 악용될 수 있는 공격 벡터도 무수히 많습니다.실행 가능한 일반적인 조언은 제한적이지만 시간이 지날수록 모범 사례 접근 방식에는 더 많은 결함이 있는 것으로 보입니다.

보안 프로그램이 사고 대응에 초점을 맞추고 있습니까?잘못하고 계세요.
사후 대응이 아닌 예방적 접근 방식에 중점을 두는 것은 보안 팀 외부에서 널리 이해되지 않을 수 있습니다. 특히 크고 심각한 보안 사고가 발생하지 않은 경우에는 더욱 그렇습니다.
Make unit tests readable with Sensei and AssertJ
Implement unit test coding guidelines uniformly and consistently

API 온 휠: 위험한 취약점이 가득한 로드 트립
API 보안을 운에 맡기는 것은 나중에 문제를 야기할 수 있는 확실한 방법이며, 최악의 경우 잠재적으로 치명적인 결과를 초래할 수 있고, 재작업과 기껏해야 성능 저하를 야기할 수 있습니다.
조다-타임을 java.time으로 마이그레이션하기
편리한 방법으로 조다-타임을 java.time으로 마이그레이션하십시오.

정부 공급망 파이프라인의 사이버 취약성에 대한 베일 제거
사이버 보안이 중요하다는 것은 분명하지만 공급망의 맥락에서 실제로 의미하는 바는 무엇일까요?

보안을 잘 아는 개발자: AppSec에는 여러분이 필요합니다!
개발자는 AppSec을 통해 수익을 창출할 수 있는 좋은 위치에 있습니다.

상사가 보안 코딩 교육에 투자하도록 설득하는 방법
보안 코딩에 대해 효과적으로 배우고 그 지식을 유지하는 것이 본질적으로 어려운 것처럼 보일 수 있지만 올바른 도구와 문화가 있다면 반드시 그럴 필요는 없습니다.하지만 이해관계자와 상사가 올바른 유형의 교육에 투자하도록 설득하는 것이 항상 쉬운 것은 아닙니다.다음은 이들의 충성도를 높이는 데 도움이 되는 몇 가지 유용한 팁입니다.

개발자에게 인센티브를 제공하는 것이 보안 관행 개선의 핵심입니다
전문 개발자는 DevSecOps를 수용하고 안전한 코드를 작성하기를 원하지만, 조직이 이러한 노력을 확대하려면 이러한 변화를 지원해야 합니다.

경로 탐색 취약점이 최근 아파치 문제의 원인으로 작용한 영향을 경험해 보십시오.
10월 초에 Apache는 경로 탐색 및 원격 코드 실행 취약점을 수정하기 위해 버전 2.4.49를 출시했으며, 수정이 불완전하다는 사실을 해결하기 위해 2.4.50을 출시했습니다.우리는 실제 환경에서 위험을 입증하겠다는 사명을 세웠습니다.지금 사용해 보세요.

워리어 인사이더: Nelnet - 보안 전문가를 양성하고 내부로부터 안전한 개발 문화를 조성하세요
미샤 마르티네즈는 넬넷의 사이버 보안 분석가이자 촬영 감독입니다.개발자를 위한 보안 코딩 관련 교육 프로그램을 만드는 임무를 맡았을 때 그는 창의적인 방법으로 팀을 참여시켰습니다.우리는 그가 보안 코드 교육 프로그램을 운영하는 방식에 깊은 인상을 받았고, 그에 대해 자세히 알아보기 위해 함께 이야기를 나눴습니다.

OWASP의 2021 리스트 셔플: 새로운 전투 계획이자 주요 적
취약점의 왕으로 악명 높은 인젝션 공격 (범주별) 은 액세스 제어 실패로 최악 중 최악으로 1위 자리를 잃었기 때문에 개발자들은 주의를 기울여야 합니다.

고급 보안 인텔리전스: 개발자가 NIST를 준비하도록 돕는 가이드 과정
개발자는 보안 구성 및 액세스 제어 외에도 코드를 가장 가까이서 개인적으로 다루는 사람들입니다.개발자의 보안 기술을 길러야 합니다. 특히 대규모 개발 집단의 경우 NIST에서 제시한 높은 표준을 달성하려면 실습 과정 구조가 이를 해결하는 효율적인 방법일 수 있습니다.

좋은 마이크로웨이브가 나빠질 때: 임베디드 시스템 보안이 개발자들의 다음 보스전이 되는 이유
웹 기반 소프트웨어, API 및 모바일 장치와 마찬가지로 임베디드 시스템의 취약한 코드는 공격자가 도중에 발견할 경우 악용될 수 있습니다.

안전한 개발은 AppSec의 면역 체계가 되어야 합니다
애플리케이션 보안 전문가의 역할은 조직 애플리케이션의 사이버 안전을 보장하는 것입니다.하지만 애플리케이션이 실행되는 코드를 작성할 책임은 없습니다.개발팀 내 엔지니어가 담당합니다.그렇다면 이들이 보안을 염두에 두고 이러한 시스템을 개발하고 있는지 어떻게 확인할 수 있을까요?

임베디드 시스템에서 엔드-투-엔드 보안이 중요한 이유
이 문서에서는 임베디드 시스템 보안에 대한 개요를 다룹니다.기본 정의부터 시작하여 임베디드 보안의 문제점, 몇 가지 일반적인 솔루션, 누락된 퍼즐에 대해 알아보겠습니다.

미스라 C 2012 vs 미스라 C2 - 스위치 만드는 법
이 게시물에서는 MISRA C 2012 표준을 C2와 비교하고 새 표준으로 전환하는 과정을 안내해 드리겠습니다.안전한 임베디드 시스템을 구축하기 위해 MISRA의 규정 준수가 필요한 이유를 설명하겠습니다.

임베디드 장치 및 임베디드 시스템 개발 - 개요
이 게시물에서는 임베디드 장치 및 임베디드 시스템 개발에 대한 개요를 제공합니다.

워리어 인사이더: 콘트라스트 시큐리티 - 개발자에게 상황별 환경을 통한 영향력 있는 사이버 보안 서비스를 제공합니다.
콘트라스트 시큐리티 (콘트라스트 시큐리티) 에서 래리 맥케론 (래리 맥케론) 과 함께 ##도덕 #0 #러닝이 어떻게 개발자들에게 보안 교육을 받을 수 있는지 논의했습니다.조직에서 일상적인 업무와 배려를 할 수 있게 도와주세요.

사이버 보안의 인적 요소를 절대 간과해서는 안 되는 이유
최근 포브스 테크놀로지 위원회 회장 겸 CEO인 피터 다니유 (Pieter Danhieux) 의 첫 번째 포브스 테크놀로지 위원회 게시물이 공개되어 매우 기뻤습니다.이 게시물에서는 개발자의 기술을 향상시켜 보다 안전한 코드를 만드는 것이 사이버 공격과 데이터 침해를 방지하는 데 얼마나 중요한지 자세히 설명했습니다.

유출되는 API로 인해 회사 평판이 바다로 밀려날 위험이 있습니다
API 보안은 대부분의 보안 전문가들이 머릿속에 떠올리지 않는 문제이며, 이에 맞서 싸우기 위한 지식을 갖추어야 하는 문제이기도 합니다.

NIST와 함께 움직이기: 사이버 방어의 미래에 대한 인간 주도의 입장
Biden 행정부의 최근 사이버 보안 행정 명령은 보안 업계, 특히 보안 코딩 모범 사례를 일상 업무에 적용하는 것이 중요하다는 사실을 개발자들의 마음을 사로잡으려는 사람들의 관심을 끌고 있습니다.

워리어 인사이더: 셀리젠트 - 비즈니스를 확장할 때 사이버 보안이 중요한 이유
저희는 최근에 지능형 마케팅 클라우드의 소프트웨어 엔지니어인 Dimitri Vanderhaeghe와 이야기를 나누었습니다.셀리전트 마케팅 클라우드는 고도로 통합된 AI 기반 옴니채널 마케팅 자동화 플랫폼으로, 야심찬 B2C 마케터들이 오늘의 소비자와의 매력 상호 작용을 극대화할 수 있도록 지원합니다.빠르게 변화하는 B2C 회사의 기술

DevSecOps의 등장과 '좌파 전환'이 조직에 실제로 의미하는 바
냉정한 통계치고는 어때요?중소기업의 60% 가 사이버 공격이 성공한 후 6개월 이내에 사업을 중단합니다.대기업은 수백만 (또는 수십억) 의 출혈을 겪습니다!반면 브랜드 평판은 사라졌습니다.보안 코딩 관행을 수용하는 조직이 점점 더 많아지면서 '좌파'가 일어나고 있습니다.DevSecOps의 등장으로 SDLC의 시작부터 보안 코드가 초점이 되고 있습니다.

Sensei Feature Highlight: Library Scope
Discover more about the most loved features of Sensei.
.avif)
안심하고 고품질 코드를 더 빠르게 출시하세요. 보안 코딩 관행의 혁신적인 힘입니다.
IBM의 연구에 따르면 출시 후 취약점을 수정하는 것이 초기에 취약점을 찾아 수정하는 것보다 30배 더 많은 비용이 듭니다.이러한 점을 고려하면 미래 지향적인 CIO가 보안 코딩 관행을 구현하고 있다는 것은 놀라운 일이 아닙니다.이는 개발자들이 처음부터 더 안전한 코드를 작성할 수 있도록 교육하고 준비시키는 것을 의미하며, 이를 통해 개발자를 조직의 '1차 방어선'으로 만들 수 있습니다.
.avif)
보안 코드 교육 = 코드 개선+출시일 단축
품질 보안 코드 교육이 조직에 미치는 잠재적 영향은 무엇이며 가치 있는 투자가 될 수 있을까요?
.avif)
보안 코딩을 중심으로 조직 재조정 — 장벽, 우려 사항 및 능동적 솔루션
초연결 세상에서는 거의 모든 조직이 공통적인 아킬레스건을 공유하고 있습니다.취약점 하나, 악용 가능한 코드 한 부분만으로도 고객 데이터 도용, 평판 손상 및 상당한 재정적 손실이 발생할 수 있습니다.보안 코딩에 대한 조직 조정이 그 어느 때보다 중요하지만, 보안 코딩을 달성하는 것은 말처럼 쉽지 않습니다.

인증된 보안 인식: 개발자 역량 강화를 위한 행정 명령
미국 연방 정부의 최신 행정 명령은 기능적 사이버 보안의 여러 측면을 다루고 있지만, 처음으로 개발자의 영향과 검증된 보안 기술 및 인식의 필요성에 대해 구체적으로 설명합니다.
.avif)
관리자 및 보안 챔피언 — 보안 코딩 관행의 파이퍼이자 중요한 영향력 행사자
현재 보안 코드 실행이 모든 사람의 책임이어야 한다는 데 동의하는 개발자는 15% 에 불과합니다.보안 위협이 증가하는 세상에서는 그것만으로는 충분하지 않습니다.뭔가 조치를 취해야 합니다.건전한 AppSec 문화를 조성하기 위한 한 가지 비결은 주요 영향력 (및 영향력 행사자) 을 이해하는 것입니다.작동 중.

39초마다 사이버 공격이 발생합니다.정부가 마침내 반격할 준비가 되었나요?
사이버 보안 모범 사례에 대한 인간 주도의 접근 방식을 강화해야 합니다. 그러면 자동화, 도구, 이미 내장되어 발견된 문제에 대한 대응에 크게 의존하는 것보다 더 나은 결과를 얻을 수 있을 것입니다.
.avif)
보안 코딩과 관련하여 개발 팀이 밤을 새우는 이유는 무엇일까요?
안전하지 않은 코드는 기업에 수백만 달러의 비용을 초래합니다. 그렇다면 보안 코딩 관행을 채택하는 데 방해가 되는 것은 무엇일까요?거의 모든 것을 소프트웨어에 의존하는 세상에서는 코드의 보안을 보장하는 것이 매우 중요합니다.브랜드 평판과 재정적 생존 가능성은 여기에 달려 있습니다.그렇긴 하지만, 보안 코딩에 대한 우려는 많지만 완전하고 효과적인 채택에는 많은 장벽이 있습니다.그 어느 때보다 새로운 작업 방식이 필요합니다.
.avif)
보안 코드가 소프트웨어 개발의 새로운 성공 지표인 이유
지난 몇 년 동안 네트워크 보안, 테라바이트에 달하는 민감한 고객 데이터, 값을 매길 수 없는 브랜드 평판 등 많은 것들이 시장 출시 속도의 제단에서 희생되었습니다.

눈에 잘 띄지 않는 곳에 숨기: SolarWinds 공격이 악의적인 사이버 위험보다 더 많은 것을 드러낸 이유
사이버 보안 업계에서 크리스마스를 망칠 만한 무언가가 있었다면 이는 엄청난 데이터 유출로 미국 정부에 영향을 미치는 사상 최대 규모의 사이버 스파이 사건이 될 것으로 예상됩니다.
.avif)
더 나은 보안 코딩 결과를 위해 보안 교육을 위한 코드 구성 방법
###############################################교육적 성과에는 많은 것이 부족합니다.
.avif)
현재의 보안 코드 교육은 개발자들을 실망시키고 있습니다.
데이터 침해와 그에 따른 비용이 계속 증가함에 따라 세계에서 생성되는 코드의 양은 보안 전문가가 혼자서 처리하기에는 너무 큽니다.기업에는 보안 코딩 기술을 갖춘 개발자가 필요합니다. 개발자들은 자신의 경력을 발전시키기 위해 보안 코딩 기술이 필요하다는 것을 알고 있습니다.하지만 현재의 보안 코드 교육은 이들을 실망시키고 있습니다.그렇다면 개발자들이 보안 코드 교육에 대해 원하는 것은 무엇일까요?
.avif)
보안 코드 교육이 제대로 활용되지 않는 이유 (및 이에 대해 취할 수 있는 조치)
지루해, 지루해, 지루해!이는 보안 코드 교육이 언급될 때마다 개발자들로부터 듣게 되는 주요 반응 중 하나입니다.시큐어 코드 워리어에서는 더 나은 방법이 있을 거라고 생각합니다.

AppSec 툴링이 특효약이라면 왜 그렇게 많은 기업들이 이를 활용하지 않는 것일까요?
AppSec 도구가 예상대로 활용되지 않는 데에는 몇 가지 이유가 있습니다. 도구 및 기능보다는 전체 보안 프로그램과 통합되는 방식에 관한 것입니다.
.avif)
개발자들은 보안 코딩에 대해 배우고자 하는 동기가 있습니다... 그런데 왜 그렇지 않을까요?
보안 코딩에 대해 배울 때 개발자의 주된 동기는 무엇이며 성공적인 애플리케이션 보안 프로그램을 설계하고 구현하는 데 이를 어떻게 활용할 수 있을까요?
.avif)
보안 코딩의 미래에서 인적 요소는 어떤 역할을 할까요?
사이버 위협의 수가 계속 증가함에 따라 조직은 보안, 실용성 및 속도 사이에서 매일 균형을 유지하며 프로세스의 위험에 노출되고 있습니다.
.avif)
코드를 보호하려면 영웅이 필요합니다.개발자들은 필요한 것을 다 알고 있나요?
사이버 위협이 계속 증가하는 상황에서 코더들이 한 걸음 더 나아가고 있습니까?가장 중요한 개발자인 시큐어 코딩의 인적 요소가 연결된 세상을 보호하는 데 자신의 역할을 할 준비가 되었나요?이 질문에 답하기 위해 Secure Code Warrior가 Evans Data Corp와 함께 수행한 보안 코딩, 보안 코드 관행 및 보안 운영에 대한 개발자의 태도에 대한 최근 연구에서 얻은 몇 가지 인사이트를 살펴보겠습니다.
.avif)
사람이 주도하는 보안 코딩을 통해 사후 대응에서 사전 대응으로 초점 이동
동일한 10가지 소프트웨어 취약점으로 인해 지난 20년 이상 동안 다른 어떤 취약점보다 더 많은 보안 침해가 발생했습니다.하지만 여전히 많은 기업들이 보안 침해 사후, 사후 문제 해결을 선택하고 있습니다. 이 모든 것이 인적 및 비즈니스에 미치는 영향을 헤쳐나가고 있습니다.하지만 이제 새로운 연구 결과 인간이 주도하는 새로운 방향이 제시되고 있습니다.

SQL 인젝션 생일 축하해, 해결할 수 없는 버그
SQL 인젝션 탄생 22주년입니다. 이 취약점을 충분히 마셔버릴 수 있을 만큼 오래되었음에도 불구하고 우리는 이 취약점을 영원히 부수는 대신 더 나은 결과를 가져오도록 내버려 두고 있습니다.
Sensei Product Update - March 2021
Discover the latest improvements to the user experience of Sensei, Secure Code Warrior's IntelliJ plugin and start writing quality code even faster.

신뢰 구축: AppSec과 개발자 간의 진정한 보안 시너지 효과를 위한 길
불안정한 불신의 토대 위에 세워진 관계는 기대치를 낮추고 접근하는 것이 가장 좋습니다.안타깝게도 이는 조직 내 개발자와 AppSec 팀 간의 업무 관계 상태일 수 있습니다.

이 온라인 Java Gotchas 퀴즈를 풀어보세요
몇 가지 문제점과 해결 방법을 보여주는 재미있는 Java Gotchas 퀴즈와 지원 Github 리포지토리
지속적 통합을 통한 IntelliJ 검사 실행
Sensei 및 IntelliJ 인텐션 액션을 IDE 내에서 검사로 배치 모드, 명령줄 및 지속적 통합에서 실행하는 방법을 알아봅니다.

“왼쪽”에서 시작: 보안 코드는 항상 품질 코드인가요?
특정 품질 수준의 코드도 그 정의상 안전하지만 모든 보안 코드의 품질이 반드시 좋은 것은 아닙니다.“왼쪽 또는 왼쪽”으로 시작하는 것이 순수한 보안 코딩 표준을 보장하는 공식일까요?
자바 문제 - 비트별 연산자와 불리언 연산자
이 블로그 게시물에서는 일반적인 Java 코딩 실수 (조건 연산자 대신 비트 연산자 사용), 이로 인해 코드가 취약해지는 오류, Sensei를 사용하여 문제를 해결하고 감지하는 방법을 살펴보겠습니다.

개발자들이 사이버 범죄를 물리치는 데 도움을 주려면 교육을 두 부분으로 나누어 진행해야 합니다.
사이버 보안 분야의 영웅과 악당 간의 경쟁은 불공평한 것으로 악명이 높습니다.민감한 데이터는 새로운 금이며, 공격자들은 방어 시설을 우회하기 위해 빠르게 적응하고 크고 작은 보안 버그를 악용하여 잠재적 이득을 취합니다.

Kamer van Koophandel Sets the Standard for Developer-Driven Security at Scale
Kamer van Koophandel shares how it embedded secure coding into everyday development through role-based certifications, Trust Score benchmarking, and a culture of shared security ownership.
Going for Gold: Soaring Secure Code Standards at Paysafe
See how Paysafe's partnership with Secure Code Warrior led to a 45% boost in developer productivity and a major reduction in code vulnerabilities.

DigitalOcean Decreases Security Debt with Secure Code Warrior
DigitalOcean's use of Secure Code Warrior training has significantly reduced security debt, allowing teams to focus more on innovation and productivity. The improved security has strengthened their product quality and competitive edge. Looking ahead, the SCW Trust Score will help them further enhance security practices and continue driving innovation.

Devlympics 2023: In Review
Explore the Devlympics 2023 results in this report. Dive into developer engagement, tech stack and languages trends in each industry that participated, and key vulnerabilities and CWEs covered in the annual global event hosted by Secure Code Warrior.

One Culture of Security: How Sage built their security champions program with agile secure code learning
Discover how Sage enhanced security with a flexible, relationship-focused approach, creating 200+ security champions and achieving measurable risk reduction.

The path to security champions: How Workday utilized agile learning to upskill developers
Discover how Workday transformed developer training with agile learning through Secure Code Warrior. By empowering developer with hands-on, language-specific education, Workday reduced vulnerabilities early in the SDLC. See their impressive results and key takeaways to build a secure code culture.

How Thales implemented developer-driven security
In this case study, learn how Thales has developed people, process, and technology approaches for an agile secure code learning program in order to engage developers to become active security champions.

How Colgate-Palmolive boosted developer security skills and created a secure coding culture
Discover how retail giant Colgate-Palmolive reshaped its application security during its digital transformation journey. Facing challenges in secure coding, they innovated their approach by integrating bite-sized, in-context learning into the developer workflow.

Security as culture: How Blue Prism cultivates world-class secure developers
Learn how Blue Prism, the global leader in intelligent automation for the enterprise, used Secure Code Warrior's agile learning platform to create a security-first culture with their developers, achieve their business goals, and ship secure code at speed
%252520%252520(3).avif)
Supercharged Security Awareness: How Tournaments are Inspiring Developers at Erste Group
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

How a ‘Game of Codes’ is leading IAG Group to a more secure coding future
IAG Group is the name behind many of the leading insurancecompanies in the Asia-Pacific region, underwriting policies formillions of customers to the tune of approximately AUD $11.4 Billionin premiums per annum.

Driving Actionable Awareness: FINRA's Push For Super-Secure Developers
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Creating a revolutionary security certification experience
Learn how they created an in-house technology education initiative, aimed at supporting thousands of employees to learn practical, cutting-edge skills in a number of disciplines, including machine learning and cybersecurity.
Beyond Compliance: Motorola Solutions Drives Winning Security Culture
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

ASRG's push for automotive software security
Explore this comprehensive case study to learn more about how they utilized Secure Code Warrior's tournaments to engage developers, increase awareness of key vulnerabilities affecting automotive software, and gain metrics across multiple languages and frameworks.
Application Security @ NAB | Gamified Security Training: The Key to Scalable Developer Growth
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Forbes: A New Frontier: NSA Proposes “Security By Design” Considerations For AI Enablement
The cybersecurity industry, which has been advocating for “security by design” principles for more than a decade, stands in wide-eyed amazement at the risks posed by artificial intelligence (AI). As organizations rush to embrace AI enablement, a CISO’s most pressing priority is to avoid becoming a roadblock. However, without effective AI usage and governance, observability and traceability, organizations may be blindsided by their AI risk.

Techpartner.news: Secure Code Warrior introduces framework to govern AI use in software development
Secure Code Warrior has introduced the SCW AI Adoption Model, a framework designed to help organisations govern AI use in software development as the industry shifts from the traditional software development lifecycle (SDLC) toward what the company calls the Agentic Development Lifecycle (ADLC).

DevOps.com: Are LLMs Equally Good (or Bad) at Building Secure Software?
With many software engineering teams moving from AI coding assistants into full agentic AI code generation and increasing the amount of code they produce exponentially, ensuring the security of that code must be a top priority. The study produces practical guidance for organizations that are getting on board the AI-assisted or agentic code development train.

TechRadar Pro: Beware the token trap: Why saving on inference might put your ADLC at risk
Token use can create unexpected, sizeable costs for organizations.

KBI Media: AI Coding Boom Raises Fresh Cybersecurity Risks for Business
AI enables faster development cycles and allows developers to focus on higher-value work. For many businesses, these efficiencies are becoming essential to remaining competitive. The challenge, therefore, is not whether to adopt AI, but how to do so responsibly. Businesses that invest in developer education, governance frameworks, AI observability and robust security controls will be better positioned to capture the benefits while limiting the associated risks.
.png)
In AI Today: AI's weakest link isn't the model but the software supply chain
The issue is no longer simply about protecting AI models themselves. Increasingly, attackers are focusing on the software ecosystem surrounding those models, including the development tools, middleware, open-source libraries, and automated deployment pipelines that organisations rely upon every day.

The AI Journal: Investigating global AI regulation: Who is winning, and where to from here?
As we will unpack together, there is a lot of movement around the world, with some collaboration between nations, but the path forward is far from uniform or clear, particularly in business environments where AI adoption is often mandated before holistic safeguarding measures are in place.

Cyber Daily: The industry reacts to OpenAI’s agent ‘accidentally’ hacking Hugging Face
According to one expert, AI guardrails are not designed as “security boundaries” but rather to influence behaviour – but what if that behaviour is hacking one of your industry partners?

SecurityBrief: Autonomous OpenAI agents breach Hugging Face in test
Cyber security experts have warned that the breach of Hugging Face infrastructure during an OpenAI security evaluation marks a turning point in the risks posed by autonomous AI agents. In the incident, AI models moved beyond a controlled test and carried out a live, multi-stage intrusion against the AI platform.

Technology Decisions: AI generated code found to produce predictable weaknesses
AI-generated code introduces an average of 15 confirmed vulnerabilities per codebase, research published by Secure Code Warrior indicates.

Forbes: OpenAI’s Hugging Face Breach Shows Frontier AI Guardrails Are Failing
.jpeg)
In AI Today: Secure Code Warrior research reveals AI-generated code introduces an average of 15 vulnerabilities per codebase
Secure Code Warrior research reveals AI-generated code introduces an average of 15 vulnerabilities per codebase.

VMBlog: Secure Code Warrior Research Reveals AI-Generated Code Introduces an Average of 15 Vulnerabilities Per Codebase
Secure Code Warrior introduced the SCW AI Trust Index, a living benchmark for AI coding security that grows with every new model, helping organizations understand and govern the security risks introduced by AI-generated code. Built on a methodology created with RMIT University, Australia, then extended by Secure Code Warrior, the research presents comprehensive benchmarks on how often leading LLMs produce insecure code, with material implications for every enterprise scaling AI-assisted development.

Dark Reading: Choose Wisely: AI-Generated Coding Risk Varies, A Lot
AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used.
.avif)
Secure Code Warrior Research Reveals AI-Generated Code Introduces an Average of 15 Vulnerabilities Per Codebase
New SCW AI Trust Index shows AI-generated coding risk is not random, it's predictable by model and framework, giving security leaders the data to safely scale AI-assisted development.

ITWire: Eight Industry Executives Comment on Worldwide AI Appreciation Day
The challenges with AI implementation, constant updates, and the race for industry dominance are coming thick and fast, and security professionals are among the most affected by its vast risk profile.

Cyber Daily: The industry speaks – part 3: AI Appreciation Day 2026
The Australian government has said AI is very much in the country’s future national interest – but where does it stand today? Here’s what the industry’s best and brightest have to say about artificial intelligence and its role in the modern enterprise.

ITWire: Agentic AI Era Demands Overhaul of Governance Frameworks
The emergence of agentic AI marks a structural shift in software development, introducing systems that not only accelerate production cycles but also perform autonomous reasoning and action beyond direct human control.

SecurityWeek: How to Conduct a Successful Audit of AI-Driven Software Development
As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production.

SD Times: Platform Engineering & Developer Experience: Making Engineers Faster Without Making Them Reckless: SD Times 100
This category has taken on new urgency in 2026 for a reason that’s specific to this moment: AI coding tools and agents are dramatically increasing how much code gets written and how often it needs to be deployed, tested, and provisioned for. Platform engineering is the layer that determines whether that increased velocity translates into shipped value or into chaos.

SD Times: AI-Assisted Development Multiplies Human Error: What’s Your AI Governance and Risk Management Strategy?
According to a recent report from Gartner, the rampant use of shadow AI and rogue automation is further fueling the proliferation of AI vulnerabilities. Gartner notes that 32% of IT workers using generative AI tools at work say they keep them hidden from cybersecurity teams. Combined with low-code/no-code platforms and vibe coding practices, the AI copilots are greatly expanding the enterprise attack surface.

Cybersecurity Tribe: What Separates Real AI Governance From Policy Theater
For this article, we asked a central question for security and risk leaders: "What differentiates a policy that genuinely mitigates enterprise risk from one that exists primarily to demonstrate that the organization has acknowledged AI risk?"

ISMG: AI Coding Tools Raise Hidden Security Risks
Secure Code Warrior's Pieter Danhieux on Managing AI-Driven Development Risks

ITWire: Decoding AI Coding “Personalities” Critical to Managing Development Risk
As generative AI cements its place in enterprise software development, a familiar discipline is taking on new urgency: risk management.

In AI Today: Secure Code Warrior launches Trust Agent: AI to enable safe, scalable AI-driven development
Secure Code Warrior have today announced SCW Trust Agent: AI, the industry’s first governance solution designed to make Artificial Intelligence (AI) influence in software development visible, attributable, and enforceable at the point of commit — enabling enterprises to scale AI coding tools with measurable control over software risk.

DEVOPSdigest: 25 Years of the Agile Manifesto, and the End of the Road for AppSec?
Even as we restructure the SDLC around the most impactful elements of the Agile methodology with careful, DevSecOps-centric security considerations, is this the end of the road for AppSec as we know it?

Cyber Defense Magazine: Global InfoSec Awards 2026 Secure Code Warrior Wins Outstanding Achievement in Cybersecurity Risk Management and Compliance Excellence
Global InfoSec Awards 2026 Secure Code Warrior Wins Outstanding Achievement in Cybersecurity Risk Management and Compliance Excellence

ITWire: Secure Code Warrior Launches Trust Agent: AI to Enable Safe, Scalable AI-Driven Development
New AI Software Governance solution makes AI-generated code visible at commit, enforces policy before production, and connects real development behavior to measurable risk reduction.

DevOps.com: Secure Code Warrior AI Agent Applies Policies to AI Generated Code
Secure Code Warrior (SCW) this week added an artificial intelligence (AI) agent that both identifies code generated by an AI coding tool and automatically applies the appropriate governance policies.

SecurityBrief UK: Secure Code Warrior unveils AI tool to govern code risk
Secure Code Warrior has launched SCW Trust Agent: AI, a software governance product that tracks the use of AI coding tools in development and links that usage to software risk when developers commit code.

2026 Globee® Awards for Cybersecurity: Secure Code Warrior Wins Gold Globee for Software Development Cybersecurity Solutions (Best Of)
2026 Globee® Awards for Cybersecurity: Secure Code Warrior Wins Gold Globee for Software Development Cybersecurity Solutions (Best Of)

DEVOPSdigest: Secure Code Warrior Releases Trust Agent
Secure Code Warrior announced SCW Trust Agent: AI, a governance solution designed to make AI influence in software development visible, attributable, and enforceable at the point of commit — enabling enterprises to scale AI coding tools with measurable control over software risk.

TalkDev: Secure Code Warrior Launches Trust Agent: AI to Enable Safe, Scalable AI-Driven Development
Secure Code Warrior today announced SCW Trust Agent: AI, the industry’s first governance solution designed to make AI influence in software development visible, attributable, and enforceable at the point of commit — enabling enterprises to scale AI coding tools with measurable control over software risk. For the first time, organizations can trace which AI models influenced specific commits, correlate that influence to vulnerability exposure, and take corrective action before insecure code reaches production.

Help Net Security: SCW Trust Agent: AI tracks AI influence in code to reduce software risk
Secure Code Warrior has announced SCW Trust Agent: AI, a governance solution designed to make AI influence in software development visible, attributable, and enforceable at the point of commit, enabling enterprises to scale AI coding tools with measurable control over software risk. Organizations can trace which AI models influenced specific commits, correlate that influence with vulnerability exposure, and take corrective action before insecure code reaches production.

Secure Code Warrior Launches Trust Agent: AI to Enable Safe, Scalable AI-Driven Development
New AI Software Governance solution makes AI-generated code visible at commit, enforces policy before production, and connects real development behavior to measurable risk reduction.

Security Boulevard: Threat Modeling with AI: A Developer-Driven Boon for Enterprise Security
Developers have long struggled to truly claim a seat at the table in traditional threat modeling programs, but with the right skills, they have the opportunity to wield AI responsibly to seriously cut risk and rework in their codebase.

The AI Journal: Understanding LLM Coding Personalities Is Now Key to Developer Risk Management
AI-generated code may be “made by machine”, but taking a cookie-cutter approach to securing that code would fall well short of mitigating the vulnerabilities LLMs can introduce. Organizations need to establish precise security reviews, with human developers anchoring the process to implement effective security controls while also managing the specific coding temperament of each LLM used. AI-generated code must undergo the same personalized risk assessments as code written by human developers.

SecurityBrief: The security challenges in AI-assisted software development
s artificial intelligence (AI) tools become more widely used in the software development process, their impact on security is becoming clearer. According to recent research, nearly 70% of organisations have discovered vulnerabilities caused by AI tools while one in five have experienced a serious incident as a result of those vulnerabilities.

KBI Media: Eliminating the Technical Debt Caused by AI-Assisted Software Development
According to research company Forrester[1], the tech debt for 75% of organisations will increase to a moderate or high level during this year, due to the rapid expansion of AI usage across a range of areas including software development.

Forbes: Security Self-Governance: Addressing The Regulatory Gap In AI-Assisted Software Development
While it’s early into 2026, we’re seeing new research that reveals the extent of cyber risks caused by artificial intelligence (AI)-assisted software development: Nearly 7 in 10 organizations have discovered vulnerabilities introduced by AI-generated code, and 1 in 5 have suffered a serious incident tied directly to the vulnerabilities.

ITWire: Why AI Is Dulling Cybersecurity’s Most Important Edge
Artificial intelligence (AI) has rapidly become indispensable to modern software development. From large language models that generate code on demand to agentic systems that automate entire workflows, AI tools promise dramatic gains in productivity and efficiency.

SecurityWeek: How to Eliminate the Technical Debt of Insecure AI-Assisted Software Development
Developers must view AI as a collaborator to be closely monitored, rather than an autonomous entity to be unleashed. Without such a mindset, crippling tech debt is inevitable.

CSO Online: Software developers: Prime cyber targets and a rising risk vector for CISOs
From technical compromise to AI-driven attacks, cyber criminals increasingly see software developers as prime targets, creating systemic risks CISOs must address.

SMBtech: Tech Industry Leaders React To Data Privacy Week 2026
It’s Online Privacy Week, a time of year where individuals and organisations are all reminded to check their digital footprint(s). Some might say that’s a futile gesture at a time where major social media and marketing players know absolutely everything about you and are cheerfully selling all that data to anyone who’ll buy it; when Microsoft is performing every trick in the book to get Windows users to put all their data in the cloud where it’s available for government agencies to snoop upon without letting you know; when a personal computer crisis means many people will be moved on to dumb-client computing landscape where everything from data storage to major processing tasks will be taking place in the cloud; and when people think that clicking ‘Accept’ on website pop-ups does something that meaningfully protects them. But, what do the experts say?

Security brief: AI heightens data privacy risks & reshapes digital trust
Technology and data specialists have warned that artificial intelligence and weak data governance are sharpening privacy risks for organisations, as businesses mark World Data Privacy Day.

ITWire: Data Privacy Week 2026
“Data Privacy Week" presents a great reminder for organisations to reassess their customer privacy policies and prioritise transparent data collection in their marketing strategies.

Dynamic Business: Data Protection Day 2026: Five experts on the privacy risks threatening your business
Five leading cybersecurity experts warn AI is being integrated faster than security policies can manage the risk, creating urgent privacy gaps for SMEs ahead of Data Protection Day on 28 January.

Information Security Buzz: OWASP Top 10 2025: New Enemies, Old Foes, and an Approach to Vulnerability Remediation That Must Evolve
The OWASP Foundation has been a guiding light for security professionals and enthusiasts alike, providing critical, practical advice on the most insidious software vulnerabilities across a plethora of categories and platforms. It has been the first major update since 2021 to the flagship OWASP Top 10 Web Vulnerabilities, and in that time, the industry has been rocked by a stampede of AI technology, tools, and code, each creating a dichotomy of security efficiency and risk for both cybersecurity and software engineering professionals.

DEVOPSdigest: What Software Developers Need to Know About Secure Coding and AI Red Flags
The bottom line: AI tools are not safe for enterprise use unless the code output is reviewed and implemented by a security-proficient human. 30% of security experts admit that they don't trust(link is external) the accuracy of code generated by AI itself. That's why security leaders must prioritize the education and upskilling of developer teams, to ensure they have the necessary skills and capabilities to mitigate AI-assisted code vulnerabilities as early as possible. This will lead to the cultivation of a "security first" team culture and safer AI use.

Stack Overflow: If you're a Zoomer, this one's for you: Everything Gen Z needs to know about the 2025 tech landscape
Here's the lowdown on all the tech from 2025 that you, dear Zoomer, should know about.

SC Media: CISOs can’t wait for the EU AI Act to take shape
CISOs hoping for the EU Artificial Intelligence Act to offer a solid framework for AI governance may be a little confused or disappointed by recent updates surrounding the implementation of AI restrictions.

SecurityBrief: Agentic AI double agents expose dangerous security gaps
An alleged nation-state attacker used Claude Code and a range of tools in the developer ecosystem to almost autonomously target specific companies with benign open-source hacking tools at scale. Of the more than thirty attacks, several were successful, and proved that AI agents could indeed execute large-scale, malicious tasks with little to no human intervention.

DEVOPSdigest: 2026 DevSecOps Predictions
DEVOPSdigest's Prediction Series continues with 2026 DevSecOps Predictions — Industry experts offer predictions on how DevSecOps will evolve and impact the industry in 2026.

ITWire: OWASP Names Latest Top 10 Application Vulnerabilities
The Open Worldwide Application Security Project (OWASP) has unveiled its latest top 10 vulnerabilities list, and it contains some surprising insights into important vulnerability classes.

Channel Insider: Cybersecurity Experts Predict AI, Nation-State Threats in 2026
Cybersecurity experts outline 2026 predictions, from AI-driven attacks and quantum risk to nation-state threats, OT security gaps, and automation pressures.

Security Journal UK: The rise of AI coding tools and the skills gap they expose
Pieter Danhieux, Co-founder and CEO of Secure Code Warrior warns that while AI coding tools promise speed and efficiency, they also introduce new risks.

ITWire: Predictions on State of AI in 2026
2026 is shaping up to be the year AI evolves from instrument to partner, transforming how we work, create and solve problems.

Fortune: AI coding tools exploded in 2025. The first security exploits show what could go wrong
While a breach of the tools hasn’t so far caused a wide-scale attack, there have been a few exploits and near-misses, and cyberthreat researchers have discovered critical vulnerabilities in several popular tools that make clear what could go horribly wrong.

SMBtech: Australian Tech Industry Leaders Make Their Predictions for 2026
It’s that time of year where the technology industry predictions start rolling-in. Here’s what you can (apparently) expect in 2026.

Technology Decisions: The importance of effective security when deploying AI tools
The concern is straightforward: development teams may place undue confidence in AI tools that are not equipped to interpret the nuanced context in which many security vulnerabilities arise. Large language models, for instance, can struggle to understand an application’s authentication or authorisation architecture, increasing the likelihood of missing critical safeguards.

ITWire: Five Steps to Improve the Security of AI Developed Code
Industry guidance on managing the risks of AI-generated code increasingly points to the same conclusion: effective safeguards rely on close collaboration between humans and machines, with developers remaining firmly in the loop.

SecurityBrief Australia: Agentic AI to transform APJ businesses & security by 2026
Agentic artificial intelligence (AI) is set to reshape the enterprise landscape in the Asia-Pacific and Japan (APJ) region in 2026, according to industry executives. Organisations are expected to embrace increasingly autonomous software agents, raising both productivity and new categories of risk across business domains.

SC Magazine UK: Why Firms Can’t Ignore Agentic AI
How big a threat does agentic AI pose to businesses currently? And what should security leaders be doing to address the risk?

VMBlog: Cybersecurity Predictions: What AI will (and won't) do for us in 2026
My co-founder and CTO, Matias Madou, Ph.D., and I consulted our crystal ball (or should that be our NVIDIA GPUs?), and this is what we believe 2026 has in store for us from an AI security perspective.

SD Times: Pumping the Brakes on Agentic AI Adoption in Software Development
An alleged nation-state attacker used Claude Code and a range of tools in the developer ecosystem, namely Model Context Protocol (MCP) systems, to almost autonomously target specific companies with benign open-source hacking tools at scale. Of the over thirty attacks, several were successful, and proved that AI agents could indeed execute large-scale, malicious tasks with little to no human intervention. Maybe it’s time we went a little slower, stopped to reflect on what is at stake here, and how best to defend ourselves.

AIthority: Building Secure and Ethical AI Practices in Software Development
AI is now a key piece of modern software development. More than four out of five developers use AI coding tools daily or weekly – with many relying on multiple tools in parallel. Teams must understand where automation ends, and where accountability begins.

SC Media: Secure Coding as Critical Thinking Instead of Vulnspotting – Matias Madou – ASW #357
Secure code should be grounded more in concepts like secure by default and secure by design than by “spot the vuln” thinking. Matias Madou shares his experience in secure coding training and the importance of teaching critical thinking. He also discusses why critical thinking is so closely related to threat modeling and how LLMs can be a tool for helping developers get beyond the superficial advice of, “Think like an attacker.”

Forbes: How CISOs Can Increase Their Influence In AI-Obsessed Boardrooms
Organizations are at an inflection point driven by the explosive adoption of AI, which promises significant changes in how businesses operate. That leaves CISOs on unsteady ground. As the gatekeepers of their organization’s data and access, they must ensure the security of the enterprise. However, the prospects of a headlong charge into wide-ranging, and possibly unchecked, use of AI could create a flood of security issues that many CISOs, under their current organizational structures, aren’t equipped to handle.

Security Boulevard: Security Degradation in AI-Generated Code: A Threat Vector CISOs Can’t Ignore
Security leaders and developers alike are already acutely aware that AI coding assistants and agentic agents can introduce vulnerabilities into the code they generate. A recent study unveiled another critical concern to keep them up at night — LLMs used for making iterative code improvements may introduce new vulnerabilities over time, even when explicitly asked to make code more secure.

Information Week: Make your own mandate: How CISOs can implement GenAI governance
Government bodies are trying to develop rules and regulations for safe AI use, but enterprises can't afford to wait. They need to address the risks now.

CFOtech Australia: How women can continue to foster fulfilling high-tech careers in the AI age
In the sphere of cybersecurity in general and application security in particular, human oversight remains an absolute 'must' to harness the benefits of AI productivity.

Tanium: Vibe coding may be unstoppable—but here’s how to rein in the risks
Like the meteoric rise of ChatGPT, vibe coding is all anybody can talk about this year. In fact, it just became a word in the dictionary. But beware the boom: These new AI coding tools offer speed, savings—and astounding vulnerabilities.

[PODCAST] Stack Overflow: AI code means more critical thinking, not less
Ryan is joined by Secure Code Warrior’s co-founder and CTO Matias Madou to discuss the implications of LLMs’ variability on code security, the future of developer training as AI coding assistants become more popular, and the importance of critical thinking—especially for junior developers—in the age of AI.

Cybersecurity Insiders: Use It or Lose It: Overreliance on AI Diminishes Critical Cybersecurity Thinking Skills
Software developers reap a host of benefits from making use of artificial intelligence assistants, whether in the form of Large Language Model (LLM) code creators or agentic AI agents. But recent reports, highlighted by a new study at MIT, warn that heavy use of AI can result in a loss of critical thinking skills among users.

Security Week: How Software Development Teams Can Securely and Ethically Deploy AI Tools
To deploy AI tools securely and ethically, teams must balance innovation with accountability—establishing strong governance, upskilling developers, and enforcing rigorous code reviews.

Dark Reading: AI Developed Code: 5 Critical Security Checkpoints for Human Oversight
To write secure code with LLMs developers must have the skills to use AI as a collaborative assistant rather than an autonomous tool, Madou argues.

Techstrong.tv: Secure Code Warrior in the Age of AI with Pieter Danhieux
Secure Code Warrior’s Chief Executive Officer, Chairman, and Co-Founder Pieter Danhieux explains his transition from offensive cybersecurity to promoting secure software development. Founded in 2015, Secure Code Warrior aims to help developers build secure code from the start, a practice Danhieux and host Alan Shimel agree is more effective than fixing vulnerabilities later. The two also discuss the impact of AI on software development, noting that while AI increases coding speed and accessibility for more people, the security of AI-generated code still lags. They emphasize the growing need for developers to master secure coding practices amidst these technological advancements.

SMBtech: Cybersecurity Awareness Month 2025: Australian Industry Reactions and Commentary
October is Australia’s Cybersecurity Awareness Month, the annual reminder for Aussies to stay vigilant online. This year’s theme, ‘Building our cyber safe culture’ once again highlights the importance of taking personal responsibility for staying secure in an increasingly digital world.

SecurityBrief: SMEs urged to cut data & boost cyber defences as attacks rise
Cybersecurity Awareness Month has brought renewed attention to the increasing risks faced by organisations of all sizes, with a particular focus on the growing threat to small and medium-sized enterprises (SMEs) in Australia and the UK.

ITBrief: Our biggest security risk isn’t our software - it’s our thinking
In the world of cybersecurity, we face creative and unconventional threats every day. But our greatest vulnerability isn't a flaw in our software, but a flaw in our collective thinking.

KBI Media: Overcoming the Security Risks of Using AI In Software Development
Development teams face relentless pressure to deliver, yet they must continue to prioritise building secure, high-quality software. Leaders play a crucial role in reinforcing how a Secure by Design approach, supported by observability, benchmarking, and ongoing education, directly enhances code quality. By embedding these practices, organisations can close governance gaps and fully capture the benefits of AI-driven productivity and efficiency, while reducing the risk of security flaws or costly rework during the SDLC.

In AI Today: The looming security challenges posed by Agentic AI
While agentic AI holds the promise of delivering significant business benefits, it also comes with significant caveats. The technology’s capabilities and autonomy present a potent enterprise threat vector beyond the realm of existing security concerns.

Help Net Security: Secure Code Warrior gives CISOs visibility into developer AI tool usage
Secure Code Warrior has launched a beta program to expand the AI capabilities of its Trust Agent product. The new offering provides CISOs with security traceability, visibility, and governance over developers’ use of AI coding tools.

Cyber Risk Leaders: Secure Code Warrior Launches AI Traceability
Secure Code Warrior have released a beta program for a major expansion of AI capabilities within its Trust Agent product. The upgrade, collectively referred to as Trust Agent: AI, leverages a combination of key signals, including AI coding tool usage, vulnerability data, code commit data and developer secure coding skills, to provide visibility into how AI development tools are impacting risk within the software development lifecycle (SDLC).

CSO Online: AI coding assistants amplify deeper cybersecurity risks
Although capable of reducing trivial mistakes, AI coding copilots leave enterprises at risk of increased insecure coding patterns, exposed secrets, and cloud misconfigurations, research reveals.

Secure Code Warrior Launches Industry-First AI Traceability to Enable Secure Developers and Supercharge Safe Productivity
New capabilities in SCW Trust Agent provide visibility and control over LLM usage for security leaders and CISOs.

ITOps Times: Secure Code Warrior announces new solution that provides visibility and governance for AI coding tools
Secure Code Warrior is trying to provide organizations with greater visibility and control over developers’ use of AI coding tools with the launch of its new solution, Trust Agent: AI.

DevOps Digest: Secure Code Warrior Introduces AI Traceability
Secure Code Warrior announced the launch of a beta program for a major expansion of AI capabilities within its Trust Agent product.

CyberWire: Business Briefing for 09.24.25
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Betanews: AI is an even playing field -- how secure by design can tip the scale [Q&A]
Vibe coding is currently all the rage, with more than 97 percent of respondents to a survey earlier this year reporting having used AI coding tools at work. The adoption of these tools only continues to grow but it comes with a catch, attackers are also employing the same techniques. We spoke to Pieter Danhieux, co-founder and CEO of Secure Code Warrior, to discuss how vibe coding is redefining the software development landscape, how malicious actors are also leveraging this technology and the need for organizations to implement secure by design strategies from the outset.

SD Times: Benchmarking AI-assisted developers (and their tools) for superior AI governance
If the tech stack lacks tools that oversee not only developer security proficiency, but also the trustworthiness of approved AI coding companions each developer uses, then it is likely that efforts to uplift the overall security program and the developers working within it will be short of the appropriate data insights to effect change.

ITWire: The Benefits and Risks of Using AI Tools in Software Development
The process of software development is undergoing a period of expedited change. Thanks to massive advances in artificial intelligence (AI) technology, projects can be completed more rapidly and by people with little or no prior experience.

LeadDev: Ethics are being forgotten as the AI race heats up
Is the tech industry capable of the change needed to curb ethical and environmental concerns?

Secure Code Warrior Expands Commitment to Secure by Design Best Practices with Free Secure Code Video Series for Developers
Launch of new 12-week video series on AI/LLM security empowers developers to safely adopt AI coding and mitigate emerging security risks.

CSO Online: When AI nukes your database: The dark side of vibe coding
As developers lean on Copilot and GhostWriter, experts warn of insecure defaults, hallucinated dependencies, and attacks that slip past traditional defenses.

The AI Journal: Resilience and Developer Risk Management: Two Pillars of Success in the Era of Secure by Design and AI Coding
Change is afoot in cybersecurity governance, and it couldn’t come at a more transformative time for security leaders worldwide. The White House issued a recent Executive Order (EO) designed to “reprioritize cybersecurity efforts to protect America”, and with it, reduce friction related to overzealous government oversight to focus on protecting critical digital assets and enhanced secure technology practices. Coupled with significant cuts to CISA, one could be forgiven for being apprehensive of the right approach going forward, especially in the wake of rapid AI technology progression and Secure by Design initiatives.

SecurityWeek: How to Close the AI Governance Gap in Software Development
Widespread adoption of AI coding tools accelerates development—but also introduces critical vulnerabilities that demand stronger governance and oversight.

teiss: When regulations aren’t enough
Pieter Danhieux at Secure Code Warrior explains why “Secure by Design” has emerged as mission critical for software development

Information Age: Vibe coding is a hot skill – and security experts are worried
GenAI tools are building insecure apps faster than ever.

CXFocus Magazine: Going above and beyond in 2026
Today’s customers are an exacting lot with little tolerance for suppliers that fail to meet their ever-increasing expectations. Almost 94 per cent of Australian consumers stopped purchasing from at least one company after a negative experience, according to CPM’s 2025 The State of Customer Experience in Australia Report.
.avif)
Which AI Model Codes Most Securely?
See how 16 leading AI models actually code, scored across 11 real-world frameworks and 1,760 codebases — the framework matters as much as the model.

Citizen AI by Secure Code Warrior
AI risk doesn't stop at engineering. Get the one-pager on Citizen AI — build AI literacy and safe habits across your whole workforce.

Understand how AI is transforming software development—and how security must evolve with it.
From AI autocomplete to autonomous agents—explore how software development is evolving and what it means for security, governance, and your team.

SCW named in new Agentic Coding Security category
Gartner named SCW twice in the 2026 Hype Cycle for Secure Software Engineering. Here's why it matters for AI-driven development.

SCW Learning Content for KnowBe4
Secure Code Warrior content available through KnowBe4 helps technical teams build secure coding and AI governance awareness through structured learning covering OWASP Top 10 risks, AI-assisted development, and modern secure coding practices.

Secure AI-driven development with KnowBe4 + Secure Code Warrior
Secure Code Warrior joins KnowBe4 to bring hands-on secure coding training into security awareness programs — covering OWASP, AI development, and 10 languages.
Trust Agent:AI - Secure and scale AI-Drive development
AI is writing code. Who’s governing it? With up to 50% of AI-generated code containing security weaknesses, managing AI risk is critical. Discover how SCW's Trust Agent: AI provides the real-time visibility, proactive governance, and targeted upskilling needed to scale AI-driven development securely.

The Power of OpenText Application Security + Secure Code Warrior
OpenText Application Security and Secure Code Warrior combine vulnerability detection with AI Software Governance and developer capability. Together, they help organizations reduce risk, strengthen secure coding practices, and confidently adopt AI-driven development.

Secure Code Warrior corporate overview
Secure Code Warrior is an AI Software Governance platform designed to enable organizations to safely adopt AI-driven development by bridging the gap between development velocity and enterprise security. The platform addresses the "Visibility Gap," where security teams often lack insights into shadow AI coding tools and the origins of production code.

Secure code training topics & content
Our industry-leading content is always evolving to fit the ever changing software development landscape with your role in mind. Topics covering everything from AI to XQuery Injection, offered for a variety of roles from Architects and Engineers to Product Managers and QA. Get a sneak peek of what our content catalog has to offer by topic and role.
Cyber Resilience Act (CRA) Aligned Learning Pathways
SCW supports Cyber Resilience Act (CRA) readiness with CRA-aligned Quests and conceptual learning collections that help development teams build the Secure by Design, SDLC, and secure coding skills aligned with the CRA’s secure development principles.
%20(1).avif)
OWASP Top 10 2025 eBook
Want to dominate the OWASP Top 10? Download the No-BS Guide to Defending Your Applications Against the OWASP Top 10:2025
Trust Agent: AI by Secure Code Warrior
This one-pager introduces SCW Trust Agent: AI, a new set of capabilities that provide deep observability and governance over AI coding tools. Learn how our solution uniquely correlates AI tool usage with developer skills to help you manage risk, optimize your SDLC, and ensure every line of AI-generated code is secure.

AI Coding Assistants: A Guide to Security-Safe Navigation for the Next Generation of Developers
Large language models deliver irresistible advantages in speed and productivity, but they also introduce undeniable risks to the enterprise. Traditional security guardrails aren’t enough to control the deluge. Developers require precise, verified security skills to identify and prevent security flaws at the outset of the software development lifecycle.
Secure by Design: Defining Best Practices, Enabling Developers and Benchmarking Preventative Security Outcomes
In this research paper, Secure Code Warrior co-founders, Pieter Danhieux and Dr. Matias Madou, Ph.D., along with expert contributors, Chris Inglis, Former US National Cyber Director (now Strategic Advisor to Paladin Capital Group), and Devin Lynch, Senior Director, Paladin Global Institute, will reveal key findings from over twenty in-depth interviews with enterprise security leaders including CISOs, a VP of Application Security, and software security professionals.

Turn Awareness Into Action This Cyber Awareness Month
This October, turn awareness into action. Make Cyber Awareness Month memorable for your developers with a high-impact, high-participation experience—led by Secure Code Warrior's Professional Services team.

Professional Services - Accelerate with expertise
Secure Code Warrior’s Program Strategy Services (PSS) team helps you build, enhance, and optimize your secure coding program. Whether you're starting fresh or refining your approach, our experts provide tailored guidance.

Quests: Industry leading learning to keep developers ahead of the game mitigating risk.
Quests is a learning platform that helps developers mitigate software security risks by enhancing their secure coding skills. With curated learning paths, hands-on challenges, and interactive activities, it empowers developers to identify and prevent vulnerabilities.
Benchmarking Security Skills: Streamlining Secure-by-Design in the Enterprise
The Secure-by-Design movement is the future of secure software development. Learn about the key elements companies need to keep in mind when they think about a Secure-by-Design initiative.
Trust Agent in action
SCW Trust Agent gives you the tools you need to deliver secure code faster, ensuring developers have the knowledge and skills to implement security best practices in the specific programming language of their code commits.
.jpeg)
Trust Agent by Secure Code Warrior
Are you confident that every line of code committed is backed by a developer with the necessary secure coding skills? Many organizations face this critical gap, leading to preventable vulnerabilities and reduced development velocity. SCW Trust Agent offers unparalleled visibility across your code repositories, analyzing commits directly against developer security proficiency. With policy gates, Trust Agent enables you to apply governance at the commit level, with policies to ensure code contributors have the secure code knowledge you require for your business-critical applications. Download our one-pager today to learn how SCW Trust Agent can help you strengthen your security posture, optimize your development lifecycle, and significantly reduce vulnerabilities.
SCW Trust Score - The best way to build, measure, and optimize your security program
Learn more about Secure Code Warrior Trust Score, the best way to build, measure and optimize your security program.
Trust Score by Secure Code Warrior
Discover SCW Trust Score, an industry-first benchmark to help measure your security program's effectiveness. Benchmark against industry peers, optimize your security posture, and drive data-driven decisions for enhanced software security.
Preparing for PCI-DSS 4.0 Compliance
Evaluate your software security infrastructure to support PCI-DSS requirements
The ultimate guide to security trends in financial services
Financial services institutions face an array of challenges that hinge on their ability to make efficient, effective use of technology in a fast-evolving financial world. Organizations are operating in a time of rapid changes—both internally and across the industry—in a highly competitive, cloud-based business environment. In pursuing their ongoing digital transformations, for example, organizations are working to get around the organizational friction that hinders investments into new technologies, such as artificial intelligence, that could accelerate payment processes and other procedures.

Predicts 2024: Generative AI is reshaping software engineering
Explore how generative AI is revolutionizing software development across the SDLC, as highlighted in Gartner's report, advising Application Security leaders on the importance of scrutinizing AI-generated software.
PCI DSS 4.0 Unraveled
This guide offers practical strategies to engage development teams in PCI DSS 4.0 compliance. It outlines the modern developer's requirements for compliance, strategies for security professionals and development managers to collaborate on developer-focused security programs, and step-by-step advice on effective training initiatives to mitigate vulnerabilities permanently.

Developer security maturity quiz
Secure Code Warrior outlines three security maturity stages for developer teams: defining, adopting, and scaling. How security-savvy are your developers? Take our quiz to find out.
Script Testing please ignore
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
ROI of Secure Code Learning
Explore the long-term ROI of secure coding education. Learn how investing in agile, proactive learning strategies enhances security and offers cost-effective protection against today's cyber threats.
Why developers need security skills to effectively navigate AI development tools
The promise of artificial intelligence writing complex code at the touch of a button is intriguing, but the reality is that AI will need a lot of help from human developers to craft truly secure and reliable code.
Top 10 predictions for 2024
Check out what SCW experts are predicting in the world of cybersecurity and software security in 2024.
Agile learning platforms: ROI of developer-driven security
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Forge your fortress: Six essential pillars of developer enablement in software security
In this white paper, security expert and Secure Code Warrior CTO & Co-Founder Matias Madou, Ph.D. will discuss:The six pillars you need to roll out effective security education and enablement for your development cohort. Lessons learned from ten executives implementing security programs at the enterprise level, and common pitfalls to avoid on your road to success.
The Agile Learning Platform
Empower your development team with Secure Code Warrior, the agile learning platform designed to tackle the evolving challenges of application security. Stay ahead in the battle against security breaches and regulatory complexities with our industry-leading, up-to-date content, ensuring a proactive and engaging approach to secure code education.

OWASP Top 10 API 2023: A tactical guide for smart developers
Explore the Latest in API Security. Dive into our 2023 OWASP Top 10 guide. Elevate your coding skills, tackle vulnerabilities, and stay agile in the ever-evolving world of API development. Download now for an insightful journey!

The secure code learning blueprint
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Your handbook to developer-driven security and agile learning
Start shifting left with developer-driven security. This handbook will show you how to engage with developers to upskill and increase their security knowledge, as well as how to go about measuring impact to write more secure code.

Software is your colleague: A new perspective to strengthen access control and API security
APIs act like flawed humans; is treating them as such the key to better cybersecurity?

The secure code training blueprint
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
The developer security maturity matrix
Building security maturity in development teams can be approached in stages. Based on our experience with 400+ organizations, we've identified common practices and traits in three different stages of security maturity - defining, adopting, and scaling.
The importance of security maturity in developer teams
By assessing and understanding a development team’s security maturity, organizations can formulate a plan with the right stakeholders, process, and technology to build and support the necessary skills and capabilities.
Development Team Security Maturity
Security maturity in development teams should be a continuous cycle of improvement with realistic goals along the way. As development teams increase their security maturity, they reduce the amount of rework and minimize risk, while also allowing automation to help create efficiency in the SDLC.

Report: The state of developer driven security 2022
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Whitepaper: The challenges (and opportunities) to improve software security
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Brief: A cohesive approach to developer-led security
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Security and privacy at Secure Code Warrior
Secure Code Warrior is committed to safeguarding our information assets, and those of our customers, against misuse, abuse or compromise. We adopt and foster a risk-based approach to managing information security, with the goal of consistently implementing appropriate risk management and mitigation measures to address the threat landscape posed to the security of the platform, customer data and information. As Secure Code Warrior continues to succeed as a major player providing services to our customers, we will continue to build security capabilities as part of our security and privacy programs. Read our whitepaper for more information.
.png)
Shift left (and achieve compliance) with repeatable secure coding skills
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
.png)
Defining secure code
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Why you need more than scanning tools to create secure code
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Your guide to defense against the dark art of zero-day attacks
Zero-day attacks can be the stuff of nightmares, but when an organization commits to using all available tools in their security arsenal towards a preventative strategy, security professionals can sleep a little easier.
A plan to upskill and engage your developers
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
The preventative, developer-driven approach to software security
Learn more about how security-aware developers represent a vast and largely untapped resource that can support cyber defenses by consistently standing against modern threats.

Security and Privacy Whitepaper
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Convince Your CISO/CTO Kit (for starting a demo)
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

OWASP Top 10 API: Strategies for Smart Developers
Download the practical guide to defeating common API security baddies in your code.
How to unify your security and development teams to stand together against security risk
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
How AppSec can reduce vulnerabilities and achieve compliance - leaving them free to tackle larger beasts
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Buyers Checklist: Secure Development Learning Platforms
Buyer’s Checklist: Secure Development Learning Platforms is aimed at decision makers and technology buyers looking to evaluate secure development learning platforms.

Shared Assessments SIG Lite Questionnaire
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

SCW Pen Test Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

SCW Cyber Insurance Certificate
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Shifting from reaction to prevention: The changing face of software security 2021 - Whitepaper
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Cybersecurity Executive Order: A deliberate approach to improve software security with developer skills
While this Executive Order for touches on many aspects of functional cybersecurity, it specifically outlines, for the first time, the impact of developers, and the need for them to have verified security skills and awareness.

FSQS-NL Certificate
Secure Code Warrior is now FSQS-NL registered. This registration is an important milestone in our continuous efforts to being compliant with regulations within the financial industry.

Platform Architecture Diagram
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Information Security Policy
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

CAIQ Questionnaire
Secure Code Warrior has completed a publicly available Consensus Assessment Initiative Questionnaire (CAIQ), based on the results of our due diligence self-assessment.
The DevSecOps Super Bowl: How security champions can support your team to victory against late-stage vulnerabilities
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Executive Roundtable Whitepaper - Visma & Blue Prism
How has 2020 changed the way we look at software security, an executive roundtable with Visma.

The women of mimmit koodaa movement dive into secure coding
Mimmit Koodaa (women who code in Finland) tell us about their secure coding experiences.

Teams in a global financial institution go head-to-head in secure coding contest.
See how a global financial organization promoted the importance of securing their banking applications across the world. With fun interactive tournaments.
Missions - Experience the impact of poor code in real-world simulations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Courses - Build Secure Coding Skills and Competency
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
A Step-By-Step Guide to Tournaments
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Your Battle Plan to Defeat the OWASP Top 10
The ten most common security vulnerabilities don’t stand a chance against secure development superheroes like you. This free eBook is your ultimate field guide to understanding each infamous entry in the OWASP Top 10 2021, gaining insight into how each bug operates.
Triumph with OWASP and Secure Code Warrior Tournaments - Whitepaper
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Tournaments - Build organizational awareness and developer engagement, making secure coding top of mind
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

The Infamous 8: Infrastructure as Code Vulnerabilities to Find and Fix
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
The Five-Step Road to DevSecOps Success: How AppSec Professionals Can Thrive in Their Dream Team
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

The Fastest and Easiest Way to Improve Your Software Security Program
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
The Creative CISO's Guide to Transforming Their Security Program
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Take the pain out of PCI-DSS Compliance Whitepaper
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Introduction to Secure Code Warrior
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Empowering developers to write secure code
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Empower developers to be the first line of defense and grow your organization's security posture
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Assessments - Benchmark the secure coding skills of your developers, and build your security posture.
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
AppSec Checklist
Download the AppSec checklist and see if you’re in need of a security lifeline.

6 Critical Steps Before You Roll Out a Security Uplift Program
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

2019 AppSec Trend Report
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
%25252520(1).png)






