Conference
|
Nov 5, 2026
OWASP 글로벌 AppSec 미국
Register
Conference
|
Oct 29, 2026
OWASP LASCON
Register
Conference
|
Sep 24, 2026
가트너 보안 & 위험 관리 서밋 2026
Register
Blog
|
Aug 24, 2026
Enabler 7: Developer Recognition
read more
Blog
|
Jul 29, 2026
Named in the Gartner® Hype Cycle™ for Application Security 2026
read more
Blog
|
Jul 21, 2026
Are you a CISO or Engineering Leader worried about the Security and Cost of LLM code generation?
read more
Case Study
|
Jan 6, 2026
Kamer van Koophandel Sets the Standard for Developer-Driven Security at Scale
read more
Case Study
|
Oct 8, 2025
Going for Gold: Soaring Secure Code Standards at Paysafe
read more
Case Study
|
Aug 15, 2024
DigitalOcean Decreases Security Debt with Secure Code Warrior
read more
News Article
|
Aug 27, 2026
Forbes: A New Frontier: NSA Proposes “Security By Design” Considerations For AI Enablement
read more
Media Release
|
Aug 21, 2026
Techpartner.news: Secure Code Warrior introduces framework to govern AI use in software development
read more
News Article
|
Aug 19, 2026
DevOps.com: Are LLMs Equally Good (or Bad) at Building Secure Software?
read more
eBook
|
Jul 21, 2026
Which AI Model Codes Most Securely?
read more
One Pager
|
Jul 7, 2026
Citizen AI by Secure Code Warrior
read more
Whitepaper
|
Jun 23, 2026
Understand how AI is transforming software development—and how security must evolve with it.
read more
Resource library

Insights from experts shaping secure development

Access expert content on secure coding, AI governance, and software risk management.

Filters
clear
Showing 0 of 100
By Category
By Role
No items found.
By Product
No items found.
Button Text
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Webinar
events-webinars
January 11, 2024
March 20, 2023

사이버 회복력 법안(Cyber Resilience Act) 대비에 SBOM이 중요한 이유

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Event ended
This is some text inside of a div block.
No items found.
No items found.
Webinar
events-webinars
January 11, 2024
March 28, 2022

대형 의료 제공업체가 개발자 중심 접근 방식으로 보안 문화를 혁신한 방법

Contrast Security의 공동 설립자 Jeff Williams와 Secure Code Warrior의 Matias Madou가 안내하는 의료 기관의 보안 문화 혁신 사례를 들어보세요.

Event ended
This is some text inside of a div block.
No items found.
No items found.
Webinar
events-webinars
January 11, 2024
July 6, 2020

임베디드 시스템과 팀 역량 강화

사물 인터넷, 생산 시스템의 자동 제어 및 관리는 임베디드 시스템 개발을 촉진하는 몇 가지 요소에 불과합니다. 임베디드 소프트웨어의 보안 취약점이 미치는 영향과 이를 완화하는 방법은 무엇일까요?

Event ended
This is some text inside of a div block.
No items found.
No items found.
Webinar
events-webinars
January 11, 2024
January 18, 2021

컴플라이언스를 넘어: 흥미진진한 애플리케이션 보안을 제공하는 팁

개발 팀이 애플리케이션 보안 교육을 단순한 체크박스 채우기로 취급하나요? 개발자가 스스로 찾아오는 교육 프로그램을 만드는 실용적인 팁을 확인하세요!

Event ended
This is some text inside of a div block.
No items found.
No items found.
Webinar
events-webinars
January 11, 2024
October 8, 2020

훌륭한 SOC 2 보고서 달성을 위한 모범 사례

SOC 보고서 프로젝트에 직면하면 때로는 매우 막막하게 느껴질 수 있습니다. 업계 전문가들과 함께 SOC 2 보고서 획득을 위한 핵심 팁을 나눕니다.

Event ended
This is some text inside of a div block.
No items found.
No items found.
Webinar
events-webinars
January 11, 2024
March 17, 2021

2021 HMG Live! 실리콘밸리 CISO 최고경영자 서밋

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Event ended
This is some text inside of a div block.
No items found.
No items found.
Webinar
events-webinars
January 11, 2024
July 14, 2021

웨비나: DevOps에서 DevSecOps로: 처음부터 품질과 보안이 확보된 개발 제공

전문가들이 SDLC에 보안 교육 및 애플리케이션 보안을 구현하기 위한 핵심 고려 사항, 게이미피케이션 학습을 통해 개발자를 참여시키는 방법, 다운타임이나 비용 부담 없이 보안 테스트를 통합하는 방법을 설명합니다.

Event ended
This is some text inside of a div block.
No items found.
No items found.
Webinar
events-webinars
January 11, 2024
November 8, 2021

코스 내 튜토리얼(Walkthroughs) 심층 탐구

새로운 Walkthrough & Missions 몰입형 실습 교육 활동이 개발자의 참여를 유도하고 입증된 단계별 학습 방식으로 개발자 역량을 단계적으로 향상시키는 방법을 알아보세요.

Event ended
This is some text inside of a div block.
No items found.
No items found.
Webinar
events-webinars
January 11, 2024
March 23, 2021

업스킬링, AppSec 보안 격차를 줄이기 위한 마지막 열쇠

Zip의 보안 총괄 Peter Robinson과 Secure Code Warrior의 공동 설립자이자 AppSec 트레이너인 Jaap Singh으로부터 보안 격차를 줄이기 위해 임직원의 사이버 보안 기술 향상이 필수적인 이유에 대한 심도 있는 논의를 들어보세요.

Event ended
This is some text inside of a div block.
No items found.
No items found.
Webinar
events-webinars
January 11, 2024
March 20, 2023

개발자 주도 보안의 ROI

테크 스택이나 추가 교육 프로그램에 투자할 때 누구나 투자 대비 좋은 수익률(ROI)을 원하지만, 보안에 있어서는 단순한 ROI 계산을 넘어 장기적인 안목으로 접근해야 합니다. 개발자 주도 보안 투자가 비싼 보안 침해 비용과 생산성 손실을 줄이는 방법과 비용 효율적인 전략을 배우세요.

Watch on demand
This is some text inside of a div block.
No items found.
No items found.
Webinar
events-webinars
January 11, 2024
August 3, 2023

시큐리티 챔피언으로 가는 길

Workday가 개발자 역량 강화를 위해 애자일 보안 학습을 활용한 방법입니다.

Watch on demand
This is some text inside of a div block.
No items found.
No items found.
Webinar
events-webinars
May 24, 2023
May 23, 2023

사람, 프로세스 및 기술

Vis Chirravuri와의 대담을 통해 시큐어 코드 학습 프로그램을 위해 사람, 프로세스, 기술적 접근 방식을 개발한 노하우를 직접 들어보세요.

Watch on demand
This is some text inside of a div block.
No items found.
No items found.
Webinar
events-webinars
April 18, 2023
April 17, 2023

Secure Code Warrior 사용자 그룹 APAC

개발자 중심 보안 프로그램을 관리하는 팁과 노하우를 공유하고 제품 팀에 질문을 던져보세요!

Watch on demand
This is some text inside of a div block.
No items found.
No items found.
Blog
blog-posts
January 25, 2021
January 25, 2021

How to catch and fix a Guice dependency injection issue using Sensei

An example scenario for a misconfiguration of Guice, which may lead to a NullPointerException being reported at runtime during testing.

Learn More
No items found.
No items found.
January 25, 2021
Blog
blog-posts
January 5, 2021
January 5, 2021

2021년 사이버 보안 예측: 은하계 전투가 시작되다

우리는 2021년이 사이버 위협으로부터 우리 은하계를 안전하게 지키는 새로운 종류의 우주 경쟁을 주류로 끌어올리는 해가 될 것으로 예측하고 있습니다.

Learn More
No items found.
No items found.
January 5, 2021
Blog
blog-posts
December 22, 2020
December 22, 2020

코더즈 컨커 시큐리티 OWASP 탑 10 API 시리즈 - 부적절한 자산 관리

이 취약점은 사람의 문제나 관리상의 문제로, 이전 API가 보다 안전한 최신 버전으로 교체된 후에도 오랫동안 그대로 유지될 수 있습니다.

Learn More
No items found.
No items found.
December 22, 2020
Blog
blog-posts
December 21, 2020
December 21, 2020

JUnit 5의 메서드 및 클래스 가시성 수정

Sensei가 더 이상 사용되지 않는 패턴을 식별하고 향후 사용할 수정 사항을 알려줌으로써 마이그레이션을 어떻게 지원할 수 있는지 알아보십시오.

Learn More
No items found.
No items found.
December 21, 2020
Blog
blog-posts
December 15, 2020
December 15, 2020

내 펜테스터, 내 적?개발자가 펜테스팅 및 정적 분석 결과에 대해 실제로 어떻게 생각하는지 밝힙니다.

침투 테스트와 정적 분석 스캐닝 도구 (SAST라고도 함) 는 보안 위험을 완화하기 위한 전체 프로세스의 일부에 불과합니다. 물론 핫픽스를 위해 코드가 우리에게 돌아오기 전까지는 우리가 하는 일과는 별개로 작동합니다!

Learn More
No items found.
No items found.
December 15, 2020
Blog
blog-posts
December 14, 2020
December 14, 2020

Automatically Adding a Private Constructor with Sensei

Learn how Sensei can identify a coding pattern, and automatically generate a private constructor to make it impossible to instantiate the class.

Learn More
No items found.
No items found.
December 14, 2020
Blog
blog-posts
December 9, 2020
December 9, 2020

업무의 미래는 유연하며 사이버 보안에 적합합니다.

불편함이 새로운 업무 방식을 모르거나, 약간의 불신에서 비롯된 것이든, 아니면 원격 근무를 믿지 않는 데서 오는 것이든, 원격 근무에 저항하는 회사는 최고의 인재를 유치하고, 전 세계에 진출하고, 솔직히 말해서 시대에 발맞추어 나아가는 측면에서 뒤처지는 경향이 있다는 것을 알게 되었습니다.

Learn More
No items found.
No items found.
December 9, 2020
Blog
blog-posts
December 7, 2020
December 7, 2020

Improving A Personal Programming Process Using Sensei

Learn how to use code reviews on pull requests to help enforce coding styles. And shorten the feedback cycle when pair programming with a more experienced programmer.

Learn More
No items found.
No items found.
December 7, 2020
Blog
blog-posts
November 30, 2020
November 30, 2020

Migrating to a Logger with Sensei

A quick example of creating a recipe to migrate from System.out.println to using a Java Logger.

Learn More
No items found.
No items found.
November 30, 2020
Blog
blog-posts
November 25, 2020
November 25, 2020

코더 컨커 시큐리티 OWASP Top 10 API 시리즈 - 로깅 및 모니터링이 충분하지 않음

불충분한 로깅 및 모니터링 결함은 대부분 실패한 인증 시도, 액세스 거부 및 입력 검증 오류를 기록하는 것과 관련된 사이버 보안 계획의 실패로 인해 발생합니다.

Learn More
No items found.
No items found.
November 25, 2020
Blog
blog-posts
November 23, 2020
November 23, 2020

팀 내에서 쿡북 공유

Sensei 쿡북을 공유하고 팀원 모두가 코드 품질과 생산성을 향상하도록 돕는 방법을 알아보세요.

Learn More
No items found.
No items found.
November 23, 2020
Blog
blog-posts
November 11, 2020
November 11, 2020

미션 소개: 개발자 중심 보안 교육의 다음 단계

시큐어 코드 워리어 플랫폼의 새로운 기능인 미션을 발표하게 되어 매우 기쁩니다.완전히 새로워진 이 챌린지 카테고리는 개발자 중심의 보안 교육의 다음 단계로, 사용자가 보안 지식을 회상하는 것에서 벗어나 실제 시뮬레이션 환경에 적용할 수 있도록 합니다.

Learn More
No items found.
No items found.
November 11, 2020
Blog
blog-posts
November 11, 2020
November 11, 2020

코더 컨커 시큐리티 OWASP Top 10 API 시리즈 - 보안 기능 비활성화/디버그 기능 활성화/부적절한 권한

API에서 조금 더 널리 퍼져 있을 가능성이 높지만 공격자는 네트워크 어디서나 패치가 적용되지 않은 결함이나 보호되지 않은 파일 또는 디렉터리를 찾으려고 시도하는 경우가 많습니다.디버깅이 활성화되거나 보안 기능이 비활성화된 API를 발견하면 악의적인 작업이 조금 더 쉬워집니다.

Learn More
No items found.
No items found.
November 11, 2020
Blog
blog-posts
November 9, 2020
November 9, 2020

Using Documentation Links with Sensei

Learn how Sensei can help onboard developers and adopt new libraries.

Learn More
No items found.
No items found.
November 9, 2020
Blog
blog-posts
October 31, 2020
October 31, 2020

Sensei Product Update - September 2020

Learn all about the latest updates to Sensei.

Learn More
No items found.
No items found.
October 31, 2020
Blog
blog-posts
October 26, 2020
October 26, 2020

재작성 작업을 사용하여 주석에 매개변수 추가

Sensei를 사용하여 문제가 있는 코드 패턴을 매칭한 다음 주석 매칭 예제를 통해 합의된 구현으로 수정하는 방법을 알아보세요.

Learn More
No items found.
No items found.
October 26, 2020
Blog
blog-posts
October 21, 2020
October 21, 2020

코더 컨커 시큐리티 OWASP 상위 10 API 시리즈 - 대량 할당

대량 할당 취약점은 많은 최신 프레임워크가 개발자에게 클라이언트의 입력을 코드 변수 및 내부 개체에 자동으로 바인딩하는 함수를 사용하도록 권장한 결과 발생했습니다.

Learn More
No items found.
No items found.
October 21, 2020
Blog
blog-posts
October 20, 2020
October 20, 2020

호주 정부가 국가 사이버 보안 복원력을 구축하고 위협에 맞서 설 수 있는 방법

사이버 보안에 대해 진지하게 생각하려는 호주 정부의 노력을 보면 사이버 보안이 국가 차원에서 주요 위험 영역으로 확인되었다는 것이 분명하지만, 그들의 전략이 충분히 도달하고 있습니까?

Learn More
No items found.
No items found.
October 20, 2020
Blog
blog-posts
October 8, 2020
October 8, 2020

What is Sensei?

The Sensei plugin provides an easy way to find specific code patterns in your source code, and then apply rewrite rules to amend the matching code. All within the Intellij IDE, and in real-time.

Learn More
No items found.
No items found.
October 8, 2020
Blog
blog-posts
October 8, 2020
October 8, 2020

SSDLC의 모든 단계에서 보안 코딩 기술 습득

시큐어 코드 워리어는 GitHub 코드 스캐닝에 컨텍스트 학습을 제공하는 GitHub Action을 구축했습니다.즉, 개발자는 Snyk Container Action과 같은 타사 작업을 사용하여 취약점을 찾은 다음 CWE에 특화된 초관련성 학습으로 결과를 확장할 수 있습니다.

Learn More
No items found.
No items found.
October 8, 2020
Blog
blog-posts
October 7, 2020
October 7, 2020

코더 컨커 시큐리티 OWASP 상위 10 API 시리즈 - 누락된 수준 기능 액세스 제어

누락된 수준 수준 액세스 제어 취약성으로 인해 사용자는 기능을 제한하거나 보호해야 하는 리소스에 액세스할 수 있습니다.

Learn More
No items found.
No items found.
October 7, 2020
Blog
blog-posts
October 1, 2020
October 1, 2020

국가 사이버 보안 인식의 달: 단순한 피싱 공격 그 이상

모든 조직은 사이버 보안 인식의 달을 활용하여 보안 인식을 새롭게 할 수 있습니다. 올해에는 코딩 커뮤니티를 위한 새로운 무료 앱도 출시할 예정입니다!

Learn More
No items found.
No items found.
October 1, 2020
Blog
blog-posts
September 30, 2020
September 30, 2020

코더 컨커 시큐리티 OWASP Top 10 API 시리즈 - 리소스 부족 및 속도 제한

이 취약점은 너무 많은 요청이 동시에 들어오고 API에 이러한 요청을 처리하기에 충분한 컴퓨팅 리소스가 없을 때 발생합니다.그러면 API를 사용할 수 없게 되거나 새 요청에 응답하지 않을 수 있습니다.

Learn More
No items found.
No items found.
September 30, 2020
Blog
blog-posts
September 28, 2020
September 28, 2020

ClickShare 취약점이 패치되었을 수도 있지만 훨씬 더 큰 문제를 숨기고 있습니다.

보안 수정 사항을 다시 개발 프로세스로 전환하는 것은 쉬운 일이 아니지만 프레젠테이션 도구와 같이 겉보기에 단순해 보이는 장치조차도 놀라울 정도로 복잡하고 다른 모든 것과 네트워크로 연결되어 있는 오늘날의 세계에서는 필요합니다.

Learn More
No items found.
No items found.
September 28, 2020
Blog
blog-posts
September 23, 2020
September 23, 2020

코더즈 컨커 시큐리티 OWASP 상위 10 API 시리즈 - 과도한 데이터 노출

이 취약점의 실제 메커니즘은 다른 취약점과 유사하지만, 이 경우 과도한 데이터 노출은 법적으로 보호되거나 매우 민감한 데이터와 관련된 것으로 정의됩니다.

Learn More
No items found.
No items found.
September 23, 2020
Blog
blog-posts
September 16, 2020
September 16, 2020

코더스 컨커 시큐리티 OWASP 탑 10 API 시리즈 - 깨진 인증

인증은 애플리케이션은 물론 잠재적으로 네트워크의 나머지 부분에 대한 게이트웨이 역할을 하는 경우가 많기 때문에 공격자의 공격 대상이 됩니다.인증 프로세스가 손상되거나 취약한 경우 공격자가 해당 취약점을 발견하고 악용할 가능성이 높습니다.

Learn More
No items found.
No items found.
September 16, 2020
Blog
blog-posts
September 10, 2020
September 10, 2020

전문가 인터뷰: 오스카 퀸타스와 함께하는 코드형 인프라

저희 전문가 중 한 명인 오스카 퀸타스 (Oscar Quintas) 에게 집중 조명하고 싶습니다.그는 제품 콘텐츠 팀의 일원으로 선임 보안 연구원으로 일하고 있습니다.그는 IaC (Infrastructure as Code) 에 관한 모든 것을 다루는 당사의 상주 마법사이기도 합니다.

Learn More
No items found.
No items found.
September 10, 2020
Blog
blog-posts
September 9, 2020
September 9, 2020

코더 컨커 시큐리티 OWASP 상위 10 API 시리즈 - 브로큰 오브젝트 레벨 인증

일반적으로 사용자의 입력을 사용하여 데이터 소스에 액세스하는 모든 함수에 대해 개체 수준 권한 부여 검사를 포함해야 하며, 이렇게 하지 않으면 큰 위험이 따릅니다.

Learn More
No items found.
No items found.
September 9, 2020
Blog
blog-posts
August 25, 2020
August 25, 2020

Death by Doki: 심각한 피해를 입은 새로운 Docker 취약점 (및 이에 대한 조치)

사이버 공격은 점점 더 빈번해지고 있으며 Linux 기반 인프라에 영향을 미치는 위협은 점점 더 흔해지고 있습니다. 최종 목표는 클라우드에 저장된 민감한 데이터의 전리품을 해킹할 수 있는 기회를 제공하는 것입니다.

Learn More
No items found.
No items found.
August 25, 2020
Blog
blog-posts
August 3, 2020
August 3, 2020

귀사는 정말 DevSec을 사용할 준비가 되어 있습니까?테스트해 보세요.

조직을 염두에 두고 역할의 맥락에서 이러한 질문에 대해 생각해 보십시오.DevSec 테스트에 적용하면 어떤 결과가 나올까요?

Learn More
No items found.
No items found.
August 3, 2020
Blog
blog-posts
July 20, 2020
July 20, 2020

먼저 공격하고 강력하게 공격하세요: 엄선된 보안 코딩 과정이 사이버 위협에 아무런 영향을 미치지 않는 이유

개발자가 숙련도를 입증하는 데 필요한 정확한 모듈이 포함된 엄선된 과정은 강력한 영향을 미치며, 일상 업무의 보안 모범 사례와 관련하여 처음부터 시작할 수 있도록 합니다.

Learn More
No items found.
No items found.
July 20, 2020
Blog
blog-posts
July 15, 2020
July 15, 2020

개발자가 보안 의식을 가지고 코딩하기를 원하시나요?교육을 개발자에게 제공하세요.

우리는 이미 근무 시간이 너무 많다는 것을 알고 있습니다. 그렇다면 개발자들이 강의실로 달려가거나 컨텍스트 전환을 통해 정적 이론 기반 교육에 액세스하기 위해 5단계를 거치면 어떤 인센티브가 필요할까요?

Learn More
No items found.
No items found.
July 15, 2020
Blog
blog-posts
July 8, 2020
July 8, 2020

COVID-19 접촉자 추적: 보안 코딩 상황은 어떻습니까?

접촉자 추적 앱의 기본 개념은 타당합니다.이 기술이 제대로 작동하면 핫스팟을 신속하게 찾아내고 포괄적인 검사를 실시할 수 있습니다. 이 두 가지 모두 전염성 바이러스 확산을 막는 데 필수적인 요소입니다.

Learn More
No items found.
No items found.
July 8, 2020
Blog
blog-posts
July 1, 2020
July 1, 2020

내 워크플로우를 방해하지 마세요!적절한 시기에 적절한 보안 교육을 받을 수 있는 방법

우리는 필요할 때 교육을 받는 데 방해가 되는 장벽을 줄이기 위해 무엇을 할 수 있는지, 그리고 마이크로 러닝을 워크플로우에 보다 원활하게 구현할 수 있는 방법에 대해 생각하기 시작했습니다.

Learn More
No items found.
No items found.
July 1, 2020
Blog
blog-posts
June 22, 2020
June 22, 2020

세계 여성 엔지니어링의 날: 스타를 만나다

6월 23일은 세계 여성 엔지니어링의 날을 기념하는 Geek 달력에 특별히 기록되는 날입니다.소프트웨어 개발에 대한 여성의 기여를 조명할 수 있는 기회입니다.

Learn More
No items found.
No items found.
June 22, 2020
Blog
blog-posts
June 22, 2020
June 22, 2020

시리즈로 보안 인프라를 정복하는 코더 시리즈 - 비즈니스 로직

이 취약성은 비즈니스 로직 규칙을 제대로 구현하지 못할 때 발생할 수 있으며, 악의적인 사용자가 악용할 시스템이 될 수 있습니다. 다양한 종류의 공격에 취약해질 수 있습니다.

Learn More
No items found.
No items found.
June 22, 2020
Blog
blog-posts
June 18, 2020
June 18, 2020

Rust는 다섯 번째로 가장 사랑받는 프로그래밍 언어입니다.이것이 우리의 새로운 보안 구세주인가요?

Rust는 일반적으로 사용되는 언어의 알려진 기능 요소를 통합하여 복잡성을 없애는 다른 철학에 따라 작업하면서 성능과 안전성을 도입합니다.

Learn More
No items found.
No items found.
June 18, 2020
Blog
blog-posts
June 15, 2020
June 15, 2020

코드 시리즈로 보안 인프라를 정복하는 코더 - 신뢰할 수 없는 출처의 구성 요소 사용

여기서 초점을 맞출 취약성 유발 행위는 신뢰할 수 없는 출처의 코드를 사용하는 것인데, 이는 겉보기에 무해해 보이지만 큰 문제를 일으키고 있습니다.

Learn More
No items found.
No items found.
June 15, 2020
Blog
blog-posts
June 9, 2020
June 9, 2020

사이버 범죄자들이 의료 기관을 공격하고 있습니다 (하지만 우리는 이에 맞서 싸울 수 있습니다)

의료는 차세대 '위대한' 사이버 보안 전쟁터가 될 수 있습니다. 범죄자들은 의료 문제를 진단하고 치료를 제공하며 생명을 유지하는 바로 그 기계를 공격합니다.

Learn More
No items found.
No items found.
June 9, 2020
Blog
blog-posts
June 8, 2020
June 8, 2020

코드 시리즈로 보안 인프라를 정복하는 코더 시리즈: 잘못된 보안 구성 - 부적절한 권한

보안 구성 오류, 특히 부적절한 권한 구성은 개발자가 새 사용자를 만들거나 작업을 수행하기 위해 응용 프로그램을 도구로 사용할 권한을 부여할 때마다 자주 발생합니다.

Learn More
No items found.
No items found.
June 8, 2020
Blog
blog-posts
June 1, 2020
June 1, 2020

코드 시리즈로 보안 인프라를 정복한 코더: 불충분한 전송 계층 보호

때때로 애플리케이션은 전체 워크로드의 일부로 다른 프로그램과 데이터를 공유하기도 합니다.전송 계층이 보호되지 않으면 외부 스누핑과 내부 무단 보기 모두에 취약해집니다.

Learn More
No items found.
No items found.
June 1, 2020
Blog
blog-posts
May 25, 2020
May 25, 2020

코드 시리즈로 보안 인프라를 정복한 코더 시리즈: 안전하지 않은 암호화

요즘에는 암호, 개인 정보 및 재무 기록과 같은 중요한 데이터를 유휴 상태에서 해시하는 것이 모든 사이버 보안 방어의 초석입니다.

Learn More
No items found.
No items found.
May 25, 2020
Blog
blog-posts
May 21, 2020
May 21, 2020

COBOL 애플리케이션 개발 보안 | 시큐어 코드 워리어

레거시 COBOL은 오래된 컴퓨터 언어이지만 오늘날에도 여전히 유효합니다.시큐어 코드 워리어로부터 COBOL 보안 애플리케이션 개발에 대해 자세히 알아보십시오.

Learn More
No items found.
No items found.
May 21, 2020
Blog
blog-posts
May 18, 2020
May 18, 2020

#시리즈로 보안 인프라를 정복한 코더 시리즈: 암호의 일반 텍스트 저장

오늘날 대부분의 컴퓨터 보안의 핵심은 암호입니다.2단계 인증이나 생체 인식과 같은 다른 보안 방법을 사용하더라도 대부분의 조직은 암호 기반 보안 보호의 손아귀로 한 손해를 사용합니다.

Learn More
No items found.
No items found.
May 18, 2020
Blog
blog-posts
May 15, 2020
May 15, 2020

웨비나: DevOps에 “Sec”를 도입할 준비가 되셨나요?

보안이 조직 전체와 SDLC 전체에서 공동 책임으로 간주되는 단계에 도달해야 합니다.이는 완전한 기능을 갖춘 고도로 지원적인 DevSecOps 환경을 이용한다면 확실히 가능합니다.

Learn More
No items found.
No items found.
May 15, 2020
Blog
blog-posts
May 11, 2020
May 11, 2020

코드 시리즈로 보안 인프라를 정복한 코더: 기능 수준 액세스 제어 누락

인프라 수준의 액세스 제어를 완벽하게 갖추지 못하면 기업 전체가 공격자에게 노출될 수 있으며, 공격자는 해당 취약점을 무단 스누핑이나 전체 공격의 게이트웨이로 사용할 수 있습니다.

Learn More
No items found.
No items found.
May 11, 2020
Blog
blog-posts
May 4, 2020
May 4, 2020

코드 시리즈로 보안 인프라를 정복하는 코더 시리즈: 장애인 보안 기능

공격자는 항상 쉽게 악용될 수 있는 취약점을 먼저 찾으려고 시도하며 스크립트를 사용하여 일반적인 약점을 찾아낼 수도 있습니다.도둑이 거리의 모든 차를 뒤져 문이 열렸는지 확인하는 것과 다르지 않습니다. 창문을 부수는 것보다 훨씬 쉽습니다.

Learn More
No items found.
No items found.
May 4, 2020
Blog
blog-posts
April 17, 2020
April 17, 2020

지루한 PCI-DSS 규정 준수를 모두를 위한 의미 있는 활동으로 전환: 2부 - CISO 및 개발자 인식

이 글은 조직 내 PCI-DSS 규정 준수에 관한 미니 시리즈 중 2부입니다.이 마지막 장에서는 CTO와 CISO가 어떻게 사이버 위험을 줄이고 프로세스를 원활하고 성공적으로 만들 수 있는지, 그리고 개발자들에게 약간의 재미를 줄 수 있는 방법을 자세히 설명합니다.

Learn More
No items found.
No items found.
April 17, 2020
Blog
blog-posts
April 16, 2020
April 16, 2020

지루한 PCI-DSS 규정 준수를 모두를 위한 의미 있는 활동으로 전환: 1부 - AppSec

이 글은 조직 내 성공적인 PCI-DSS 규정 준수에 관한 2부작 시리즈 중 1부입니다.이 장에서는 AppSec 전문가가 개발 관리자와 긴밀하게 협력하여 개발자의 역량을 강화하고 SSDLC를 강화하며 일반 법률의 구체적인 결과를 도출하는 방법을 자세히 설명합니다.

Learn More
No items found.
No items found.
April 16, 2020
Blog
blog-posts
April 6, 2020
April 6, 2020

사이버 보안의 미래: 내년에는 일어나지 않을 일

우리 업계에서는 많은 보안 전문가들이 올해의 주요 문제를 예측하기 시작했지만, 2019년에 50억 개 이상의 민감한 데이터 기록이 도난당했기 때문에 가까운 미래에 사이버 보안에서 일어나지 않을 일을 예측하는 것이 더 정확할 것이라고 생각했습니다.

Learn More
No items found.
No items found.
April 6, 2020
Blog
blog-posts
March 25, 2020
March 25, 2020

왼쪽으로 이동하는 것만으로는 충분하지 않습니다: 왼쪽으로 시작하는 것이 소프트웨어 보안 우수성의 핵심인 이유

개발 프로세스 초기에 보안을 도입하는 “좌익이동”을 중심으로 한 이니셔티브의 대부분은 제대로 성과를 거두지 못합니다.

Learn More
No items found.
No items found.
March 25, 2020
Blog
blog-posts
March 5, 2020
March 5, 2020

DACH의 DevSecOps: 보안 코딩 파일럿 프로그램의 주요 결과

GDPR의 도래와 독일 연방 정부의 서버뿐만 아니라 많은 유명 인사의 민감한 데이터를 노출시킨 다단계 공격에 따른 전략이 수정됨에 따라 DACH 지역의 리더들은 사이버 보안에 대한 인식과 조치를 최우선으로 여긴다는 것이 분명해졌습니다.

Learn More
No items found.
No items found.
March 5, 2020
Blog
blog-posts
February 28, 2020
February 28, 2020

멋진 데브젝옵스 엔지니어가 되는 방법

세계는 워터폴, 애자일, 그리고 이제는 DevOps로 바뀌기 시작했습니다. 다음 솔루션은 무엇일까요?그리고 개발자로서 이러한 접근 방식의 변화에 발맞추는 데 있어 어떤 역할을 하고 계신가요?

Learn More
No items found.
No items found.
February 28, 2020
Blog
blog-posts
February 12, 2020
February 12, 2020

2019년 가장 위험한 소프트웨어 오류: 역사가 반복되고 있다는 더 많은 증거

작년 말, MITRE의 멋진 커뮤니티는 2019년에 전 세계에 영향을 미친 CWE 상위 25대 가장 위험한 소프트웨어 오류 목록을 발표했습니다.그리고 대부분은 놀랄 일도 아니었습니다.

Learn More
No items found.
No items found.
February 12, 2020
Blog
blog-posts
January 28, 2020
January 28, 2020

성장 급증: 5번째 생일 축하해, 시큐어 코드 워리어

초고속 성장 중인 스타트업을 나타내는 모든 사실과 수치로 이 기사를 시작할 수도 있었을 것입니다. 이러한 사실과 수치는 의심할 여지 없이 인상적이며 우리의 지속적인 회사 궤적은 강력합니다.하지만 제가 보기에 이 수치들은 제가 2019년에 가장 자랑스럽게 생각하는 것을 반영하지 못합니다.

Learn More
No items found.
No items found.
January 28, 2020
Blog
blog-posts
January 1, 2020
January 1, 2020

DevOps 구현이 자주 실패하는 이유 (및 해결 방법)

DevOps 구현에 진정으로 성공한 회사는 거의 없습니다.하지만 비즈니스 전반에 걸친 적절한 지원, 육성 및 이해는 프로세스를 혁신할 수 있습니다.

Learn More
No items found.
No items found.
January 1, 2020
Blog
blog-posts
December 2, 2019
December 2, 2019

새로운 NIST 지침: 안전한 소프트웨어를 만들기 위해 맞춤형 교육이 필수적인 이유

국립 표준 기술 연구소 (NIST) 는 소프트웨어 취약성과 사이버 위험을 줄이기 위한 몇 가지 실행 계획을 자세히 설명하는 업데이트된 백서를 발표했습니다.

Learn More
No items found.
No items found.
December 2, 2019
Blog
blog-posts
November 21, 2019
November 21, 2019

OWASP 앱섹 데이 2019: 보안 개발자 육성

이러한 개발자 중심 이벤트는 일정에서 제가 가장 좋아하는 행사 중 하나입니다. 소프트웨어 엔지니어와 전문가가 업무의 보안을 옹호할 수 있도록 끊임없이 교육하고 역량을 강화하는 커뮤니티를 겸손하게 상기시켜줍니다.

Learn More
No items found.
No items found.
November 21, 2019
Blog
blog-posts
October 31, 2019
October 31, 2019

스태틱 대.동적 사이버 보안 교육: 충동적인 규정 준수, 향후 문제

규제 이니셔티브는 의심할 여지 없이 시간이 지남에 따라 개선되고 성장하겠지만, 조직이 이미 패닉 버튼을 누르고 지금 바로 교육에 뛰어든다면 미래를 위한 준비가 제대로 되어 있지 않을 수도 있습니다.

Learn More
No items found.
No items found.
October 31, 2019
Blog
blog-posts
October 16, 2019
October 16, 2019

마을이 필요하다: 커뮤니티 정신이 개발자를 더 안전하게 만드는 방법

각계각층의 모든 유형의 개발자가 있으며, 우리가 하는 모든 일에는 항상 커뮤니티 의식이 있었습니다.

Learn More
No items found.
No items found.
October 16, 2019
Blog
blog-posts
September 30, 2019
September 30, 2019

심층적인 보안 교육을 통한 교육에 대한 의문이 제기되고 있습니다.

보안 코딩은 고등 교육 단계에서 소프트웨어 엔지니어링의 필수 구성 요소가 되어야 합니다. 하지만 일부 대학은 처음부터 개발 프로세스의 첫 단계에서부터 최고의 서비스를 제공하고 보안의 우선 순위를 정하는 데 앞장서고 있습니다.

Learn More
No items found.
No items found.
September 30, 2019
Blog
blog-posts
September 24, 2019
September 24, 2019

우먼 인 시큐리티: 파테마 베이던에 대한 스포트라이트

고객 성공 담당 부사장인 Fatemah Beydoun은 최근 “미래를 위한 멘토링: 여성 사이버 보안 인재를 양성하는 데 있어 우리 모두가 더 잘할 수 있는 방법”이라는 강연을 매우 호의적인 청중에게 발표했습니다.그녀는 사이버 보안 산업 내에서 긍정적인 변화를 주도하는 데 없어서는 안 될 역할을 해왔습니다.

Learn More
No items found.
No items found.
September 24, 2019
Blog
blog-posts
September 20, 2019
September 20, 2019

코더들이 보안을 정복하다: Share & Learn 시리즈 - 안전하지 않은 역직렬화

애플리케이션에서 역직렬화되는 데이터를 신뢰할 수 있는 것으로 취급할 때마다 안전하지 않은 역직렬화가 발생할 수 있습니다.사용자가 새로 재구성된 데이터를 수정할 수 있는 경우 코드 삽입, 서비스 거부 공격 또는 권한 상승과 같은 모든 종류의 악의적 활동을 수행할 수 있습니다.

Learn More
No items found.
No items found.
September 20, 2019
Blog
blog-posts
September 11, 2019
September 11, 2019

상황에 맞는 실습 학습: 보안을 위해 두뇌를 훈련하는 강력한 방법

많은 곳에서 새로운 이니셔티브를 최대한 활용하기 위해 여전히 강의실, 마른 교과서, 정신을 마비시키는 비디오 교육에 의존하고 있다는 사실은 정말 놀랍습니다. 특히 훨씬 더 훌륭하고 매력적이며 가치 있는 학습 방법이 있다면 더욱 그렇습니다. 바로 상황에 맞는 교육입니다.

Learn More
No items found.
No items found.
September 11, 2019
Blog
blog-posts
September 5, 2019
September 5, 2019

공감, 감사, 겸손: 우리 문화의 기초

소프트웨어 보안 산업은 따뜻하고 흐릿한 감정, 기발한 관찰, 삶에 대한 평론으로 잘 알려져 있지는 않지만, 아마도 나이가 들면서 우리 모두가 세상에 미칠 수 있는 영향에 대해 곰곰이 생각해 보게 될 것입니다.

Learn More
No items found.
No items found.
September 5, 2019
Blog
blog-posts
September 4, 2019
September 4, 2019

코더들이 보안을 정복하다: 공유 및 학습 시리즈 - 민감한 데이터 노출

민감한 데이터 노출은 승인된 열람만을 위한 정보가 암호화되지 않았거나 보호되지 않거나 보호가 취약한 상태에서 승인되지 않은 사람에게 노출될 때마다 발생합니다.

Learn More
No items found.
No items found.
September 4, 2019
Blog
blog-posts
August 14, 2019
August 14, 2019

호기심 많은 보안 담당자를 처벌하는 것이 아니라 지원해야 하는 이유

10대 보안 연구원인 Bill Demirkapi는 학교에서 사용하는 소프트웨어의 주요 취약점을 폭로하면서 기억을 되살렸습니다.호기심 많은 아이였을 때 소프트웨어의 후드를 들어서 그 밑을 들여다보고 어떻게 작동하는지 살펴봤던 기억이 납니다... 그리고 제가 그걸 깨뜨릴 수 있을지 말이죠.

Learn More
No items found.
No items found.
August 14, 2019
Blog
blog-posts
August 5, 2019
August 5, 2019

훌륭한 글로벌 패치: 수백만 개의 디바이스를 손상시킬 수 있는 VxWorks 결함

VxWorks는 일반 소비자에게 잘 알려진 이름은 아니지만, 이 소프트웨어 제품은 여러분과 저와 같은 많은 사람들에게 매일 혜택을 줍니다.그리고 지금은 수억 대의 VxWorks 기반 디바이스가 손상될 가능성에 직면해 있습니다.

Learn More
No items found.
No items found.
August 5, 2019
Blog
blog-posts
August 1, 2019
August 1, 2019

코더들이 보안을 정복하다: 공유 및 학습 시리즈 - XXE Injection

간단히 XXE 인젝션이라고도 하는 XML 외부 엔티티 인젝션 (External Entity Injection) 공격은 비교적 새로운 공격이지만, 현재 해킹 커뮤니티에서 매우 인기가 있으며 성공을 거두면서 그 수가 더욱 증가하고 있습니다.

Learn More
No items found.
No items found.
August 1, 2019
Blog
blog-posts
July 25, 2019
July 25, 2019

코더들이 보안을 정복하다: 셰어 앤 런 시리즈 - CRLF 인젝션

공격자가 기존 애플리케이션에 CR 또는 LF 코드를 삽입할 수 있는 경우 때때로 동작을 변경할 수 있습니다.대부분의 공격에 비해 그 영향을 예측하기는 쉽지 않지만 대상 조직에 미치는 위험도 낮을 수는 없습니다.

Learn More
No items found.
No items found.
July 25, 2019
Blog
blog-posts
July 23, 2019
July 23, 2019

창의적인 CISO와 CIO가 보안 프로그램을 혁신하고 혁신할 수 있는 방법

창의적이고 영감을 주는 CISO와 CIO는 디지털 세상을 혁신하고 변화시킬 수 있는 힘을 가지고 있지만 조직의 보안 문화를 변화시키는 데도 중요한 역할을 할 수 있습니다.

Learn More
No items found.
No items found.
July 23, 2019
Blog
blog-posts
July 18, 2019
July 18, 2019

코더즈 컨커 보안: 공유 및 학습 시리즈 - 원격 파일 포함

여러 면에서 원격 파일 포함 취약점은 로컬 파일에 대응하는 취약점보다 훨씬 위험하고 악용하기도 쉽습니다.따라서 가능한 한 빨리 발견하여 해결해야 합니다.

Learn More
No items found.
No items found.
July 18, 2019
Blog
blog-posts
July 4, 2019
July 4, 2019

개정된 PCI 보안 표준 위원회 지침: 개정된 지침은 충분히 왼쪽으로 바뀌었는가?

올해 PCI 보안 표준 위원회는 PCI 소프트웨어 보안 프레임워크의 일부로 완전히 새로운 소프트웨어 보안 지침을 발표했습니다.이번 업데이트는 소프트웨어 보안 모범 사례를 최신 소프트웨어 개발과 연계하는 것을 목표로 합니다.

Learn More
No items found.
No items found.
July 4, 2019
Blog
blog-posts
July 4, 2019
July 4, 2019

코더들이 보안을 정복하다: 공유 및 학습 시리즈 - 로컬 파일 포함 및 경로 탐색

다른 많은 취약점과는 달리, 로컬 파일 포함 및 경로 탐색 프로세스를 악용하려면 충분히 숙련된 공격자와 상당한 시간, 그리고 아마도 약간의 운이 필요합니다.

Learn More
No items found.
No items found.
July 4, 2019
Blog
blog-posts
June 27, 2019
June 27, 2019

코더들이 보안을 정복하다: Share & Learn 시리즈 - 불충분한 전송 계층 보호

애플리케이션 서버와 이 서버에서 사용하는 백엔드 시스템을 완전히 보호하더라도 전송 계층 보호가 충분하지 않으면 통신이 여전히 스누핑에 취약할 수 있습니다.

Learn More
No items found.
No items found.
June 27, 2019
Blog
blog-posts
June 20, 2019
June 20, 2019

코더들이 보안을 정복하다: 셰어 앤 런 시리즈 - XML 인젝션

XML 인젝션 공격은 해커가 XML 데이터베이스를 호스팅하는 시스템을 손상시키기 위해 고안한 아주 작은 익스플로잇입니다.여기에는 의약품부터 영화에 이르기까지 모든 것에 대한 정보를 자세하게 저장하는 기존 데이터베이스를 생각할 때 떠오르는 것들이 포함됩니다.

Learn More
No items found.
No items found.
June 20, 2019
Blog
blog-posts
June 6, 2019
June 6, 2019

Huawei 보안 UK 문제는 보안 코딩의 필요성을 보여줍니다

영국 화웨이 사이버 보안 평가 센터의 최근 보고서에 따르면 화웨이의 소프트웨어 엔지니어링 프로세스 내에서 주요 보안 문제가 확인되었습니다.하지만 이 문제는 고칠 수 있습니다.

Learn More
No items found.
No items found.
June 6, 2019
Blog
blog-posts
June 5, 2019
June 5, 2019

베스트 오브 더 브런치: AppSec의 리더들이 지혜를 공유하다

Leaders in AppSec 패널은 조직의 AppSec 예산을 최대한 활용하는 방법과 같은 중요한 문제뿐만 아니라 청중으로부터 제기되는 몇 가지 복잡한 질문을 다루면서 보안 전문가가 조직 내에서 실행 가능한 프로그램을 구축하는 데 도움이 될 진정한 아침 마법을 제시했습니다.

Learn More
No items found.
No items found.
June 5, 2019
Blog
blog-posts
May 30, 2019
May 30, 2019

코더들이 보안을 정복하다: Share & Learn 시리즈 - 불충분한 로깅 및 모니터링

불충분한 로깅 및 모니터링은 애플리케이션의 방어 구조 내에 존재할 수 있는 가장 위험한 상태 중 하나입니다.이러한 취약점이나 상태가 존재하면 이를 대상으로 한 거의 모든 고급 공격이 결국 성공할 것입니다.

Learn More
No items found.
No items found.
May 30, 2019
Blog
blog-posts
May 23, 2019
May 23, 2019

코더들이 보안을 정복하다: 셰어&런 시리즈 - 검증되지 않은 리다이렉션 및 전달

검증되지 않은 리디렉션 및 전달을 할 수 있는 기능을 갖춘 웹 사이트 또는 애플리케이션을 모두에게 매우 위험할 수 있습니다.

Learn More
No items found.
No items found.
May 23, 2019
Blog
blog-posts
May 22, 2019
May 22, 2019

시큐어 코드 워리어와 버그크라우드: 매칭 메이드 인 시큐리티 긱 헤븐

공식 발표입니다. 저희는 Bugcrowd와 힘을 합쳐 개발자들에게 보안 코딩에 대해 교육하고, 권한을 부여하고, 계몽하기 위해 노력하고 있습니다.

Learn More
No items found.
No items found.
May 22, 2019
Blog
blog-posts
May 16, 2019
May 16, 2019

코더즈 컨커 보안: 셰어 앤 런 시리즈 - 코드 인젝션

코드 인젝션 공격은 많은 웹 사이트와 애플리케이션에서 발생하는 가장 흔하고 가장 위험한 공격 중 하나입니다.이러한 공격은 정교함과 위험 측면에서 모두 뛰어나지만 사용자 입력을 받아들이는 거의 모든 사이트나 앱이 취약할 수 있습니다.

Learn More
No items found.
No items found.
May 16, 2019
Blog
blog-posts
May 9, 2019
May 9, 2019

GitHub 사용자는 일반 텍스트 문제를 겪으며 몸값을 지불해야 했습니다.

GitHub 리포지토리에 대한 최근의 공격은 보안 업계에서 잘 알려진 문제를 부각시키고 있습니다. 대부분의 개발자는 단순히 보안을 충분히 인식하지 못하고 귀중한 데이터가 언제든지 위험에 처할 수 있다는 것입니다.

Learn More
No items found.
No items found.
May 9, 2019
Blog
blog-posts
May 9, 2019
May 9, 2019

코더즈 컨커 보안: 공유 및 학습 시리즈 - 깨진 액세스 제어

고객이 내부용이든 외부용이든 비즈니스 애플리케이션을 구축할 때 모든 사용자가 모든 기능을 수행하도록 허용하지는 않을 수 있습니다.그렇게 하면 액세스 제어 해제에 취약해질 수 있습니다.

Learn More
No items found.
No items found.
May 9, 2019
Blog
blog-posts
May 3, 2019
May 3, 2019

사이버 보안 모범 사례를 보려면 금융 산업을 살펴보십시오.

모든 업종의 모든 유형의 조직에 영향을 미치는 사이버 공격이 증가함에 따라 비용이 많이 들고 당혹스러우며 수익에 영향을 미치는 데이터 침해 위협은 매우 현실적입니다.문제는 작아지는 것이 아니라 종양처럼 커지고 있다는 것입니다.

Learn More
No items found.
No items found.
May 3, 2019
Blog
blog-posts
May 2, 2019
May 2, 2019

코더들이 보안을 정복하다: 공유 및 학습 시리즈 - 정보 노출

웹 앱이 너무 많은 정보를 노출하면 공격자가 더 쉽게 침입할 수 있습니다. 이 게시물에서는 정보 노출의 정의, 위험한 이유, 방지 방법에 대해 알아보겠습니다.

Learn More
No items found.
No items found.
May 2, 2019
Blog
blog-posts
April 25, 2019
April 25, 2019

코더들이 보안을 정복하다: Share & Learn 시리즈 - 알려진 취약점이 있는 구성 요소 사용

모든 애플리케이션은 대부분 사용자가 작성하지 않은 구성 요소를 사용하므로 사용하는 구성 요소 내의 취약성이 문제가 될 수 있습니다.취약성이 알려진 구성 요소를 사용하는 것이 무엇을 의미하는지, 얼마나 위험한지, 해결 방법에 대해 알아보겠습니다.

Learn More
No items found.
No items found.
April 25, 2019
Blog
blog-posts
April 17, 2019
April 17, 2019

'보안'은 더러운 단어가 아닙니다: 긍정적인 접근 방식이 보안 프로그램을 혁신하는 방법

저는 양쪽 입장을 견지해 왔기 때문에 보안 모범 사례를 유지하는 데 있어 개발팀과 AppSec 전문가 간에 발생할 수 있는 긴장감을 너무나 잘 알고 있습니다.하지만 더 나은 접근 방식이 있습니다.

Learn More
No items found.
No items found.
April 17, 2019
Blog
blog-posts
April 11, 2019
April 11, 2019

코더즈 컨커 시큐리티: 셰어 앤 런 시리즈 - 인증

웹 사이트를 운영하거나 직원들이 컴퓨터 리소스에 원격으로 액세스할 수 있도록 하는 조직, 즉 거의 모든 사람이 직면하는 가장 일반적인 문제 중 하나를 다루겠습니다.네, 아마도 우리가 인증에 대해 이야기할 것이라고 짐작하셨을 것입니다.

Learn More
No items found.
No items found.
April 11, 2019
Blog
blog-posts
April 4, 2019
April 4, 2019

코더들이 보안을 정복하다: 셰어&런 시리즈 - 불충분한 안티오토메이션

응용 프로그램에 대한 자동화 관리 관리가 불가능한 경우 공격자는 일치하는 암호를 찾을 수 있습니다. 이를 이해하는 방법은 다음과 같습니다.

Learn More
No items found.
No items found.
April 4, 2019
Blog
blog-posts
March 28, 2019
March 28, 2019

코더들이 보안을 정복하다: Share & Learn 시리즈 - 비즈니스 로직 문제

코딩 문제가 문제의 일부일 수 있지만 비즈니스 로직 오류는 대부분 앱을 처음 만들 때 설계 결함이나 잘못된 논리적 가정으로 인해 발생합니다.

Learn More
No items found.
No items found.
March 28, 2019
Blog
blog-posts
March 27, 2019
March 27, 2019

DevSecOps: 오래된 보안 버그는 여전히 새로운 트릭을 수행하고 있습니다

사이버 보안 분야에서 우리는 종종 사냥꾼과 같습니다.우리의 눈은 지평선에 단단히 고정되어 다음 취약점을 찾아냅니다.하지만 이러한 미래 지향적인 초점은 전반적인 보안 인식을 약화시키는 놀라운 결과를 초래할 수 있습니다.

Learn More
No items found.
No items found.
March 27, 2019
Blog
blog-posts
March 21, 2019
March 21, 2019

코더즈 컨커 시큐리티: 셰어 앤 런 시리즈 - 이메일 헤더 인젝션

웹 사이트와 애플리케이션에서는 사용자가 이메일을 사용하여 애플리케이션을 통해 피드백 및 기타 다양한 정보를 보낼 수 있도록 하는 것이 일반적입니다.그리고 대부분의 사람들은 잠재적인 보안 위험 측면에서는 이에 대해 생각조차 하지 않습니다.

Learn More
No items found.
No items found.
March 21, 2019
Blog
blog-posts
March 14, 2019
March 14, 2019

코더들이 보안을 정복하다: Share & Learn 시리즈: 안전하지 않은 다이렉트 오브젝트 레퍼런스

직접 객체 참조는 특정 레코드 ('객체') 가 애플리케이션 내에서 참조되는 경우입니다.일반적으로 고유 식별자의 형태를 취하며 URL에 표시될 수 있습니다.

Learn More
No items found.
No items found.
March 14, 2019
Blog
blog-posts
March 13, 2019
March 13, 2019

소프트웨어 보안은 와일드 웨스트 (Wild West) 에 있습니다 (그리고 그것은 우리를 죽일 것입니다)

저는 소프트웨어 보안을 항상 최우선으로 생각합니다. 점점 더 디지털화되고 개인 정보를 공유하는 라이프스타일로 인해 초래되는 실제 위험도 마찬가지입니다.결국 우리는 거의 규제되지 않고 감독도 받지 않으며 홀가분하게 무시당하는 영역에 처해 있습니다.우린 와일드 웨스트에 있어요.

Learn More
No items found.
No items found.
March 13, 2019
Blog
blog-posts
March 7, 2019
March 7, 2019

안전하지 않은 암호화 스토리지 및 보안 | 시큐어 코드 워리어

이 디지털 사회에서 개발자는 안전하지 않은 암호화 저장소로부터 정보와 비즈니스를 안전하게 보호할 책임이 있습니다.시큐어 코드 워리어로부터 배워보세요.

Learn More
No items found.
No items found.
March 7, 2019
Blog
blog-posts
February 28, 2019
February 28, 2019

코더들이 보안을 정복하다: 공유 및 학습 시리즈 - 엑스쿼리 인젝션

#대다수의 웹 사이트는 XML 데이터베이스를 사용하여 사용자 로그인 자격 증명, 고객 정보, 개인 신원 정보 및 기밀 또는 민감한 데이터를 보관하는 것과 같은 중요한 데이터를 보관하므로 xQuery 공격, 면적이 다소 커집니다.

Learn More
No items found.
No items found.
February 28, 2019
Blog
blog-posts
February 21, 2019
February 21, 2019

보안 구성 오류란 무엇입니까?| 시큐어 코드 워리어

잘못된 보안 구성이란 무엇입니까?가장 많이 발생하는 보안 구성 오류와 취약성 방지 방법을 찾아보세요.시큐어 코드 워리어로부터 배워보세요.

Learn More
No items found.
No items found.
February 21, 2019
Blog
blog-posts
February 15, 2019
February 15, 2019

4번째 생일 축하해, 시큐어 코드 워리어, 너 치키 리틀 토들러

딸과 회사가 나이가 들수록 스타트업 여정과 처음으로 부모가 되는 여정 사이에는 유사점이 너무 많다는 것을 더 많이 깨닫게 됩니다.저는 이제 둘 다 4년차에 접어들었습니다.pi

Learn More
No items found.
No items found.
February 15, 2019
Blog
blog-posts
February 14, 2019
February 14, 2019

코더들이 보안을 정복하다: 셰어 앤 런 시리즈 - 클릭재킹

이제 클릭재킹이 어떻게 작동하는지, 왜 위험한지, 그리고 여러분과 같은 개발자가 이를 방지하기 위해 무엇을 할 수 있는지 살펴보겠습니다.

Learn More
No items found.
No items found.
February 14, 2019
Case Study
case-studies
January 6, 2026
January 6, 2026

Kamer van Koophandel Sets the Standard for Developer-Driven Security at Scale

Kamer van Koophandel shares how it embedded secure coding into everyday development through role-based certifications, Trust Score benchmarking, and a culture of shared security ownership.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Case Study
case-studies
October 8, 2025
October 8, 2025

Going for Gold: Soaring Secure Code Standards at Paysafe

See how Paysafe's partnership with Secure Code Warrior led to a 45% boost in developer productivity and a major reduction in code vulnerabilities.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Case Study
case-studies
August 15, 2024
August 15, 2024

DigitalOcean Decreases Security Debt with Secure Code Warrior

DigitalOcean's use of Secure Code Warrior training has significantly reduced security debt, allowing teams to focus more on innovation and productivity. The improved security has strengthened their product quality and competitive edge. Looking ahead, the SCW Trust Score will help them further enhance security practices and continue driving innovation.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Case Study
case-studies
November 28, 2023
November 28, 2023

Devlympics 2023: In Review

Explore the Devlympics 2023 results in this report. Dive into developer engagement, tech stack and languages trends in each industry that participated, and key vulnerabilities and CWEs covered in the annual global event hosted by Secure Code Warrior.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Case Study
case-studies
November 22, 2023
November 22, 2023

One Culture of Security: How Sage built their security champions program with agile secure code learning

Discover how Sage enhanced security with a flexible, relationship-focused approach, creating 200+ security champions and achieving measurable risk reduction.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Case Study
case-studies
October 2, 2023
October 2, 2023

The path to security champions: How Workday utilized agile learning to upskill developers

Discover how Workday transformed developer training with agile learning through Secure Code Warrior. By empowering developer with hands-on, language-specific education, Workday reduced vulnerabilities early in the SDLC. See their impressive results and key takeaways to build a secure code culture.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Case Study
case-studies
July 22, 2023
July 22, 2023

How Thales implemented developer-driven security

In this case study, learn how Thales has developed people, process, and technology approaches for an agile secure code learning program in order to engage developers to become active security champions.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Case Study
case-studies
June 7, 2023
June 7, 2023

How Colgate-Palmolive boosted developer security skills and created a secure coding culture

Discover how retail giant Colgate-Palmolive reshaped its application security during its digital transformation journey. Facing challenges in secure coding, they innovated their approach by integrating bite-sized, in-context learning into the developer workflow.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Case Study
case-studies
May 13, 2021
May 13, 2021

Security as culture: How Blue Prism cultivates world-class secure developers

Learn how Blue Prism, the global leader in intelligent automation for the enterprise, used Secure Code Warrior's agile learning platform to create a security-first culture with their developers, achieve their business goals, and ship secure code at speed

Learn More
No items found.
No items found.
This is some text inside of a div block.
Case Study
case-studies
May 12, 2021
May 12, 2021

Supercharged Security Awareness: How Tournaments are Inspiring Developers at Erste Group

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Case Study
case-studies
January 1, 2021
January 1, 2021

How a ‘Game of Codes’ is leading IAG Group to a more secure coding future

IAG Group is the name behind many of the leading insurancecompanies in the Asia-Pacific region, underwriting policies formillions of customers to the tune of approximately AUD $11.4 Billionin premiums per annum.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Case Study
case-studies
January 1, 2021
January 1, 2021

Driving Actionable Awareness: FINRA's Push For Super-Secure Developers

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Case Study
case-studies
January 1, 2021
January 1, 2021

Creating a revolutionary security certification experience

Learn how they created an in-house technology education initiative, aimed at supporting thousands of employees to learn practical, cutting-edge skills in a number of disciplines, including machine learning and cybersecurity.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Case Study
case-studies
January 1, 2021
January 1, 2021

Beyond Compliance: Motorola Solutions Drives Winning Security Culture

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Case Study
case-studies
January 1, 2021
January 1, 2021

ASRG's push for automotive software security

Explore this comprehensive case study to learn more about how they utilized Secure Code Warrior's tournaments to engage developers, increase awareness of key vulnerabilities affecting automotive software, and gain metrics across multiple languages and frameworks.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Case Study
case-studies
January 1, 2021
January 1, 2021

Application Security @ NAB | Gamified Security Training: The Key to Scalable Developer Growth

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
August 27, 2026
August 27, 2026

Forbes: A New Frontier: NSA Proposes “Security By Design” Considerations For AI Enablement

​The cybersecurity industry, which has been advocating for “security by design” principles for more than a decade, stands in wide-eyed amazement at the risks posed by artificial intelligence (AI). As organizations rush to embrace AI enablement, a CISO’s most pressing priority is to avoid becoming a roadblock. However, without effective AI usage and governance, observability and traceability, organizations may be blindsided by their AI risk.​

Learn More
No items found.
No items found.
This is some text inside of a div block.
Media Release
news-articles
August 21, 2026
August 21, 2026

Techpartner.news: Secure Code Warrior introduces framework to govern AI use in software development

Secure Code Warrior has introduced the SCW AI Adoption Model, a framework designed to help organisations govern AI use in software development as the industry shifts from the traditional software development lifecycle (SDLC) toward what the company calls the Agentic Development Lifecycle (ADLC).

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
August 19, 2026
August 19, 2026

DevOps.com: Are LLMs Equally Good (or Bad) at Building Secure Software?

With many software engineering teams moving from AI coding assistants into full agentic AI code generation and increasing the amount of code they produce exponentially, ensuring the security of that code must be a top priority. The study produces practical guidance for organizations that are getting on board the AI-assisted or agentic code development train.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
August 14, 2026
August 14, 2026

TechRadar Pro: Beware the token trap: Why saving on inference might put your ADLC at risk

Token use can create unexpected, sizeable costs for organizations.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
August 11, 2026
August 11, 2026

KBI Media: AI Coding Boom Raises Fresh Cybersecurity Risks for Business

AI enables faster development cycles and allows developers to focus on higher-value work. For many businesses, these efficiencies are becoming essential to remaining competitive. The challenge, therefore, is not whether to adopt AI, but how to do so responsibly. Businesses that invest in developer education, governance frameworks, AI observability and robust security controls will be better positioned to capture the benefits while limiting the associated risks.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
August 11, 2026
August 11, 2026

In AI Today: AI's weakest link isn't the model but the software supply chain

The issue is no longer simply about protecting AI models themselves. Increasingly, attackers are focusing on the software ecosystem surrounding those models, including the development tools, middleware, open-source libraries, and automated deployment pipelines that organisations rely upon every day.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
August 10, 2026
August 10, 2026

The AI Journal: Investigating global AI regulation: Who is winning, and where to from here?

As we will unpack together, there is a lot of movement around the world, with some collaboration between nations, but the path forward is far from uniform or clear, particularly in business environments where AI adoption is often mandated before holistic safeguarding measures are in place.  

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
July 27, 2026
July 27, 2026

Cyber Daily: The industry reacts to OpenAI’s agent ‘accidentally’ hacking Hugging Face

According to one expert, AI guardrails are not designed as “security boundaries” but rather to influence behaviour – but what if that behaviour is hacking one of your industry partners?

Learn More
No items found.
No items found.
This is some text inside of a div block.
Media Release
news-articles
July 24, 2026
July 24, 2026

SecurityBrief: Autonomous OpenAI agents breach Hugging Face in test

Cyber security experts have warned that the breach of Hugging Face infrastructure during an OpenAI security evaluation marks a turning point in the risks posed by autonomous AI agents. In the incident, AI models moved beyond a controlled test and carried out a live, multi-stage intrusion against the AI platform.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
July 24, 2026
July 24, 2026

Technology Decisions: AI generated code found to produce predictable weaknesses

AI-generated code introduces an average of 15 confirmed vulnerabilities per codebase, research published by Secure Code Warrior indicates.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
July 23, 2026
July 23, 2026

Forbes: OpenAI’s Hugging Face Breach Shows Frontier AI Guardrails Are Failing

Frontier AI is facing a PR crisis. After Hugging Face released a blog post on July 16 claiming an autonomous agent had breached its internal environment, OpenAI posted on July 21 that the incident occurred when GPT 5.6 Sol and a “pre-release model” escaped a controlled testing environment.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
July 22, 2026
July 22, 2026

In AI Today: Secure Code Warrior research reveals AI-generated code introduces an average of 15 vulnerabilities per codebase

Secure Code Warrior research reveals AI-generated code introduces an average of 15 vulnerabilities per codebase.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
July 21, 2026
July 21, 2026

VMBlog: Secure Code Warrior Research Reveals AI-Generated Code Introduces an Average of 15 Vulnerabilities Per Codebase

Secure Code Warrior introduced the SCW AI Trust Index, a living benchmark for AI coding security that grows with every new model, helping organizations understand and govern the security risks introduced by AI-generated code. Built on a methodology created with RMIT University, Australia, then extended by Secure Code Warrior, the research presents comprehensive benchmarks on how often leading LLMs produce insecure code, with material implications for every enterprise scaling AI-assisted development.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
July 21, 2026
July 21, 2026

Dark Reading: Choose Wisely: AI-Generated Coding Risk Varies, A Lot

AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Media Release
news-articles
July 21, 2026
July 21, 2026

Secure Code Warrior Research Reveals AI-Generated Code Introduces an Average of 15 Vulnerabilities Per Codebase

New SCW AI Trust Index shows AI-generated coding risk is not random, it's predictable by model and framework, giving security leaders the data to safely scale AI-assisted development.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
July 16, 2026
July 16, 2026

ITWire: Eight Industry Executives Comment on Worldwide AI Appreciation Day

The challenges with AI implementation, constant updates, and the race for industry dominance are coming thick and fast, and security professionals are among the most affected by its vast risk profile.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
July 16, 2026
July 16, 2026

Cyber Daily: The industry speaks – part 3: AI Appreciation Day 2026

The Australian government has said AI is very much in the country’s future national interest – but where does it stand today? Here’s what the industry’s best and brightest have to say about artificial intelligence and its role in the modern enterprise.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
July 13, 2026
July 13, 2026

ITWire: Agentic AI Era Demands Overhaul of Governance Frameworks

The emergence of agentic AI marks a structural shift in software development, introducing systems that not only accelerate production cycles but also perform autonomous reasoning and action beyond direct human control.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
July 2, 2026
July 2, 2026

SecurityWeek: How to Conduct a Successful Audit of AI-Driven Software Development

As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
July 1, 2026
July 1, 2026

SD Times: Platform Engineering & Developer Experience: Making Engineers Faster Without Making Them Reckless: SD Times 100

This category has taken on new urgency in 2026 for a reason that’s specific to this moment: AI coding tools and agents are dramatically increasing how much code gets written and how often it needs to be deployed, tested, and provisioned for. Platform engineering is the layer that determines whether that increased velocity translates into shipped value or into chaos.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
April 10, 2026
April 10, 2026

SD Times: AI-Assisted Development Multiplies Human Error: What’s Your AI Governance and Risk Management Strategy?

According to a recent report from Gartner, the rampant use of shadow AI and rogue automation is further fueling the proliferation of AI vulnerabilities. Gartner notes that 32% of IT workers using generative AI tools at work say they keep them hidden from cybersecurity teams. Combined with low-code/no-code platforms and vibe coding practices, the AI copilots are greatly expanding the enterprise attack surface.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
March 31, 2026
March 31, 2026

Cybersecurity Tribe: What Separates Real AI Governance From Policy Theater

For this article, we asked a central question for security and risk leaders: "What differentiates a policy that genuinely mitigates enterprise risk from one that exists primarily to demonstrate that the organization has acknowledged AI risk?"

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
March 31, 2026
March 31, 2026

ISMG: AI Coding Tools Raise Hidden Security Risks

Secure Code Warrior's Pieter Danhieux on Managing AI-Driven Development Risks

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
March 30, 2026
March 30, 2026

ITWire: Decoding AI Coding “Personalities” Critical to Managing Development Risk

As generative AI cements its place in enterprise software development, a familiar discipline is taking on new urgency: risk management.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
March 24, 2026
March 24, 2026

In AI Today: Secure Code Warrior launches Trust Agent: AI to enable safe, scalable AI-driven development

Secure Code Warrior have today announced SCW Trust Agent: AI, the industry’s first governance solution designed to make Artificial Intelligence (AI) influence in software development visible, attributable, and enforceable at the point of commit — enabling enterprises to scale AI coding tools with measurable control over software risk.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
March 23, 2026
March 23, 2026

DEVOPSdigest: 25 Years of the Agile Manifesto, and the End of the Road for AppSec?

Even as we restructure the SDLC around the most impactful elements of the Agile methodology with careful, DevSecOps-centric security considerations, is this the end of the road for AppSec as we know it?

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
March 23, 2026
March 23, 2026

Cyber Defense Magazine: Global InfoSec Awards 2026 Secure Code Warrior Wins Outstanding Achievement in Cybersecurity Risk Management and Compliance Excellence

Global InfoSec Awards 2026 Secure Code Warrior Wins Outstanding Achievement in Cybersecurity Risk Management and Compliance Excellence

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
March 19, 2026
March 19, 2026

ITWire: Secure Code Warrior Launches Trust Agent: AI to Enable Safe, Scalable AI-Driven Development

New AI Software Governance solution makes AI-generated code visible at commit, enforces policy before production, and connects real development behavior to measurable risk reduction.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
March 19, 2026
March 19, 2026

DevOps.com: Secure Code Warrior AI Agent Applies Policies to AI Generated Code

Secure Code Warrior (SCW) this week added an artificial intelligence (AI) agent that both identifies code generated by an AI coding tool and automatically applies the appropriate governance policies.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
March 18, 2026
March 18, 2026

SecurityBrief UK: Secure Code Warrior unveils AI tool to govern code risk

Secure Code Warrior has launched SCW Trust Agent: AI, a software governance product that tracks the use of AI coding tools in development and links that usage to software risk when developers commit code.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
March 17, 2026
March 17, 2026

2026 Globee® Awards for Cybersecurity: Secure Code Warrior Wins Gold Globee for Software Development Cybersecurity Solutions (Best Of)

2026 Globee® Awards for Cybersecurity: Secure Code Warrior Wins Gold Globee for Software Development Cybersecurity Solutions (Best Of)

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
March 17, 2026
March 17, 2026

DEVOPSdigest: Secure Code Warrior Releases Trust Agent

Secure Code Warrior announced SCW Trust Agent: AI, a governance solution designed to make AI influence in software development visible, attributable, and enforceable at the point of commit — enabling enterprises to scale AI coding tools with measurable control over software risk.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
March 17, 2026
March 17, 2026

TalkDev: Secure Code Warrior Launches Trust Agent: AI to Enable Safe, Scalable AI-Driven Development

Secure Code Warrior today announced SCW Trust Agent: AI, the industry’s first governance solution designed to make AI influence in software development visible, attributable, and enforceable at the point of commit — enabling enterprises to scale AI coding tools with measurable control over software risk. For the first time, organizations can trace which AI models influenced specific commits, correlate that influence to vulnerability exposure, and take corrective action before insecure code reaches production.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
March 17, 2026
March 17, 2026

Help Net Security: SCW Trust Agent: AI tracks AI influence in code to reduce software risk

Secure Code Warrior has announced SCW Trust Agent: AI, a governance solution designed to make AI influence in software development visible, attributable, and enforceable at the point of commit, enabling enterprises to scale AI coding tools with measurable control over software risk. Organizations can trace which AI models influenced specific commits, correlate that influence with vulnerability exposure, and take corrective action before insecure code reaches production.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Media Release
news-articles
March 17, 2026
March 17, 2026

Secure Code Warrior Launches Trust Agent: AI to Enable Safe, Scalable AI-Driven Development

New AI Software Governance solution makes AI-generated code visible at commit, enforces policy before production, and connects real development behavior to measurable risk reduction.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
March 13, 2026
March 13, 2026

Security Boulevard: Threat Modeling with AI: A Developer-Driven Boon for Enterprise Security

Developers have long struggled to truly claim a seat at the table in traditional threat modeling programs, but with the right skills, they have the opportunity to wield AI responsibly to seriously cut risk and rework in their codebase.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
March 9, 2026
March 9, 2026

The AI Journal: Understanding LLM Coding Personalities Is Now Key to Developer Risk Management

AI-generated code may be “made by machine”, but taking a cookie-cutter approach to securing that code would fall well short of mitigating the vulnerabilities LLMs can introduce. Organizations need to establish precise security reviews, with human developers anchoring the process to implement effective security controls while also managing the specific coding temperament of each LLM used. AI-generated code must undergo the same personalized risk assessments as code written by human developers.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
March 2, 2026
March 2, 2026

SecurityBrief: The security challenges in AI-assisted software development

s artificial intelligence (AI) tools become more widely used in the software development process, their impact on security is becoming clearer. According to recent research, nearly 70% of organisations have discovered vulnerabilities caused by AI tools while one in five have experienced a serious incident as a result of those vulnerabilities.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
March 2, 2026
March 2, 2026

KBI Media: Eliminating the Technical Debt Caused by AI-Assisted Software Development

According to research company Forrester[1], the tech debt for 75% of organisations will increase to a moderate or high level during this year, due to the rapid expansion of AI usage across a range of areas including software development.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
February 20, 2026
February 20, 2026

Forbes: Security Self-Governance: Addressing The Regulatory Gap In AI-Assisted Software Development

While it’s early into 2026, we’re seeing new research that reveals the extent of cyber risks caused by artificial intelligence (AI)-assisted software development: Nearly 7 in 10 organizations have discovered vulnerabilities introduced by AI-generated code, and 1 in 5 have suffered a serious incident tied directly to the vulnerabilities.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
February 19, 2026
February 19, 2026

ITWire: Why AI Is Dulling Cybersecurity’s Most Important Edge

Artificial intelligence (AI) has rapidly become indispensable to modern software development. From large language models that generate code on demand to agentic systems that automate entire workflows, AI tools promise dramatic gains in productivity and efficiency.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
February 12, 2026
February 12, 2026

SecurityWeek: How to Eliminate the Technical Debt of Insecure AI-Assisted Software Development

Developers must view AI as a collaborator to be closely monitored, rather than an autonomous entity to be unleashed. Without such a mindset, crippling tech debt is inevitable.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
February 9, 2026
February 9, 2026

CSO Online: Software developers: Prime cyber targets and a rising risk vector for CISOs

From technical compromise to AI-driven attacks, cyber criminals increasingly see software developers as prime targets, creating systemic risks CISOs must address.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
January 30, 2026
January 30, 2026

SMBtech: Tech Industry Leaders React To Data Privacy Week 2026

It’s Online Privacy Week, a time of year where individuals and organisations are all reminded to check their digital footprint(s). Some might say that’s a futile gesture at a time where major social media and marketing players know absolutely everything about you and are cheerfully selling all that data to anyone who’ll buy it; when Microsoft is performing every trick in the book to get Windows users to put all their data in the cloud where it’s available for government agencies to snoop upon without letting you know; when a personal computer crisis means many people will be moved on to dumb-client computing landscape where everything from data storage to major processing tasks will be taking place in the cloud; and when people think that clicking ‘Accept’ on website pop-ups does something that meaningfully protects them. But, what do the experts say?

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
January 29, 2026
January 29, 2026

Security brief: AI heightens data privacy risks & reshapes digital trust

Technology and data specialists have warned that artificial intelligence and weak data governance are sharpening privacy risks for organisations, as businesses mark World Data Privacy Day.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
January 27, 2026
January 27, 2026

ITWire: Data Privacy Week 2026

“Data Privacy Week" presents a great reminder for organisations to reassess their customer privacy policies and prioritise transparent data collection in their marketing strategies.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
January 27, 2026
January 27, 2026

Dynamic Business: Data Protection Day 2026: Five experts on the privacy risks threatening your business

Five leading cybersecurity experts warn AI is being integrated faster than security policies can manage the risk, creating urgent privacy gaps for SMEs ahead of Data Protection Day on 28 January.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
January 22, 2026
January 22, 2026

Information Security Buzz: OWASP Top 10 2025: New Enemies, Old Foes, and an Approach to Vulnerability Remediation That Must Evolve

The OWASP Foundation has been a guiding light for security professionals and enthusiasts alike, providing critical, practical advice on the most insidious software vulnerabilities across a plethora of categories and platforms. It has been the first major update since 2021 to the flagship OWASP Top 10 Web Vulnerabilities, and in that time, the industry has been rocked by a stampede of AI technology, tools, and code, each creating a dichotomy of security efficiency and risk for both cybersecurity and software engineering professionals.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
January 22, 2026
January 22, 2026

DEVOPSdigest: What Software Developers Need to Know About Secure Coding and AI Red Flags

The bottom line: AI tools are not safe for enterprise use unless the code output is reviewed and implemented by a security-proficient human. 30% of security experts admit that they don't trust(link is external) the accuracy of code generated by AI itself. That's why security leaders must prioritize the education and upskilling of developer teams, to ensure they have the necessary skills and capabilities to mitigate AI-assisted code vulnerabilities as early as possible. This will lead to the cultivation of a "security first" team culture and safer AI use.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
January 15, 2026
January 15, 2026

Stack Overflow: If you're a Zoomer, this one's for you: Everything Gen Z needs to know about the 2025 tech landscape

Here's the lowdown on all the tech from 2025 that you, dear Zoomer, should know about.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
January 15, 2026
January 15, 2026

SC Media: CISOs can’t wait for the EU AI Act to take shape

CISOs hoping for the EU Artificial Intelligence Act to offer a solid framework for AI governance may be a little confused or disappointed by recent updates surrounding the implementation of AI restrictions.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
January 14, 2026
January 14, 2026

SecurityBrief: Agentic AI double agents expose dangerous security gaps

An alleged nation-state attacker used Claude Code and a range of tools in the developer ecosystem to almost autonomously target specific companies with benign open-source hacking tools at scale. Of the more than thirty attacks, several were successful, and proved that AI agents could indeed execute large-scale, malicious tasks with little to no human intervention.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
January 14, 2026
January 14, 2026

DEVOPSdigest: 2026 DevSecOps Predictions

DEVOPSdigest's Prediction Series continues with 2026 DevSecOps Predictions — Industry experts offer predictions on how DevSecOps will evolve and impact the industry in 2026.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
January 12, 2026
January 12, 2026

ITWire: OWASP Names Latest Top 10 Application Vulnerabilities

The Open Worldwide Application Security Project (OWASP) has unveiled its latest top 10 vulnerabilities list, and it contains some surprising insights into important vulnerability classes.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
December 24, 2025
December 24, 2025

Channel Insider: Cybersecurity Experts Predict AI, Nation-State Threats in 2026

Cybersecurity experts outline 2026 predictions, from AI-driven attacks and quantum risk to nation-state threats, OT security gaps, and automation pressures.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
December 15, 2025
December 15, 2025

Security Journal UK: The rise of AI coding tools and the skills gap they expose

Pieter Danhieux, Co-founder and CEO of Secure Code Warrior warns that while AI coding tools promise speed and efficiency, they also introduce new risks.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
December 15, 2025
December 15, 2025

ITWire: Predictions on State of AI in 2026

2026 is shaping up to be the year AI evolves from instrument to partner, transforming how we work, create and solve problems.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
December 15, 2025
December 15, 2025

Fortune: AI coding tools exploded in 2025. The first security exploits show what could go wrong

While a breach of the tools hasn’t so far caused a wide-scale attack, there have been a few exploits and near-misses, and cyberthreat researchers have discovered critical vulnerabilities in several popular tools that make clear what could go horribly wrong.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
December 10, 2025
December 10, 2025

SMBtech: Australian Tech Industry Leaders Make Their Predictions for 2026

It’s that time of year where the technology industry predictions start rolling-in. Here’s what you can (apparently) expect in 2026.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
December 9, 2025
December 9, 2025

Technology Decisions: The importance of effective security when deploying AI tools

The concern is straightforward: development teams may place undue confidence in AI tools that are not equipped to interpret the nuanced context in which many security vulnerabilities arise. Large language models, for instance, can struggle to understand an application’s authentication or authorisation architecture, increasing the likelihood of missing critical safeguards.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
December 8, 2025
December 8, 2025

ITWire: Five Steps to Improve the Security of AI Developed Code

Industry guidance on managing the risks of AI-generated code increasingly points to the same conclusion: effective safeguards rely on close collaboration between humans and machines, with developers remaining firmly in the loop.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
December 1, 2025
December 1, 2025

SecurityBrief Australia: Agentic AI to transform APJ businesses & security by 2026

Agentic artificial intelligence (AI) is set to reshape the enterprise landscape in the Asia-Pacific and Japan (APJ) region in 2026, according to industry executives. Organisations are expected to embrace increasingly autonomous software agents, raising both productivity and new categories of risk across business domains.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
December 1, 2025
December 1, 2025

SC Magazine UK: Why Firms Can’t Ignore Agentic AI

How big a threat does agentic AI pose to businesses currently? And what should security leaders be doing to address the risk?

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
November 25, 2025
November 25, 2025

VMBlog: Cybersecurity Predictions: What AI will (and won't) do for us in 2026

My co-founder and CTO, Matias Madou, Ph.D., and I consulted our crystal ball (or should that be our NVIDIA GPUs?), and this is what we believe 2026 has in store for us from an AI security perspective.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
November 21, 2025
November 21, 2025

SD Times: Pumping the Brakes on Agentic AI Adoption in Software Development

An alleged nation-state attacker used Claude Code and a range of tools in the developer ecosystem, namely Model Context Protocol (MCP) systems, to almost autonomously target specific companies with benign open-source hacking tools at scale. Of the over thirty attacks, several were successful, and proved that AI agents could indeed execute large-scale, malicious tasks with little to no human intervention. Maybe it’s time we went a little slower, stopped to reflect on what is at stake here, and how best to defend ourselves.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
November 20, 2025
November 20, 2025

AIthority: Building Secure and Ethical AI Practices in Software Development

AI is now a key piece of modern software development. More than four out of five developers use AI coding tools daily or weekly – with many relying on multiple tools in parallel. Teams must understand where automation ends, and where accountability begins.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
November 18, 2025
November 18, 2025

SC Media: Secure Coding as Critical Thinking Instead of Vulnspotting – Matias Madou – ASW #357

Secure code should be grounded more in concepts like secure by default and secure by design than by “spot the vuln” thinking. Matias Madou shares his experience in secure coding training and the importance of teaching critical thinking. He also discusses why critical thinking is so closely related to threat modeling and how LLMs can be a tool for helping developers get beyond the superficial advice of, “Think like an attacker.”

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
November 17, 2025
November 17, 2025

Forbes: How CISOs Can Increase Their Influence In AI-Obsessed Boardrooms

Organizations are at an inflection point driven by the explosive adoption of AI, which promises significant changes in how businesses operate. That leaves CISOs on unsteady ground. As the gatekeepers of their organization’s data and access, they must ensure the security of the enterprise. However, the prospects of a headlong charge into wide-ranging, and possibly unchecked, use of AI could create a flood of security issues that many CISOs, under their current organizational structures, aren’t equipped to handle.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
November 14, 2025
November 14, 2025

Security Boulevard: Security Degradation in AI-Generated Code: A Threat Vector CISOs Can’t Ignore

Security leaders and developers alike are already acutely aware that AI coding assistants and agentic agents can introduce vulnerabilities into the code they generate. A recent study unveiled another critical concern to keep them up at night — LLMs used for making iterative code improvements may introduce new vulnerabilities over time, even when explicitly asked to make code more secure.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
November 13, 2025
November 13, 2025

Information Week: Make your own mandate: How CISOs can implement GenAI governance

Government bodies are trying to develop rules and regulations for safe AI use, but enterprises can't afford to wait. They need to address the risks now.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
November 12, 2025
November 12, 2025

CFOtech Australia: How women can continue to foster fulfilling high-tech careers in the AI age

In the sphere of cybersecurity in general and application security in particular, human oversight remains an absolute 'must' to harness the benefits of AI productivity.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
November 11, 2025
November 11, 2025

Tanium: Vibe coding may be unstoppable—but here’s how to rein in the risks

Like the meteoric rise of ChatGPT, vibe coding is all anybody can talk about this year. In fact, it just became a word in the dictionary. But beware the boom: These new AI coding tools offer speed, savings—and astounding vulnerabilities.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
November 11, 2025
November 11, 2025

[PODCAST] Stack Overflow: AI code means more critical thinking, not less

Ryan is joined by Secure Code Warrior’s co-founder and CTO Matias Madou to discuss the implications of LLMs’ variability on code security, the future of developer training as AI coding assistants become more popular, and the importance of critical thinking—especially for junior developers—in the age of AI.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
November 9, 2025
November 9, 2025

Cybersecurity Insiders: Use It or Lose It: Overreliance on AI Diminishes Critical Cybersecurity Thinking Skills

Software developers reap a host of benefits from making use of artificial intelligence assistants, whether in the form of Large Language Model (LLM) code creators or agentic AI agents. But recent reports, highlighted by a new study at MIT, warn that heavy use of AI can result in a loss of critical thinking skills among users.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
November 3, 2025
November 3, 2025

Security Week: How Software Development Teams Can Securely and Ethically Deploy AI Tools

To deploy AI tools securely and ethically, teams must balance innovation with accountability—establishing strong governance, upskilling developers, and enforcing rigorous code reviews.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
November 3, 2025
November 3, 2025

Dark Reading: AI Developed Code: 5 Critical Security Checkpoints for Human Oversight

To write secure code with LLMs developers must have the skills to use AI as a collaborative assistant rather than an autonomous tool, Madou argues.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
October 23, 2025
October 23, 2025

Techstrong.tv: Secure Code Warrior in the Age of AI with Pieter Danhieux

Secure Code Warrior’s Chief Executive Officer, Chairman, and Co-Founder Pieter Danhieux explains his transition from offensive cybersecurity to promoting secure software development. Founded in 2015, Secure Code Warrior aims to help developers build secure code from the start, a practice Danhieux and host Alan Shimel agree is more effective than fixing vulnerabilities later. The two also discuss the impact of AI on software development, noting that while AI increases coding speed and accessibility for more people, the security of AI-generated code still lags. They emphasize the growing need for developers to master secure coding practices amidst these technological advancements.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
October 20, 2025
October 20, 2025

SMBtech: Cybersecurity Awareness Month 2025: Australian Industry Reactions and Commentary

October is Australia’s Cybersecurity Awareness Month, the annual reminder for Aussies to stay vigilant online. This year’s theme, ‘Building our cyber safe culture’ once again highlights the importance of taking personal responsibility for staying secure in an increasingly digital world.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
October 16, 2025
October 16, 2025

SecurityBrief: SMEs urged to cut data & boost cyber defences as attacks rise

Cybersecurity Awareness Month has brought renewed attention to the increasing risks faced by organisations of all sizes, with a particular focus on the growing threat to small and medium-sized enterprises (SMEs) in Australia and the UK.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
October 14, 2025
October 14, 2025

ITBrief: Our biggest security risk isn’t our software - it’s our thinking

In the world of cybersecurity, we face creative and unconventional threats every day. But our greatest vulnerability isn't a flaw in our software, but a flaw in our collective thinking.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
October 10, 2025
October 10, 2025

KBI Media: Overcoming the Security Risks of Using AI In Software Development

Development teams face relentless pressure to deliver, yet they must continue to prioritise building secure, high-quality software. Leaders play a crucial role in reinforcing how a Secure by Design approach, supported by observability, benchmarking, and ongoing education, directly enhances code quality. By embedding these practices, organisations can close governance gaps and fully capture the benefits of AI-driven productivity and efficiency, while reducing the risk of security flaws or costly rework during the SDLC.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
October 1, 2025
October 1, 2025

In AI Today: The looming security challenges posed by Agentic AI

While agentic AI holds the promise of delivering significant business benefits, it also comes with significant caveats. The technology’s capabilities and autonomy present a potent enterprise threat vector beyond the realm of existing security concerns.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
September 25, 2025
September 25, 2025

Help Net Security: Secure Code Warrior gives CISOs visibility into developer AI tool usage

Secure Code Warrior has launched a beta program to expand the AI capabilities of its Trust Agent product. The new offering provides CISOs with security traceability, visibility, and governance over developers’ use of AI coding tools.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
September 25, 2025
September 25, 2025

Cyber Risk Leaders: Secure Code Warrior Launches AI Traceability

Secure Code Warrior have released a beta program for a major expansion of AI capabilities within its Trust Agent product. The upgrade, collectively referred to as Trust Agent: AI, leverages a combination of key signals, including AI coding tool usage, vulnerability data, code commit data and developer secure coding skills, to provide visibility into how AI development tools are impacting risk within the software development lifecycle (SDLC).

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
September 25, 2025
September 25, 2025

CSO Online: AI coding assistants amplify deeper cybersecurity risks

Although capable of reducing trivial mistakes, AI coding copilots leave enterprises at risk of increased insecure coding patterns, exposed secrets, and cloud misconfigurations, research reveals.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Media Release
news-articles
September 24, 2025
September 24, 2025

Secure Code Warrior Launches Industry-First AI Traceability to Enable Secure Developers and Supercharge Safe Productivity

New capabilities in SCW Trust Agent provide visibility and control over LLM usage for security leaders and CISOs.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
September 24, 2025
September 24, 2025

ITOps Times: Secure Code Warrior announces new solution that provides visibility and governance for AI coding tools

Secure Code Warrior is trying to provide organizations with greater visibility and control over developers’ use of AI coding tools with the launch of its new solution, Trust Agent: AI.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
September 24, 2025
September 24, 2025

DevOps Digest: Secure Code Warrior Introduces AI Traceability

Secure Code Warrior announced the launch of a beta program for a major expansion of AI capabilities within its Trust Agent product.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
September 24, 2025
September 24, 2025

CyberWire: Business Briefing for 09.24.25

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
September 24, 2025
September 24, 2025

Betanews: AI is an even playing field -- how secure by design can tip the scale [Q&A]

Vibe coding is currently all the rage, with more than 97 percent of respondents to a survey earlier this year reporting having used AI coding tools at work. The adoption of these tools only continues to grow but it comes with a catch, attackers are also employing the same techniques. We spoke to Pieter Danhieux, co-founder and CEO of Secure Code Warrior, to discuss how vibe coding is redefining the software development landscape, how malicious actors are also leveraging this technology and the need for organizations to implement secure by design strategies from the outset.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
September 22, 2025
September 22, 2025

SD Times: Benchmarking AI-assisted developers (and their tools) for superior AI governance

If the tech stack lacks tools that oversee not only developer security proficiency, but also the trustworthiness of approved AI coding companions each developer uses, then it is likely that efforts to uplift the overall security program and the developers working within it will be short of the appropriate data insights to effect change.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
September 22, 2025
September 22, 2025

ITWire: The Benefits and Risks of Using AI Tools in Software Development

The process of software development is undergoing a period of expedited change. Thanks to massive advances in artificial intelligence (AI) technology, projects can be completed more rapidly and by people with little or no prior experience.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
September 10, 2025
September 10, 2025

LeadDev: Ethics are being forgotten as the AI race heats up

Is the tech industry capable of the change needed to curb ethical and environmental concerns?

Learn More
No items found.
No items found.
This is some text inside of a div block.
Media Release
news-articles
September 9, 2025
September 9, 2025

Secure Code Warrior Expands Commitment to Secure by Design Best Practices with Free Secure Code Video Series for Developers

Launch of new 12-week video series on AI/LLM security empowers developers to safely adopt AI coding and mitigate emerging security risks.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
September 9, 2025
September 9, 2025

CSO Online: When AI nukes your database: The dark side of vibe coding

As developers lean on Copilot and GhostWriter, experts warn of insecure defaults, hallucinated dependencies, and attacks that slip past traditional defenses.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
September 8, 2025
September 8, 2025

The AI Journal: Resilience and Developer Risk Management: Two Pillars of Success in the Era of Secure by Design and AI Coding

Change is afoot in cybersecurity governance, and it couldn’t come at a more transformative time for security leaders worldwide. The White House issued a recent Executive Order (EO) designed to “reprioritize cybersecurity efforts to protect America”, and with it, reduce friction related to overzealous government oversight to focus on protecting critical digital assets and enhanced secure technology practices. Coupled with significant cuts to CISA, one could be forgiven for being apprehensive of the right approach going forward, especially in the wake of rapid AI technology progression and Secure by Design initiatives.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
September 5, 2025
September 5, 2025

SecurityWeek: How to Close the AI Governance Gap in Software Development

Widespread adoption of AI coding tools accelerates development—but also introduces critical vulnerabilities that demand stronger governance and oversight.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
September 3, 2025
September 3, 2025

teiss: When regulations aren’t enough

Pieter Danhieux at Secure Code Warrior explains why “Secure by Design” has emerged as mission critical for software development

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
September 2, 2025
September 2, 2025

Information Age: Vibe coding is a hot skill – and security experts are worried

GenAI tools are building insecure apps faster than ever.

Learn More
No items found.
No items found.
This is some text inside of a div block.
News Article
news-articles
August 26, 2025
August 26, 2025

CXFocus Magazine: Going above and beyond in 2026

Today’s customers are an exacting lot with little tolerance for suppliers that fail to meet their ever-increasing expectations. Almost 94 per cent of Australian consumers stopped purchasing from at least one company after a negative experience, according to CPM’s 2025 The State of Customer Experience in Australia Report.

Learn More
No items found.
No items found.
This is some text inside of a div block.
eBook
downloads
July 21, 2026
July 21, 2026

Which AI Model Codes Most Securely?

See how 16 leading AI models actually code, scored across 11 real-world frameworks and 1,760 codebases — the framework matters as much as the model.

Learn More
No items found.
No items found.
This is some text inside of a div block.
One Pager
downloads
July 7, 2026
July 7, 2026

Citizen AI by Secure Code Warrior

AI risk doesn't stop at engineering. Get the one-pager on Citizen AI — build AI literacy and safe habits across your whole workforce.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
June 23, 2026
June 23, 2026

Understand how AI is transforming software development—and how security must evolve with it.

From AI autocomplete to autonomous agents—explore how software development is evolving and what it means for security, governance, and your team.

Learn More
No items found.
No items found.
This is some text inside of a div block.
One Pager
downloads
June 9, 2026
June 9, 2026

SCW named in new Agentic Coding Security category

Gartner named SCW twice in the 2026 Hype Cycle for Secure Software Engineering. Here's why it matters for AI-driven development.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Guide
downloads
May 15, 2026
May 15, 2026

SCW Learning Content for KnowBe4

Secure Code Warrior content available through KnowBe4 helps technical teams build secure coding and AI governance awareness through structured learning covering OWASP Top 10 risks, AI-assisted development, and modern secure coding practices.

Learn More
No items found.
No items found.
This is some text inside of a div block.
One Pager
downloads
May 13, 2026
May 13, 2026

Secure AI-driven development with KnowBe4 + Secure Code Warrior

Secure Code Warrior joins KnowBe4 to bring hands-on secure coding training into security awareness programs — covering OWASP, AI development, and 10 languages.

Learn More
No items found.
No items found.
This is some text inside of a div block.
One Pager
downloads
April 1, 2026
April 1, 2026

Trust Agent:AI - Secure and scale AI-Drive development

AI is writing code. Who’s governing it? With up to 50% of AI-generated code containing security weaknesses, managing AI risk is critical. Discover how SCW's Trust Agent: AI provides the real-time visibility, proactive governance, and targeted upskilling needed to scale AI-driven development securely.

Learn More
No items found.
No items found.
This is some text inside of a div block.
One Pager
downloads
March 23, 2026
March 23, 2026

The Power of OpenText Application Security + Secure Code Warrior

OpenText Application Security and Secure Code Warrior combine vulnerability detection with AI Software Governance and developer capability. Together, they help organizations reduce risk, strengthen secure coding practices, and confidently adopt AI-driven development.

Learn More
No items found.
No items found.
This is some text inside of a div block.
One Pager
downloads
March 19, 2026
March 19, 2026

Secure Code Warrior corporate overview

Secure Code Warrior is an AI Software Governance platform designed to enable organizations to safely adopt AI-driven development by bridging the gap between development velocity and enterprise security. The platform addresses the "Visibility Gap," where security teams often lack insights into shadow AI coding tools and the origins of production code.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Brochure
downloads
March 11, 2026
March 11, 2026

Secure code training topics & content

Our industry-leading content is always evolving to fit the ever changing software development landscape with your role in mind. Topics covering everything from AI to XQuery Injection, offered for a variety of roles from Architects and Engineers to Product Managers and QA. Get a sneak peek of what our content catalog has to offer by topic and role.

Learn More
No items found.
No items found.
This is some text inside of a div block.
One Pager
downloads
January 20, 2026
January 20, 2026

Cyber Resilience Act (CRA) Aligned Learning Pathways

SCW supports Cyber Resilience Act (CRA) readiness with CRA-aligned Quests and conceptual learning collections that help development teams build the Secure by Design, SDLC, and secure coding skills aligned with the CRA’s secure development principles.

Learn More
No items found.
No items found.
This is some text inside of a div block.
eBook
downloads
December 23, 2025
December 23, 2025

OWASP Top 10 2025 eBook

Want to dominate the OWASP Top 10? Download the No-BS Guide to Defending Your Applications Against the OWASP Top 10:2025

Learn More
No items found.
No items found.
This is some text inside of a div block.
One Pager
downloads
September 24, 2025
September 24, 2025

Trust Agent: AI by Secure Code Warrior

This one-pager introduces SCW Trust Agent: AI, a new set of capabilities that provide deep observability and governance over AI coding tools. Learn how our solution uniquely correlates AI tool usage with developer skills to help you manage risk, optimize your SDLC, and ensure every line of AI-generated code is secure.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
July 9, 2025
July 9, 2025

AI Coding Assistants: A Guide to Security-Safe Navigation for the Next Generation of Developers

Large language models deliver irresistible advantages in speed and productivity, but they also introduce undeniable risks to the enterprise. Traditional security guardrails aren’t enough to control the deluge. Developers require precise, verified security skills to identify and prevent security flaws at the outset of the software development lifecycle.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
April 28, 2025
April 28, 2025

Secure by Design: Defining Best Practices, Enabling Developers and Benchmarking Preventative Security Outcomes

In this research paper, Secure Code Warrior co-founders, Pieter Danhieux and Dr. Matias Madou, Ph.D., along with expert contributors, Chris Inglis, Former US National Cyber Director (now Strategic Advisor to Paladin Capital Group), and Devin Lynch, Senior Director, Paladin Global Institute, will reveal key findings from over twenty in-depth interviews with enterprise security leaders including CISOs, a VP of Application Security, and software security professionals.

Learn More
No items found.
No items found.
This is some text inside of a div block.
One Pager
downloads
April 16, 2025
April 16, 2025

Turn Awareness Into Action This Cyber Awareness Month

This October, turn awareness into action. Make Cyber Awareness Month memorable for your developers with a high-impact, high-participation experience—led by Secure Code Warrior's Professional Services team.

Learn More
No items found.
No items found.
This is some text inside of a div block.
One Pager
downloads
April 2, 2025
April 2, 2025

Professional Services - Accelerate with expertise

Secure Code Warrior’s Program Strategy Services (PSS) team helps you build, enhance, and optimize your secure coding program. Whether you're starting fresh or refining your approach, our experts provide tailored guidance.

Learn More
No items found.
No items found.
This is some text inside of a div block.
One Pager
downloads
March 19, 2025
March 19, 2025

Quests: Industry leading learning to keep developers ahead of the game mitigating risk.

Quests is a learning platform that helps developers mitigate software security risks by enhancing their secure coding skills. With curated learning paths, hands-on challenges, and interactive activities, it empowers developers to identify and prevent vulnerabilities.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
October 15, 2024
October 15, 2024

Benchmarking Security Skills: Streamlining Secure-by-Design in the Enterprise

The Secure-by-Design movement is the future of secure software development. Learn about the key elements companies need to keep in mind when they think about a Secure-by-Design initiative.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Video
downloads
August 15, 2024
August 15, 2024

Trust Agent in action

SCW Trust Agent gives you the tools you need to deliver secure code faster, ensuring developers have the knowledge and skills to implement security best practices in the specific programming language of their code commits.

Learn More
No items found.
No items found.
This is some text inside of a div block.
One Pager
downloads
July 23, 2024
July 23, 2024

Trust Agent by Secure Code Warrior

Are you confident that every line of code committed is backed by a developer with the necessary secure coding skills? Many organizations face this critical gap, leading to preventable vulnerabilities and reduced development velocity. SCW Trust Agent offers unparalleled visibility across your code repositories, analyzing commits directly against developer security proficiency. With policy gates, Trust Agent enables you to apply governance at the commit level, with policies to ensure code contributors have the secure code knowledge you require for your business-critical applications. Download our one-pager today to learn how SCW Trust Agent can help you strengthen your security posture, optimize your development lifecycle, and significantly reduce vulnerabilities.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Video
downloads
June 28, 2024
June 28, 2024

SCW Trust Score - The best way to build, measure, and optimize your security program

Learn more about Secure Code Warrior Trust Score, the best way to build, measure and optimize your security program.

Learn More
No items found.
No items found.
This is some text inside of a div block.
One Pager
downloads
April 26, 2024
April 26, 2024

Trust Score by Secure Code Warrior

Discover SCW Trust Score, an industry-first benchmark to help measure your security program's effectiveness. Benchmark against industry peers, optimize your security posture, and drive data-driven decisions for enhanced software security.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
April 26, 2024
April 26, 2024

Preparing for PCI-DSS 4.0 Compliance

Evaluate your software security infrastructure to support PCI-DSS requirements

Learn More
No items found.
No items found.
This is some text inside of a div block.
Guide
downloads
April 5, 2024
April 5, 2024

The ultimate guide to security trends in financial services

Financial services institutions face an array of challenges that hinge on their ability to make efficient, effective use of technology in a fast-evolving financial world. Organizations are operating in a time of rapid changes—both internally and across the industry—in a highly competitive, cloud-based business environment. In pursuing their ongoing digital transformations, for example, organizations are working to get around the organizational friction that hinders investments into new technologies, such as artificial intelligence, that could accelerate payment processes and other procedures.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Report
downloads
March 24, 2024
March 24, 2024

Predicts 2024: Generative AI is reshaping software engineering

Explore how generative AI is revolutionizing software development across the SDLC, as highlighted in Gartner's report, advising Application Security leaders on the importance of scrutinizing AI-generated software.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
March 7, 2024
March 7, 2024

PCI DSS 4.0 Unraveled

This guide offers practical strategies to engage development teams in PCI DSS 4.0 compliance. It outlines the modern developer's requirements for compliance, strategies for security professionals and development managers to collaborate on developer-focused security programs, and step-by-step advice on effective training initiatives to mitigate vulnerabilities permanently.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Other
downloads
March 4, 2024
March 4, 2024

Developer security maturity quiz

Secure Code Warrior outlines three security maturity stages for developer teams: defining, adopting, and scaling. How security-savvy are your developers? Take our quiz to find out.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Other
downloads
February 22, 2024
February 22, 2024

Script Testing please ignore

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Infographic
downloads
February 1, 2024
February 1, 2024

ROI of Secure Code Learning

Explore the long-term ROI of secure coding education. Learn how investing in agile, proactive learning strategies enhances security and offers cost-effective protection against today's cyber threats.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
January 30, 2024
January 30, 2024

Why developers need security skills to effectively navigate AI development tools

The promise of artificial intelligence writing complex code at the touch of a button is intriguing, but the reality is that AI will need a lot of help from human developers to craft truly secure and reliable code.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Infographic
downloads
January 29, 2024
January 29, 2024

Top 10 predictions for 2024

Check out what SCW experts are predicting in the world of cybersecurity and software security in 2024.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
November 30, 2023
November 30, 2023

Agile learning platforms: ROI of developer-driven security

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
September 12, 2023
September 12, 2023

Forge your fortress: Six essential pillars of developer enablement in software security

In this white paper, security expert and Secure Code Warrior CTO & Co-Founder Matias Madou, Ph.D. will discuss:The six pillars you need to roll out effective security education and enablement for your development cohort. Lessons learned from ten executives implementing security programs at the enterprise level, and common pitfalls to avoid on your road to success.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Video
downloads
September 1, 2023
September 1, 2023

The Agile Learning Platform

Empower your development team with Secure Code Warrior, the agile learning platform designed to tackle the evolving challenges of application security. Stay ahead in the battle against security breaches and regulatory complexities with our industry-leading, up-to-date content, ensuring a proactive and engaging approach to secure code education.

Learn More
No items found.
No items found.
This is some text inside of a div block.
eBook
downloads
August 14, 2023
August 14, 2023

OWASP Top 10 API 2023: A tactical guide for smart developers

Explore the Latest in API Security. Dive into our 2023 OWASP Top 10 guide. Elevate your coding skills, tackle vulnerabilities, and stay agile in the ever-evolving world of API development. Download now for an insightful journey!

Learn More
No items found.
No items found.
This is some text inside of a div block.
eBook
downloads
July 17, 2023
July 17, 2023

The secure code learning blueprint

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
eBook
downloads
December 13, 2022
December 13, 2022

Your handbook to developer-driven security and agile learning

Start shifting left with developer-driven security. This handbook will show you how to engage with developers to upskill and increase their security knowledge, as well as how to go about measuring impact to write more secure code.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
July 28, 2022
July 28, 2022

Software is your colleague: A new perspective to strengthen access control and API security

APIs act like flawed humans; is treating them as such the key to better cybersecurity?

Learn More
No items found.
No items found.
This is some text inside of a div block.
eBook
downloads
July 21, 2022
July 21, 2022

The secure code training blueprint

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Infographic
downloads
July 1, 2022
July 1, 2022

The developer security maturity matrix

Building security maturity in development teams can be approached in stages. Based on our experience with 400+ organizations, we've identified common practices and traits in three different stages of security maturity - defining, adopting, and scaling.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
July 1, 2022
July 1, 2022

The importance of security maturity in developer teams

By assessing and understanding a development team’s security maturity, organizations can formulate a plan with the right stakeholders, process, and technology to build and support the necessary skills and capabilities.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Infographic
downloads
July 1, 2022
July 1, 2022

Development Team Security Maturity

Security maturity in development teams should be a continuous cycle of improvement with realistic goals along the way. As development teams increase their security maturity, they reduce the amount of rework and minimize risk, while also allowing automation to help create efficiency in the SDLC.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Report
downloads
June 30, 2022
June 30, 2022

Report: The state of developer driven security 2022

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
June 30, 2022
June 30, 2022

Whitepaper: The challenges (and opportunities) to improve software security

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Brief
downloads
June 20, 2022
June 20, 2022

Brief: A cohesive approach to developer-led security

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Other
downloads
June 16, 2022
June 16, 2022

Security and privacy at Secure Code Warrior

Secure Code Warrior is committed to safeguarding our information assets, and those of our customers, against misuse, abuse or compromise. We adopt and foster a risk-based approach to managing information security, with the goal of consistently implementing appropriate risk management and mitigation measures to address the threat landscape posed to the security of the platform, customer data and information. As Secure Code Warrior continues to succeed as a major player providing services to our customers, we will continue to build security capabilities as part of our security and privacy programs. Read our whitepaper for more information.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Brief
downloads
May 3, 2022
May 3, 2022

Shift left (and achieve compliance) with repeatable secure coding skills

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Brief
downloads
May 3, 2022
May 3, 2022

Defining secure code

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
February 17, 2022
February 17, 2022

Why you need more than scanning tools to create secure code

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
eBook
downloads
February 14, 2022
February 14, 2022

Your guide to defense against the dark art of zero-day attacks

Zero-day attacks can be the stuff of nightmares, but when an organization commits to using all available tools in their security arsenal towards a preventative strategy, security professionals can sleep a little easier.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Guide
downloads
January 14, 2022
January 14, 2022

A plan to upskill and engage your developers

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
January 13, 2022
January 13, 2022

The preventative, developer-driven approach to software security

Learn more about how security-aware developers represent a vast and largely untapped resource that can support cyber defenses by consistently standing against modern threats.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
November 11, 2021
November 11, 2021

Security and Privacy Whitepaper

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Other
downloads
October 19, 2021
October 19, 2021

Convince Your CISO/CTO Kit (for starting a demo)

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
eBook
downloads
September 24, 2021
September 24, 2021

OWASP Top 10 API: Strategies for Smart Developers

Download the practical guide to defeating common API security baddies in your code.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Guide
downloads
September 20, 2021
September 20, 2021

How to unify your security and development teams to stand together against security risk

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
August 4, 2021
August 4, 2021

How AppSec can reduce vulnerabilities and achieve compliance - leaving them free to tackle larger beasts

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Guide
downloads
July 28, 2021
July 28, 2021

Buyers Checklist: Secure Development Learning Platforms

Buyer’s Checklist: Secure Development Learning Platforms is aimed at decision makers and technology buyers looking to evaluate secure development learning platforms.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Other
downloads
July 18, 2021
July 18, 2021

Shared Assessments SIG Lite Questionnaire

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Other
downloads
July 18, 2021
July 18, 2021

SCW Pen Test Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Other
downloads
July 18, 2021
July 18, 2021

SCW Cyber Insurance Certificate

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
June 4, 2021
June 4, 2021

Shifting from reaction to prevention: The changing face of software security 2021 - Whitepaper

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
June 3, 2021
June 3, 2021

Cybersecurity Executive Order: A deliberate approach to improve software security with developer skills

While this Executive Order for touches on many aspects of functional cybersecurity, it specifically outlines, for the first time, the impact of developers, and the need for them to have verified security skills and awareness.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Other
downloads
May 18, 2021
May 18, 2021

FSQS-NL Certificate

Secure Code Warrior is now FSQS-NL registered. This registration is an important milestone in our continuous efforts to being compliant with regulations within the financial industry.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Other
downloads
May 17, 2021
May 17, 2021

Platform Architecture Diagram

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Other
downloads
May 16, 2021
May 16, 2021

Information Security Policy

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Other
downloads
May 16, 2021
May 16, 2021

CAIQ Questionnaire

Secure Code Warrior has completed a publicly available Consensus Assessment Initiative Questionnaire (CAIQ), based on the results of our due diligence self-assessment.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
May 12, 2021
May 12, 2021

The DevSecOps Super Bowl: How security champions can support your team to victory against late-stage vulnerabilities

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
March 16, 2021
March 16, 2021

Executive Roundtable Whitepaper - Visma & Blue Prism

How has 2020 changed the way we look at software security, an executive roundtable with Visma.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Other
downloads
March 9, 2021
March 9, 2021

The women of mimmit koodaa movement dive into secure coding

Mimmit Koodaa (women who code in Finland) tell us about their secure coding experiences.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Other
downloads
March 9, 2021
March 9, 2021

Teams in a global financial institution go head-to-head in secure coding contest.

See how a global financial organization promoted the importance of securing their banking applications across the world. With fun interactive tournaments.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Brochure
downloads
February 15, 2021
February 15, 2021

Missions - Experience the impact of poor code in real-world simulations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Brochure
downloads
February 15, 2021
February 15, 2021

Courses - Build Secure Coding Skills and Competency

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Video
downloads
January 1, 2021
January 1, 2021

A Step-By-Step Guide to Tournaments

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
eBook
downloads
January 1, 2021
January 1, 2021

Your Battle Plan to Defeat the OWASP Top 10

The ten most common security vulnerabilities don’t stand a chance against secure development superheroes like you. This free eBook is your ultimate field guide to understanding each infamous entry in the OWASP Top 10 2021, gaining insight into how each bug operates.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
January 1, 2021
January 1, 2021

Triumph with OWASP and Secure Code Warrior Tournaments - Whitepaper

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Brochure
downloads
January 1, 2021
January 1, 2021

Tournaments - Build organizational awareness and developer engagement, making secure coding top of mind

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
eBook
downloads
January 1, 2021
January 1, 2021

The Infamous 8: Infrastructure as Code Vulnerabilities to Find and Fix

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
January 1, 2021
January 1, 2021

The Five-Step Road to DevSecOps Success: How AppSec Professionals Can Thrive in Their Dream Team

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Other
downloads
January 1, 2021
January 1, 2021

The Fastest and Easiest Way to Improve Your Software Security Program

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Guide
downloads
January 1, 2021
January 1, 2021

The Creative CISO's Guide to Transforming Their Security Program

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
January 1, 2021
January 1, 2021

Take the pain out of PCI-DSS Compliance Whitepaper

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Other
downloads
January 1, 2021
January 1, 2021

Introduction to Secure Code Warrior

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Whitepaper
downloads
January 1, 2021
January 1, 2021

Empowering developers to write secure code

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Brochure
downloads
January 1, 2021
January 1, 2021

Empower developers to be the first line of defense and grow your organization's security posture

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Brochure
downloads
January 1, 2021
January 1, 2021

Assessments - Benchmark the secure coding skills of your developers, and build your security posture.

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Guide
downloads
January 1, 2021
January 1, 2021

AppSec Checklist

Download the AppSec checklist and see if you’re in need of a security lifeline.

Learn More
No items found.
No items found.
This is some text inside of a div block.
eBook
downloads
January 1, 2021
January 1, 2021

6 Critical Steps Before You Roll Out a Security Uplift Program

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Other
downloads
January 1, 2021
January 1, 2021

2019 AppSec Trend Report

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Learn More
No items found.
No items found.
This is some text inside of a div block.
Other
downloads
December 1, 2019
December 1, 2019

ISO 27001 Compliance Certificate

Secure Code Warrior is ISO 27001:2013 certified

Learn More
No items found.
No items found.
This is some text inside of a div block.
No resources found. Try another search!