Insights from experts shaping secure development
Access expert content on secure coding, AI governance, and software risk management.
为何 SBOM 对准备《网络韧性法案》至关重要?
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
大型医疗保健提供商如何通过开发人员驱动的方法转型其安全文化
参加本次研讨会,听取 Contrast Security 联合创始人兼 CTO Jeff Williams 和 Secure Code Warrior 联合创始人兼 CTO Matias Madou 的分享。
嵌入式系统与赋能您的团队
物联网、生产系统的自动化控制和管理只是推动嵌入式系统发展的几个因素。但随着我们越来越依赖嵌入式软件,安全漏洞的影响是什么,我们又该如何缓解?
超越合规性:交付引人入胜的应用安全的技巧
您的开发团队是否将应用安全培训视为走过场?您是否希望他们更多地参与网络安全?本节将涵盖创建让开发人员主动参与的培训计划的技巧!
获得出色 SOC 2 报告的最佳实践
在接手 SOC 报告项目时,有时会感到非常不知所措。这就是为什么我们与一些行业专家合作,探讨获取 SOC2 报告时的一些顶级技巧。

2021 HMG Live! 硅谷 CISO 最高领导力峰会
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
研讨会:从 DevOps 到 DevSecOps:从一开始就交付质量与安全兼备的发展
我们的专家将讨论在 SDLC 中实施安全培训和应用安全的关键考虑因素,如何通过游戏化学习吸引开发人员,以及如何在没有任何停机时间或高昂成本的情况下嵌入安全测试。
课程演练 (Walkthroughs) 深入剖析
了解我们全新的演练与任务 (Walkthrough & Missions) 沉浸式实战培训活动如何通过经过验证的渐进式学习方法提高开发人员参与度并提升技能。
技能提升:填补 AppSec 安全差距的缺失环节
听取 Zip 安全主管 Peter Robinson 和 Secure Code Warrior 联合创始人兼 AppSec 培训师 Jaap Singh 的深入讨论,探讨为什么提升员工的网络安全技能对于填补安全差距至关重要。
开发人员驱动安全的投资回报率 (ROI)
在投资技术栈或额外培训计划时,每个人都希望获得良好的投资回报,但在安全方面,人们需要进行超越简单 ROI 计算的长远布局。了解对开发人员驱动安全的投资如何不仅能节省昂贵的漏洞费用,还能创造主动且具有成本效益的策略。
How to catch and fix a Guice dependency injection issue using Sensei
An example scenario for a misconfiguration of Guice, which may lead to a NullPointerException being reported at runtime during testing.

2021 年网络预警安全预测:星际之战开启
我们预计,2021年是我们将一种全新类型的太空竞赛纳入主流的一年:保护我们的银河系免受网络欢迎。

程序员征服安全 OWASP 十大 API 系列-资产管理不当
该漏洞更像是人为问题或管理问题,它允许旧的 API 在本应被更新、更安全的版本所取代之后很长一段时间内仍然存在。

修改 JUnit 5 的方法和类可见性
了解 Sensei 如何通过识别过时的模式并提示您提供后续使用的修复程序来帮助迁移。

我的渗透者,我的敌人?开发人员透露了他们对渗透测试和静态分析结果的真实想法
渗透测试和静态分析扫描工具(俗称 SAST)只是降低安全风险的整个过程的一部分,它们的运行完全独立于我们的工作——当然,直到代码返回给我们进行修复!

Automatically Adding a Private Constructor with Sensei
Learn how Sensei can identify a coding pattern, and automatically generate a private constructor to make it impossible to instantiate the class.

未来的工作是灵活的,对网络安全非常有利
无论不适感来自于未知的新工作方式、一点不信任,还是不相信远程办公,我都发现抵制远程办公的公司在吸引顶尖人才、保持全球影响力以及坦率地说,与时俱进方面往往会落后。
Improving A Personal Programming Process Using Sensei
Learn how to use code reviews on pull requests to help enforce coding styles. And shorten the feedback cycle when pair programming with a more experienced programmer.
Migrating to a Logger with Sensei
A quick example of creating a recipe to migrate from System.out.println to using a Java Logger.

程序员征服安全 OWASP 十大 API 系列-日志记录和监控不足
日志和监控不足的漏洞主要是由于网络安全计划失败造成的,该计划涉及记录所有失败的身份验证尝试、拒绝访问和输入验证错误。

任务简介:下一阶段以开发者为中心的安全培训
我们很高兴地宣布在 Secure Code Warrior 平台上发布全新功能:任务。这一全新的挑战类别是开发人员专属安全培训的下一阶段,它将用户从回忆安全知识转向将其应用于现实世界的仿真环境。

Coders Conquer Security OWASP 十大 API 系列-禁用安全功能/调试功能启用/权限不正确
它在 API 中可能更为普遍,但攻击者通常会尝试在网络中的任何地方发现未修补的漏洞和未受保护的文件或目录。遇到一个启用了调试或禁用了安全功能的 API 只会让他们的恶意工作变得容易一些。
Using Documentation Links with Sensei
Learn how Sensei can help onboard developers and adopt new libraries.

Sensei Product Update - September 2020
Learn all about the latest updates to Sensei.

使用重写操作向注释添加参数
通过注解匹配示例,学习如何使用 Sensei 来匹配有问题的代码模式,然后将其修改为商定的实现。

程序员服装安全 OWASP 十大 API 系列-大规格模任务业务
大规格模分配漏洞的产出是由于许多现代架构的鼓鼓鼓鼓的开发人员使用自动将来自客户端的输入绑定到代码变量和内部对象的函数。

澳大利亚政府如何建立国家网络安全抵御能力并挺身而出抵御威胁
从澳大利亚政府认真对待网络安全的努力中可以明显看出,网络安全已被确定为国家层面的关键风险领域,但是他们的战略是否足够深远?
What is Sensei?
The Sensei plugin provides an easy way to find specific code patterns in your source code, and then apply rewrite rules to amend the matching code. All within the Intellij IDE, and in real-time.

在 SSDLC 的每个阶段培养安全编码技能
Secure Code Warrior 开发了一个 GitHub Action,为GitHub代码扫描带来了情境学习。这意味着开发人员可以使用像 Snyk 容器操作这样的第三方操作来发现漏洞,然后通过 CWE 专用、高度相关的学习来增强输出。

程序员征服安全 OWASP 十大 API 系列-缺少功能级别访问控制
缺少的功能级别访问控制漏洞允许用户执行应受限制的功能,或者允许他们访问应受保护的资源。

全国网络安全宣传月:不仅仅是一次网络钓鱼探险
每个组织都可以利用网络安全宣传月来刷新他们的安全意识,今年,我们还为编程社区推出了一款新的免费应用程序!

程序员征服安全 OWASP 十大 API 系列-缺乏资源和速率限制
当同时传入的请求过多,且 API 没有足够的计算资源来处理这些请求时,就会出现此漏洞。然后,该 API 可能变得不可用或无法响应新请求。

ClickShare漏洞可能已被修补,但它们掩盖了一个更大的问题
将安全补丁转移回开发流程并不容易,但在当今世界中,即使是像演示工具这样看似简单的设备也非常复杂,而且还能与其他所有设备联网,这是必要的。

程序员征服安全 OWASP 十大 API 系列-数据泄露过多
该漏洞背后的实际机制与其他漏洞相似,但在这种情况下,过度数据泄露被定义为涉及受法律保护或高度敏感的数据。

程序员征服安全 OWASP 十大 API 系列-身份验证失效
身份验证通常既是应用程序的网关,也可能是通往网络其他部分的网关,因此它们是攻击者的诱人目标。如果身份验证过程中断或存在漏洞,攻击者很可能会发现该漏洞并加以利用。

专家访谈:奥斯卡·昆塔斯的《基础设施即代码》
我们想把焦点聚焦在我们的专家之一奥斯卡·昆塔斯身上。他是我们产品内容团队的一员,担任高级安全研究员。他还是我们在基础设施即代码 (IaC) 方面的常驻巫师。

程序员征服安全 OWASP 十大 API 系列-失效的对象级授权
通常,对于使用用户输入访问数据源的每个函数,都应包括对象级授权检查,不这样做会带来很大的风险。

Doki 之死:一个新的 Docker 漏洞,存在严重问题(以及你可以做些什么)
网络攻击越来越频繁,影响基于Linux的基础设施的威胁也变得越来越普遍,最终目标是有机会破解存储在云中的敏感数据的战利品箱。

您的组织真的为 DevSec 做好准备了吗?把它付诸测试。
考虑到您的组织,请在您的角色背景下考虑这些问题。接受 DevSec 测试时表现如何?

先出击,重拳出击:为什么精心策划的安全编程课程对网络威胁毫不留情
精心策划的课程包含开发人员需要表现出熟练程度所需的确切模块,这将产生强大的影响,并使他们在日常工作中掌握安全最佳实践时能够从头开始。

希望开发人员以安全意识编写代码吗?把训练带给他们。
我们已经知道工作日里有太多事情要做,那么开发人员需要什么动机去教室,或者切换情境,完成五个步骤才能获得基于静态理论的培训呢?

COVID-19 接触者追踪:安全编码情况如何?
接触者追踪应用程序背后的想法是合理的。这项技术如果运行良好,将确保迅速发现热点并进行全面测试,这两者都是对抗传染性病毒传播的重要组成部分。

别再打乱我的工作流程了!如何在正确的时间接受正确的安全培训
我们开始考虑我们可以做些什么来减少在你需要时接受培训的障碍,以及如何以更无缝的方式将微学习应用到你的工作流程中。

国际工程界女性日:认识我们的明星
6月23日是极客日历中的一个特别条目,旨在纪念国际工程界女性日。这是我们阐明女性对软件开发的贡献的机会。

程序员以代码的形式征服安全基础架构系列-商业逻辑
当程序员无法正确实现业务逻辑规则时,就会出现此漏洞,如果恶意用户选择利用这些规则,这可能会使他们的应用程序容易受到不同类型的攻击。

Rust 第五次成为最受欢迎的编程语言。这是我们的新安全救星吗?
Rust 融合了常用语言中的已知和功能元素,采用了一种不同的理念,既考虑了复杂性,又引入了性能和安全性。

程序员以代码的形式征服安全基础架构系列——使用来自不可信来源的组件
我们将在此重点讨论的诱发漏洞的行为是使用来自不可信来源的代码,这种看似良性的做法会造成重大问题。

网络犯罪分子正在攻击医疗保健(但我们可以反击)
医疗保健可能是下一个 “伟大” 的网络安全战场,犯罪分子攻击的正是诊断医疗问题、提供治疗和维持生命的机器。

程序员以代码的形式化服装安全基础架构系列:安全配置错误权限不正确
安全配置错误,尤其是权限不当的配置错误,通常发生在开发人员完成任务并创建新用户或本应用程序权限时。

程序员以代码的形式征服安全基础架构系列:传输层保护不足
有时,应用程序还会与其他程序共享数据,这是总体工作负载的一部分。除非传输层受到保护,否则它很容易受到外部监听和未经授权的内部查看。

程序员以代码的形式征服安全基础架构系列:不安全的密码学
如今,对诸如密码、个人信息和财务记录之类的关键数据进行哈希处理是任何网络安全防御的基石。

COBOL 应用程序开发安全 | 安全代码勇士
传统的 COBOL 虽然是一种较旧的计算机语言,但至今仍然有效。从 Secure Code Warrior 了解有关 COBOL 安全应用程序开发的更多信息。

程序员以代码的形式征服安全基础架构系列:密码的明文存储
如今,大多数计算机安全的关键都涉及密码。即使采用其他安全方法,例如双因素身份验证或生物识别,大多数组织仍将基于密码的安全性作为其保护要素之一。

网络研讨会:你准备好将 “安全” 引入 DevOps 了吗?
我们必须进入这样一个阶段,即安全被视为整个组织乃至整个 SDLC 的共同责任。当你承诺使用一个成熟的、高度支持的 DevSecOps 环境时,这肯定是可能的。

程序员以代码的形式征服安全基础架构系列:缺少功能级别访问控制
如果基础设施级别的访问控制不完善,它就会向攻击者开放整个企业,攻击者可以利用该漏洞作为未经授权的窥探或全面攻击的门户。

程序员以代码的形式征服安全基础架构系列:禁用的安全功能
攻击者总是会首先尝试找到易于利用的漏洞,甚至可能使用脚本来修复常见的漏洞。这与小偷检查街上的所有汽车以查看是否有门被解锁没什么不同,这比砸窗户容易得多。

将乏味的 PCI-DSS 合规性变成对每个人都有意义的练习:第 2 部分-首席信息安全官和开发人员意识
这是关于组织内PCI-DSS合规性的迷你系列的第二部分。在最后一章中,我们将详细介绍首席技术官和首席信息安全官如何从高层领导降低网络风险,使流程顺畅、成功... 也许还能为开发人员带来一点乐趣。

将乏味的 PCI-DSS 合规性变成对每个人都有意义的练习:第 1 部分-AppSec
这是关于组织内部成功合规 PCI-DSS 的系列文章的第 1 部分,共分为两部分。在本章中,我们将详细介绍 AppSec 专家如何与开发经理密切合作,以增强开发人员的能力,加强 SSDLC 并从一般立法中获得具体成果。

网络安全的未来:未来一年不会发生的事情
在我们的行业中,许多安全专家已经开始预测今年的热点问题,但是由于2019年有超过50亿条敏感数据记录被盗,我们认为预测在可预见的将来网络安全不会发生的事情会更加准确。

向左移动是不够的:为什么左移是实现卓越软件安全的关键
围绕 “向左移动” 的许多举措,即在开发过程的早期引入安全性,根本无法起到足够的作用。

DACH 中的 DevSecOps:安全编码试点计划的主要发现
随着GDPR的出台,以及在多阶段攻击暴露了许多公众人物以及德国联邦政府服务器的敏感数据之后的战略的修订,很明显,网络安全意识和行动是DACH地区领导人的头等大事。

如何成为一名出色的 DevSecOps 工程师
世界开始走过瀑布、敏捷和现在的 DevOps,那么下一个解决方案是什么?作为一名开发人员,你在跟上这些方法变化方面扮演什么角色?

2019年最危险的软件错误:更多历史重演的证据
去年年底,MITRE的精彩社区发布了2019年CWE影响全球的25大最危险软件错误清单。而且大部分都不足为奇。

快速增长:5 岁生日快乐,安全代码勇士
我本可以从所有事实和数据开始写这篇文章,说明一家蓬勃发展、高速增长的初创公司;不可否认,它们给人留下了深刻的印象,而且我们持续的公司发展轨迹也很强劲。但是,对我来说,这些数字并不能反映我在2019年最引以为豪的事情。

为什么 DevOps 实施经常不成功(以及如何修复它)
很少有公司能真正成功实施 DevOps。但是,在整个企业中提供正确的支持、培育和理解可以改变您的流程。

新的 NIST 指南:为什么定制培训对于创建安全软件至关重要
美国国家标准与技术研究所(NIST)发布了更新的白皮书,详细介绍了减少软件漏洞和网络风险的几项行动计划。

2019 年 OWASP AppSec 日:培训育安全开发人员
这些开发以人为中心的活动是日历上我最喜欢的活动之一;它们是 “卑斯地提醒” 社区不是 “地下人” 和 “增强” 软件工程师和专家的能力,使他们能够在工作中保持安全。

静态 vs.动态网络安全培训:冲动合规,未来问题
尽管监管举措无疑将随着时间的推移而得到改善和发展,但如果各组织现在已经按下了紧急按钮并开始接受培训,他们可能会发现自己没有为未来做好准备。

需要一个村庄:社区精神如何创造更安全的开发者
有来自各行各业的各种类型的开发人员,而且我们所做的每件事都具有社区意识。

深入的安全培训引发了教育方面的质疑
尽管安全编码需要成为高等教育阶段软件工程的必备组成部分,但一些大学从一开始就在提供一流培训和优先考虑安全性方面处于领先地位。p

安全领域的女性:聚焦 Fatemah Beydoun
我们的客户成功副总裁Fatemah Beydoun最近向非常乐于接受的听众发表了她的演讲,“指导未来:我们如何在培养女性网络安全人才方面做得更好”。她一直是推动网络安全行业积极变革不可或缺的一部分。

程序员征服安全:分享与学习系列-不安全的反序列化
每当应用程序将反序列化的数据视为可信数据时,就会发生不安全的反序列化。如果用户能够修改新重建的数据,他们就可以执行各种恶意活动,例如代码注入、拒绝服务攻击或提升权限。

情境式动手学习:训练大脑以增强安全性的强大方式
令人难以置信的是,许多地方仍然依赖教室、枯燥的教科书和乏味的视频培训来让自己的最佳和最聪明的人参与新举措,尤其是在有一种更好、更具吸引力、更有价值的学习方式:情境式培训时。

同情、感恩和保持谦虚:我们文化的基础
软件安全行业并不完全以其温暖而模糊的感受、异想天开的观察和生活评论而闻名,但是,也许随着年龄的增长,我发现自己正在反思我们所有人可能对世界产生的影响。

程序员征服安全:分享与学习系列——敏感数据泄露
每当仅供授权查看的信息在未加密、未保护或保护薄弱的状态下暴露给未经授权的人时,就会发生敏感数据泄露。

为什么我们需要支持而不是惩罚好奇的安全人员
青少年安全研究员比尔·德米尔卡皮揭露了学校使用的软件中的主要漏洞,这无疑让人回想起。我记得我还是个好奇的孩子,打开了软件的盖子,偷看下面,看看它是如何运作的... 以及我能否破解它。

全球大补丁:VxWorks 漏洞将危及数百万台设备
尽管对于普通消费者来说,VxWorks 并不是家喻户晓的名字,但这款软件产品每天都会使许多人受益,就像你我一样。现在,我们面临着数亿台基于VxWorks的设备遭到入侵的可能性。

程序员征服安全:分享与学习系列-XXE 注入
XML 外部实体注入攻击(有时简称为 XXE 注入)相对较新,但它目前在黑客社区中非常受欢迎,而且随着成功的积累,这种攻击甚至会越来越多。

程序员服装安全:分享与学员学习系列-CRLF 注入
如果攻击者可以在现实的应用程序中插入 CR 或 LF 代码,他们有时间可以对其行为进行改进。与大多数人攻击相比,其影响不太大,但对目标进行组织化的危险也同样严重。

富创造力的首席信息安全官员和首席信息官员如何创新和转变其安全计划
富有创造力、鼓舞人心的首席信息安全官员和首席信息官员能量创新,塑造我们的数字世界,但他们也可以改变变量组织的安全文明方面发作重要作用。

程序员征服安全:共享与学习系列-远程文件包含
在许多方面,远程文件包含漏洞比其本地文件漏洞危险得多,也更容易被利用。因此,应尽快找到并予以补救。

修订后的PCI安全标准委员会指南:它们向左移动得足够远吗?
今年,PCI安全标准委员会发布了一套全新的软件安全指南,作为其PCI软件安全框架的一部分。此更新旨在使软件安全最佳实践与现代软件开发保持一致。

Coders 征服安全:共享与学习系列-本地文件包含和路径遍历
与许多漏洞不同,利用本地文件包含和路径遍历过程实现恶意目的需要足够熟练的攻击者、相当长的时间,可能还需要一点运气。

程序员征服安全:分享与学习系列-传输层保护不足
即使您已经完全保护了应用程序服务器及其使用的后端系统,但如果传输层保护不足,通信仍可能容易受到窥探。

程序员征服安全:分享与学习系列-XML 注入
XML 注入攻击是黑客发明的令人讨厌的小漏洞,目的是帮助他们破坏托管 XML 数据库的系统。这包括人们在考虑传统数据库时想到的各种东西,即从药物到电影等任何事物的详细信息存储。

华为英国安全问题表明需要安全编码
英国华为网络安全评估中心最近的一份报告确定了华为软件工程流程中的主要安全问题。但这是一个可以解决的问题。

最佳早午餐:我们的 AppSec 领导者分享他们的智慧
针对诸如如何充分利用组织的 AppSec 预算等热点问题,以及听众提出的几个棘手问题,AppSec小组提供了一些真正的早间魔法,将帮助安全专家在其组织内制定可行的计划。

程序员征服安全:分享与学习系列-日志记录和监控不足
记录和监控不足是应用程序防御结构中可能存在的最危险的情况之一。如果存在此漏洞或情况,那么几乎所有针对它的高级攻击最终都会成功。

程序员征服安全:分享与学习系列-未经验证的重定向和转发
对能够处理未经验证的重定向和转发的网站或应用程序进行编码对您的用户和组织来说都极其危险。

安全代码勇士和漏洞人群:安全极客天堂的天作之合
这是官方消息:我们正在与Bugcrowd联手对开发人员进行安全编码方面的教育、赋权和启发。

程序员征服安全:分享与学习系列-代码注入
代码注入攻击是许多网站和应用程序将遇到的最常见,也是最危险的攻击之一。它们在复杂性和构成的危险方面无所不包,但是几乎所有接受用户输入的网站或应用程序都可能存在漏洞。

GitHub 用户因纯文本痛苦而被勒索赎金
最近对GitHub存储库的攻击凸显了安全行业中一个众所周知的问题:大多数开发人员根本不够安全意识,宝贵的数据随时可能面临风险。

程序员征服安全:分享与学习系列——访问控制失效
在构建业务应用程序时,无论是供客户内部使用还是外部使用,都可能不会让每个用户执行每一项功能。如果这样做,则可能容易受到访问控制中断的影响。

要了解网络安全最佳实践,请查看金融行业
随着网络攻击的增加——影响各个垂直领域的各类组织——代价高昂、令人尴尬和影响利润的数据泄露的威胁是真实存在的。问题不是变小,而是像肿瘤一样生长。

程序员服装安全:分享与学习系列——信息泄露
当你的网络应用程序泄露了很多信息时,它会使攻击者更容易进入这些信息。在这篇文章中,我们将介绍什么是信息泄露、它为何危险,以及如何防止。

程序员征服安全:分享与学习系列——使用存在已知漏洞的组件
由于所有应用程序都使用组件,其中大部分是您尚未编写的,因此您使用的组件中的漏洞可能会成为负担。让我们讨论使用具有已知漏洞的组件意味着什么,它有多危险,以及如何解决这个问题。

“安全” 不是一个脏话:积极的方法将如何改变你的安全计划
我一直站在两边,我非常清楚开发团队和AppSec专家之间在维护安全最佳实践方面可能出现的紧张关系。但是,有更好的方法。

程序员征服安全:分享与学习系列-身份验证
我们将介绍运营网站或允许员工远程访问计算机资源的组织(几乎是所有人)面临的最常见问题之一。是的,你可能猜到我们将要谈论身份验证。

程序员征服安全:分享与学习系列-反自动化不足
如果应用程序没有足够的反自动化检查,攻击者只需猜测密码直到找到匹配的密码即可。以下是阻止他们的方法。

程序员征服安全:分享与学习系列-业务逻辑问题
尽管编码问题可能是问题的一部分,但业务逻辑错误通常是由首次创建应用程序时的设计缺陷或错误的逻辑假设造成的。

DevSecOps:旧的安全漏洞仍在发挥新作用
在网络安全领域,我们通常就像猎人一样。我们的眼睛紧紧地注视着地平线,正在寻找下一个突破漏洞。但是,这种前瞻性的关注可能会产生令人惊讶的效果,削弱我们的整体安全意识。

程序员征服安全:分享与学习系列-电子邮件标题注入
网站和应用程序通常允许用户使用电子邮件通过应用程序发送反馈和其他各种信息。而且大多数人甚至没有从潜在的安全风险的角度来考虑这个问题。

程序员征服安全:分享与学习系列:不安全的直接对象参考
直接对象引用是指在应用程序中引用特定记录(“对象”)。它通常采用唯一标识符的形式,可能出现在 URL 中。

软件安全处于狂野西部(它会让我们被杀死)
软件安全一直是我的头等大事,我们日益数字化的个人信息共享生活方式所构成的真正危险也是如此。毕竟,我们处在一个基本上不受监管、无人监督、被忽视的领域。我们在狂野的西部。

不安全的加密存储和安全 | Secure Code Warrior
在这个数字社会中,开发人员有责任保护信息和企业免受不安全的加密存储的影响。向安全代码勇士学习。

程序员征服安全:分享与学习系列-XQuery 注入
绝大多数网站使用XML数据库来执行关键功能,例如保存用户登录凭证、客户信息、个人身份信息以及机密或敏感数据,这使得XQuery攻击的攻击足迹相当大。

什么是安全配置错误?| 安全代码战士
什么是安全配置错误?找出最常见的安全配置错误以及如何防止漏洞。向安全代码勇士学习。

Kamer van Koophandel Sets the Standard for Developer-Driven Security at Scale
Kamer van Koophandel shares how it embedded secure coding into everyday development through role-based certifications, Trust Score benchmarking, and a culture of shared security ownership.
Going for Gold: Soaring Secure Code Standards at Paysafe
See how Paysafe's partnership with Secure Code Warrior led to a 45% boost in developer productivity and a major reduction in code vulnerabilities.

DigitalOcean Decreases Security Debt with Secure Code Warrior
DigitalOcean's use of Secure Code Warrior training has significantly reduced security debt, allowing teams to focus more on innovation and productivity. The improved security has strengthened their product quality and competitive edge. Looking ahead, the SCW Trust Score will help them further enhance security practices and continue driving innovation.

Devlympics 2023: In Review
Explore the Devlympics 2023 results in this report. Dive into developer engagement, tech stack and languages trends in each industry that participated, and key vulnerabilities and CWEs covered in the annual global event hosted by Secure Code Warrior.

One Culture of Security: How Sage built their security champions program with agile secure code learning
Discover how Sage enhanced security with a flexible, relationship-focused approach, creating 200+ security champions and achieving measurable risk reduction.

The path to security champions: How Workday utilized agile learning to upskill developers
Discover how Workday transformed developer training with agile learning through Secure Code Warrior. By empowering developer with hands-on, language-specific education, Workday reduced vulnerabilities early in the SDLC. See their impressive results and key takeaways to build a secure code culture.

How Thales implemented developer-driven security
In this case study, learn how Thales has developed people, process, and technology approaches for an agile secure code learning program in order to engage developers to become active security champions.

How Colgate-Palmolive boosted developer security skills and created a secure coding culture
Discover how retail giant Colgate-Palmolive reshaped its application security during its digital transformation journey. Facing challenges in secure coding, they innovated their approach by integrating bite-sized, in-context learning into the developer workflow.

Security as culture: How Blue Prism cultivates world-class secure developers
Learn how Blue Prism, the global leader in intelligent automation for the enterprise, used Secure Code Warrior's agile learning platform to create a security-first culture with their developers, achieve their business goals, and ship secure code at speed
%252520%252520(3).avif)
Supercharged Security Awareness: How Tournaments are Inspiring Developers at Erste Group
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

How a ‘Game of Codes’ is leading IAG Group to a more secure coding future
IAG Group is the name behind many of the leading insurancecompanies in the Asia-Pacific region, underwriting policies formillions of customers to the tune of approximately AUD $11.4 Billionin premiums per annum.

Driving Actionable Awareness: FINRA's Push For Super-Secure Developers
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Creating a revolutionary security certification experience
Learn how they created an in-house technology education initiative, aimed at supporting thousands of employees to learn practical, cutting-edge skills in a number of disciplines, including machine learning and cybersecurity.
Beyond Compliance: Motorola Solutions Drives Winning Security Culture
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

ASRG's push for automotive software security
Explore this comprehensive case study to learn more about how they utilized Secure Code Warrior's tournaments to engage developers, increase awareness of key vulnerabilities affecting automotive software, and gain metrics across multiple languages and frameworks.
Application Security @ NAB | Gamified Security Training: The Key to Scalable Developer Growth
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Forbes: A New Frontier: NSA Proposes “Security By Design” Considerations For AI Enablement
The cybersecurity industry, which has been advocating for “security by design” principles for more than a decade, stands in wide-eyed amazement at the risks posed by artificial intelligence (AI). As organizations rush to embrace AI enablement, a CISO’s most pressing priority is to avoid becoming a roadblock. However, without effective AI usage and governance, observability and traceability, organizations may be blindsided by their AI risk.

Techpartner.news: Secure Code Warrior introduces framework to govern AI use in software development
Secure Code Warrior has introduced the SCW AI Adoption Model, a framework designed to help organisations govern AI use in software development as the industry shifts from the traditional software development lifecycle (SDLC) toward what the company calls the Agentic Development Lifecycle (ADLC).

DevOps.com: Are LLMs Equally Good (or Bad) at Building Secure Software?
With many software engineering teams moving from AI coding assistants into full agentic AI code generation and increasing the amount of code they produce exponentially, ensuring the security of that code must be a top priority. The study produces practical guidance for organizations that are getting on board the AI-assisted or agentic code development train.

TechRadar Pro: Beware the token trap: Why saving on inference might put your ADLC at risk
Token use can create unexpected, sizeable costs for organizations.

KBI Media: AI Coding Boom Raises Fresh Cybersecurity Risks for Business
AI enables faster development cycles and allows developers to focus on higher-value work. For many businesses, these efficiencies are becoming essential to remaining competitive. The challenge, therefore, is not whether to adopt AI, but how to do so responsibly. Businesses that invest in developer education, governance frameworks, AI observability and robust security controls will be better positioned to capture the benefits while limiting the associated risks.
.png)
In AI Today: AI's weakest link isn't the model but the software supply chain
The issue is no longer simply about protecting AI models themselves. Increasingly, attackers are focusing on the software ecosystem surrounding those models, including the development tools, middleware, open-source libraries, and automated deployment pipelines that organisations rely upon every day.

The AI Journal: Investigating global AI regulation: Who is winning, and where to from here?
As we will unpack together, there is a lot of movement around the world, with some collaboration between nations, but the path forward is far from uniform or clear, particularly in business environments where AI adoption is often mandated before holistic safeguarding measures are in place.

Cyber Daily: The industry reacts to OpenAI’s agent ‘accidentally’ hacking Hugging Face
According to one expert, AI guardrails are not designed as “security boundaries” but rather to influence behaviour – but what if that behaviour is hacking one of your industry partners?

SecurityBrief: Autonomous OpenAI agents breach Hugging Face in test
Cyber security experts have warned that the breach of Hugging Face infrastructure during an OpenAI security evaluation marks a turning point in the risks posed by autonomous AI agents. In the incident, AI models moved beyond a controlled test and carried out a live, multi-stage intrusion against the AI platform.

Technology Decisions: AI generated code found to produce predictable weaknesses
AI-generated code introduces an average of 15 confirmed vulnerabilities per codebase, research published by Secure Code Warrior indicates.

Forbes: OpenAI’s Hugging Face Breach Shows Frontier AI Guardrails Are Failing
.jpeg)
In AI Today: Secure Code Warrior research reveals AI-generated code introduces an average of 15 vulnerabilities per codebase
Secure Code Warrior research reveals AI-generated code introduces an average of 15 vulnerabilities per codebase.

VMBlog: Secure Code Warrior Research Reveals AI-Generated Code Introduces an Average of 15 Vulnerabilities Per Codebase
Secure Code Warrior introduced the SCW AI Trust Index, a living benchmark for AI coding security that grows with every new model, helping organizations understand and govern the security risks introduced by AI-generated code. Built on a methodology created with RMIT University, Australia, then extended by Secure Code Warrior, the research presents comprehensive benchmarks on how often leading LLMs produce insecure code, with material implications for every enterprise scaling AI-assisted development.

Dark Reading: Choose Wisely: AI-Generated Coding Risk Varies, A Lot
AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used.
.avif)
Secure Code Warrior Research Reveals AI-Generated Code Introduces an Average of 15 Vulnerabilities Per Codebase
New SCW AI Trust Index shows AI-generated coding risk is not random, it's predictable by model and framework, giving security leaders the data to safely scale AI-assisted development.

ITWire: Eight Industry Executives Comment on Worldwide AI Appreciation Day
The challenges with AI implementation, constant updates, and the race for industry dominance are coming thick and fast, and security professionals are among the most affected by its vast risk profile.

Cyber Daily: The industry speaks – part 3: AI Appreciation Day 2026
The Australian government has said AI is very much in the country’s future national interest – but where does it stand today? Here’s what the industry’s best and brightest have to say about artificial intelligence and its role in the modern enterprise.

ITWire: Agentic AI Era Demands Overhaul of Governance Frameworks
The emergence of agentic AI marks a structural shift in software development, introducing systems that not only accelerate production cycles but also perform autonomous reasoning and action beyond direct human control.

SecurityWeek: How to Conduct a Successful Audit of AI-Driven Software Development
As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production.

SD Times: Platform Engineering & Developer Experience: Making Engineers Faster Without Making Them Reckless: SD Times 100
This category has taken on new urgency in 2026 for a reason that’s specific to this moment: AI coding tools and agents are dramatically increasing how much code gets written and how often it needs to be deployed, tested, and provisioned for. Platform engineering is the layer that determines whether that increased velocity translates into shipped value or into chaos.

SD Times: AI-Assisted Development Multiplies Human Error: What’s Your AI Governance and Risk Management Strategy?
According to a recent report from Gartner, the rampant use of shadow AI and rogue automation is further fueling the proliferation of AI vulnerabilities. Gartner notes that 32% of IT workers using generative AI tools at work say they keep them hidden from cybersecurity teams. Combined with low-code/no-code platforms and vibe coding practices, the AI copilots are greatly expanding the enterprise attack surface.

Cybersecurity Tribe: What Separates Real AI Governance From Policy Theater
For this article, we asked a central question for security and risk leaders: "What differentiates a policy that genuinely mitigates enterprise risk from one that exists primarily to demonstrate that the organization has acknowledged AI risk?"

ISMG: AI Coding Tools Raise Hidden Security Risks
Secure Code Warrior's Pieter Danhieux on Managing AI-Driven Development Risks

ITWire: Decoding AI Coding “Personalities” Critical to Managing Development Risk
As generative AI cements its place in enterprise software development, a familiar discipline is taking on new urgency: risk management.

In AI Today: Secure Code Warrior launches Trust Agent: AI to enable safe, scalable AI-driven development
Secure Code Warrior have today announced SCW Trust Agent: AI, the industry’s first governance solution designed to make Artificial Intelligence (AI) influence in software development visible, attributable, and enforceable at the point of commit — enabling enterprises to scale AI coding tools with measurable control over software risk.

DEVOPSdigest: 25 Years of the Agile Manifesto, and the End of the Road for AppSec?
Even as we restructure the SDLC around the most impactful elements of the Agile methodology with careful, DevSecOps-centric security considerations, is this the end of the road for AppSec as we know it?

Cyber Defense Magazine: Global InfoSec Awards 2026 Secure Code Warrior Wins Outstanding Achievement in Cybersecurity Risk Management and Compliance Excellence
Global InfoSec Awards 2026 Secure Code Warrior Wins Outstanding Achievement in Cybersecurity Risk Management and Compliance Excellence

ITWire: Secure Code Warrior Launches Trust Agent: AI to Enable Safe, Scalable AI-Driven Development
New AI Software Governance solution makes AI-generated code visible at commit, enforces policy before production, and connects real development behavior to measurable risk reduction.

DevOps.com: Secure Code Warrior AI Agent Applies Policies to AI Generated Code
Secure Code Warrior (SCW) this week added an artificial intelligence (AI) agent that both identifies code generated by an AI coding tool and automatically applies the appropriate governance policies.

SecurityBrief UK: Secure Code Warrior unveils AI tool to govern code risk
Secure Code Warrior has launched SCW Trust Agent: AI, a software governance product that tracks the use of AI coding tools in development and links that usage to software risk when developers commit code.

2026 Globee® Awards for Cybersecurity: Secure Code Warrior Wins Gold Globee for Software Development Cybersecurity Solutions (Best Of)
2026 Globee® Awards for Cybersecurity: Secure Code Warrior Wins Gold Globee for Software Development Cybersecurity Solutions (Best Of)

DEVOPSdigest: Secure Code Warrior Releases Trust Agent
Secure Code Warrior announced SCW Trust Agent: AI, a governance solution designed to make AI influence in software development visible, attributable, and enforceable at the point of commit — enabling enterprises to scale AI coding tools with measurable control over software risk.

TalkDev: Secure Code Warrior Launches Trust Agent: AI to Enable Safe, Scalable AI-Driven Development
Secure Code Warrior today announced SCW Trust Agent: AI, the industry’s first governance solution designed to make AI influence in software development visible, attributable, and enforceable at the point of commit — enabling enterprises to scale AI coding tools with measurable control over software risk. For the first time, organizations can trace which AI models influenced specific commits, correlate that influence to vulnerability exposure, and take corrective action before insecure code reaches production.

Help Net Security: SCW Trust Agent: AI tracks AI influence in code to reduce software risk
Secure Code Warrior has announced SCW Trust Agent: AI, a governance solution designed to make AI influence in software development visible, attributable, and enforceable at the point of commit, enabling enterprises to scale AI coding tools with measurable control over software risk. Organizations can trace which AI models influenced specific commits, correlate that influence with vulnerability exposure, and take corrective action before insecure code reaches production.

Secure Code Warrior Launches Trust Agent: AI to Enable Safe, Scalable AI-Driven Development
New AI Software Governance solution makes AI-generated code visible at commit, enforces policy before production, and connects real development behavior to measurable risk reduction.

Security Boulevard: Threat Modeling with AI: A Developer-Driven Boon for Enterprise Security
Developers have long struggled to truly claim a seat at the table in traditional threat modeling programs, but with the right skills, they have the opportunity to wield AI responsibly to seriously cut risk and rework in their codebase.

The AI Journal: Understanding LLM Coding Personalities Is Now Key to Developer Risk Management
AI-generated code may be “made by machine”, but taking a cookie-cutter approach to securing that code would fall well short of mitigating the vulnerabilities LLMs can introduce. Organizations need to establish precise security reviews, with human developers anchoring the process to implement effective security controls while also managing the specific coding temperament of each LLM used. AI-generated code must undergo the same personalized risk assessments as code written by human developers.

SecurityBrief: The security challenges in AI-assisted software development
s artificial intelligence (AI) tools become more widely used in the software development process, their impact on security is becoming clearer. According to recent research, nearly 70% of organisations have discovered vulnerabilities caused by AI tools while one in five have experienced a serious incident as a result of those vulnerabilities.

KBI Media: Eliminating the Technical Debt Caused by AI-Assisted Software Development
According to research company Forrester[1], the tech debt for 75% of organisations will increase to a moderate or high level during this year, due to the rapid expansion of AI usage across a range of areas including software development.

Forbes: Security Self-Governance: Addressing The Regulatory Gap In AI-Assisted Software Development
While it’s early into 2026, we’re seeing new research that reveals the extent of cyber risks caused by artificial intelligence (AI)-assisted software development: Nearly 7 in 10 organizations have discovered vulnerabilities introduced by AI-generated code, and 1 in 5 have suffered a serious incident tied directly to the vulnerabilities.

ITWire: Why AI Is Dulling Cybersecurity’s Most Important Edge
Artificial intelligence (AI) has rapidly become indispensable to modern software development. From large language models that generate code on demand to agentic systems that automate entire workflows, AI tools promise dramatic gains in productivity and efficiency.

SecurityWeek: How to Eliminate the Technical Debt of Insecure AI-Assisted Software Development
Developers must view AI as a collaborator to be closely monitored, rather than an autonomous entity to be unleashed. Without such a mindset, crippling tech debt is inevitable.

CSO Online: Software developers: Prime cyber targets and a rising risk vector for CISOs
From technical compromise to AI-driven attacks, cyber criminals increasingly see software developers as prime targets, creating systemic risks CISOs must address.

SMBtech: Tech Industry Leaders React To Data Privacy Week 2026
It’s Online Privacy Week, a time of year where individuals and organisations are all reminded to check their digital footprint(s). Some might say that’s a futile gesture at a time where major social media and marketing players know absolutely everything about you and are cheerfully selling all that data to anyone who’ll buy it; when Microsoft is performing every trick in the book to get Windows users to put all their data in the cloud where it’s available for government agencies to snoop upon without letting you know; when a personal computer crisis means many people will be moved on to dumb-client computing landscape where everything from data storage to major processing tasks will be taking place in the cloud; and when people think that clicking ‘Accept’ on website pop-ups does something that meaningfully protects them. But, what do the experts say?

Security brief: AI heightens data privacy risks & reshapes digital trust
Technology and data specialists have warned that artificial intelligence and weak data governance are sharpening privacy risks for organisations, as businesses mark World Data Privacy Day.

ITWire: Data Privacy Week 2026
“Data Privacy Week" presents a great reminder for organisations to reassess their customer privacy policies and prioritise transparent data collection in their marketing strategies.

Dynamic Business: Data Protection Day 2026: Five experts on the privacy risks threatening your business
Five leading cybersecurity experts warn AI is being integrated faster than security policies can manage the risk, creating urgent privacy gaps for SMEs ahead of Data Protection Day on 28 January.

Information Security Buzz: OWASP Top 10 2025: New Enemies, Old Foes, and an Approach to Vulnerability Remediation That Must Evolve
The OWASP Foundation has been a guiding light for security professionals and enthusiasts alike, providing critical, practical advice on the most insidious software vulnerabilities across a plethora of categories and platforms. It has been the first major update since 2021 to the flagship OWASP Top 10 Web Vulnerabilities, and in that time, the industry has been rocked by a stampede of AI technology, tools, and code, each creating a dichotomy of security efficiency and risk for both cybersecurity and software engineering professionals.

DEVOPSdigest: What Software Developers Need to Know About Secure Coding and AI Red Flags
The bottom line: AI tools are not safe for enterprise use unless the code output is reviewed and implemented by a security-proficient human. 30% of security experts admit that they don't trust(link is external) the accuracy of code generated by AI itself. That's why security leaders must prioritize the education and upskilling of developer teams, to ensure they have the necessary skills and capabilities to mitigate AI-assisted code vulnerabilities as early as possible. This will lead to the cultivation of a "security first" team culture and safer AI use.

Stack Overflow: If you're a Zoomer, this one's for you: Everything Gen Z needs to know about the 2025 tech landscape
Here's the lowdown on all the tech from 2025 that you, dear Zoomer, should know about.

SC Media: CISOs can’t wait for the EU AI Act to take shape
CISOs hoping for the EU Artificial Intelligence Act to offer a solid framework for AI governance may be a little confused or disappointed by recent updates surrounding the implementation of AI restrictions.

SecurityBrief: Agentic AI double agents expose dangerous security gaps
An alleged nation-state attacker used Claude Code and a range of tools in the developer ecosystem to almost autonomously target specific companies with benign open-source hacking tools at scale. Of the more than thirty attacks, several were successful, and proved that AI agents could indeed execute large-scale, malicious tasks with little to no human intervention.

DEVOPSdigest: 2026 DevSecOps Predictions
DEVOPSdigest's Prediction Series continues with 2026 DevSecOps Predictions — Industry experts offer predictions on how DevSecOps will evolve and impact the industry in 2026.

ITWire: OWASP Names Latest Top 10 Application Vulnerabilities
The Open Worldwide Application Security Project (OWASP) has unveiled its latest top 10 vulnerabilities list, and it contains some surprising insights into important vulnerability classes.

Channel Insider: Cybersecurity Experts Predict AI, Nation-State Threats in 2026
Cybersecurity experts outline 2026 predictions, from AI-driven attacks and quantum risk to nation-state threats, OT security gaps, and automation pressures.

Security Journal UK: The rise of AI coding tools and the skills gap they expose
Pieter Danhieux, Co-founder and CEO of Secure Code Warrior warns that while AI coding tools promise speed and efficiency, they also introduce new risks.

ITWire: Predictions on State of AI in 2026
2026 is shaping up to be the year AI evolves from instrument to partner, transforming how we work, create and solve problems.

Fortune: AI coding tools exploded in 2025. The first security exploits show what could go wrong
While a breach of the tools hasn’t so far caused a wide-scale attack, there have been a few exploits and near-misses, and cyberthreat researchers have discovered critical vulnerabilities in several popular tools that make clear what could go horribly wrong.

SMBtech: Australian Tech Industry Leaders Make Their Predictions for 2026
It’s that time of year where the technology industry predictions start rolling-in. Here’s what you can (apparently) expect in 2026.

Technology Decisions: The importance of effective security when deploying AI tools
The concern is straightforward: development teams may place undue confidence in AI tools that are not equipped to interpret the nuanced context in which many security vulnerabilities arise. Large language models, for instance, can struggle to understand an application’s authentication or authorisation architecture, increasing the likelihood of missing critical safeguards.

ITWire: Five Steps to Improve the Security of AI Developed Code
Industry guidance on managing the risks of AI-generated code increasingly points to the same conclusion: effective safeguards rely on close collaboration between humans and machines, with developers remaining firmly in the loop.

SecurityBrief Australia: Agentic AI to transform APJ businesses & security by 2026
Agentic artificial intelligence (AI) is set to reshape the enterprise landscape in the Asia-Pacific and Japan (APJ) region in 2026, according to industry executives. Organisations are expected to embrace increasingly autonomous software agents, raising both productivity and new categories of risk across business domains.

SC Magazine UK: Why Firms Can’t Ignore Agentic AI
How big a threat does agentic AI pose to businesses currently? And what should security leaders be doing to address the risk?

VMBlog: Cybersecurity Predictions: What AI will (and won't) do for us in 2026
My co-founder and CTO, Matias Madou, Ph.D., and I consulted our crystal ball (or should that be our NVIDIA GPUs?), and this is what we believe 2026 has in store for us from an AI security perspective.

SD Times: Pumping the Brakes on Agentic AI Adoption in Software Development
An alleged nation-state attacker used Claude Code and a range of tools in the developer ecosystem, namely Model Context Protocol (MCP) systems, to almost autonomously target specific companies with benign open-source hacking tools at scale. Of the over thirty attacks, several were successful, and proved that AI agents could indeed execute large-scale, malicious tasks with little to no human intervention. Maybe it’s time we went a little slower, stopped to reflect on what is at stake here, and how best to defend ourselves.

AIthority: Building Secure and Ethical AI Practices in Software Development
AI is now a key piece of modern software development. More than four out of five developers use AI coding tools daily or weekly – with many relying on multiple tools in parallel. Teams must understand where automation ends, and where accountability begins.

SC Media: Secure Coding as Critical Thinking Instead of Vulnspotting – Matias Madou – ASW #357
Secure code should be grounded more in concepts like secure by default and secure by design than by “spot the vuln” thinking. Matias Madou shares his experience in secure coding training and the importance of teaching critical thinking. He also discusses why critical thinking is so closely related to threat modeling and how LLMs can be a tool for helping developers get beyond the superficial advice of, “Think like an attacker.”

Forbes: How CISOs Can Increase Their Influence In AI-Obsessed Boardrooms
Organizations are at an inflection point driven by the explosive adoption of AI, which promises significant changes in how businesses operate. That leaves CISOs on unsteady ground. As the gatekeepers of their organization’s data and access, they must ensure the security of the enterprise. However, the prospects of a headlong charge into wide-ranging, and possibly unchecked, use of AI could create a flood of security issues that many CISOs, under their current organizational structures, aren’t equipped to handle.

Security Boulevard: Security Degradation in AI-Generated Code: A Threat Vector CISOs Can’t Ignore
Security leaders and developers alike are already acutely aware that AI coding assistants and agentic agents can introduce vulnerabilities into the code they generate. A recent study unveiled another critical concern to keep them up at night — LLMs used for making iterative code improvements may introduce new vulnerabilities over time, even when explicitly asked to make code more secure.

Information Week: Make your own mandate: How CISOs can implement GenAI governance
Government bodies are trying to develop rules and regulations for safe AI use, but enterprises can't afford to wait. They need to address the risks now.

CFOtech Australia: How women can continue to foster fulfilling high-tech careers in the AI age
In the sphere of cybersecurity in general and application security in particular, human oversight remains an absolute 'must' to harness the benefits of AI productivity.

Tanium: Vibe coding may be unstoppable—but here’s how to rein in the risks
Like the meteoric rise of ChatGPT, vibe coding is all anybody can talk about this year. In fact, it just became a word in the dictionary. But beware the boom: These new AI coding tools offer speed, savings—and astounding vulnerabilities.

[PODCAST] Stack Overflow: AI code means more critical thinking, not less
Ryan is joined by Secure Code Warrior’s co-founder and CTO Matias Madou to discuss the implications of LLMs’ variability on code security, the future of developer training as AI coding assistants become more popular, and the importance of critical thinking—especially for junior developers—in the age of AI.

Cybersecurity Insiders: Use It or Lose It: Overreliance on AI Diminishes Critical Cybersecurity Thinking Skills
Software developers reap a host of benefits from making use of artificial intelligence assistants, whether in the form of Large Language Model (LLM) code creators or agentic AI agents. But recent reports, highlighted by a new study at MIT, warn that heavy use of AI can result in a loss of critical thinking skills among users.

Security Week: How Software Development Teams Can Securely and Ethically Deploy AI Tools
To deploy AI tools securely and ethically, teams must balance innovation with accountability—establishing strong governance, upskilling developers, and enforcing rigorous code reviews.

Dark Reading: AI Developed Code: 5 Critical Security Checkpoints for Human Oversight
To write secure code with LLMs developers must have the skills to use AI as a collaborative assistant rather than an autonomous tool, Madou argues.

Techstrong.tv: Secure Code Warrior in the Age of AI with Pieter Danhieux
Secure Code Warrior’s Chief Executive Officer, Chairman, and Co-Founder Pieter Danhieux explains his transition from offensive cybersecurity to promoting secure software development. Founded in 2015, Secure Code Warrior aims to help developers build secure code from the start, a practice Danhieux and host Alan Shimel agree is more effective than fixing vulnerabilities later. The two also discuss the impact of AI on software development, noting that while AI increases coding speed and accessibility for more people, the security of AI-generated code still lags. They emphasize the growing need for developers to master secure coding practices amidst these technological advancements.

SMBtech: Cybersecurity Awareness Month 2025: Australian Industry Reactions and Commentary
October is Australia’s Cybersecurity Awareness Month, the annual reminder for Aussies to stay vigilant online. This year’s theme, ‘Building our cyber safe culture’ once again highlights the importance of taking personal responsibility for staying secure in an increasingly digital world.

SecurityBrief: SMEs urged to cut data & boost cyber defences as attacks rise
Cybersecurity Awareness Month has brought renewed attention to the increasing risks faced by organisations of all sizes, with a particular focus on the growing threat to small and medium-sized enterprises (SMEs) in Australia and the UK.

ITBrief: Our biggest security risk isn’t our software - it’s our thinking
In the world of cybersecurity, we face creative and unconventional threats every day. But our greatest vulnerability isn't a flaw in our software, but a flaw in our collective thinking.

KBI Media: Overcoming the Security Risks of Using AI In Software Development
Development teams face relentless pressure to deliver, yet they must continue to prioritise building secure, high-quality software. Leaders play a crucial role in reinforcing how a Secure by Design approach, supported by observability, benchmarking, and ongoing education, directly enhances code quality. By embedding these practices, organisations can close governance gaps and fully capture the benefits of AI-driven productivity and efficiency, while reducing the risk of security flaws or costly rework during the SDLC.

In AI Today: The looming security challenges posed by Agentic AI
While agentic AI holds the promise of delivering significant business benefits, it also comes with significant caveats. The technology’s capabilities and autonomy present a potent enterprise threat vector beyond the realm of existing security concerns.

Help Net Security: Secure Code Warrior gives CISOs visibility into developer AI tool usage
Secure Code Warrior has launched a beta program to expand the AI capabilities of its Trust Agent product. The new offering provides CISOs with security traceability, visibility, and governance over developers’ use of AI coding tools.

Cyber Risk Leaders: Secure Code Warrior Launches AI Traceability
Secure Code Warrior have released a beta program for a major expansion of AI capabilities within its Trust Agent product. The upgrade, collectively referred to as Trust Agent: AI, leverages a combination of key signals, including AI coding tool usage, vulnerability data, code commit data and developer secure coding skills, to provide visibility into how AI development tools are impacting risk within the software development lifecycle (SDLC).

CSO Online: AI coding assistants amplify deeper cybersecurity risks
Although capable of reducing trivial mistakes, AI coding copilots leave enterprises at risk of increased insecure coding patterns, exposed secrets, and cloud misconfigurations, research reveals.

Secure Code Warrior Launches Industry-First AI Traceability to Enable Secure Developers and Supercharge Safe Productivity
New capabilities in SCW Trust Agent provide visibility and control over LLM usage for security leaders and CISOs.

ITOps Times: Secure Code Warrior announces new solution that provides visibility and governance for AI coding tools
Secure Code Warrior is trying to provide organizations with greater visibility and control over developers’ use of AI coding tools with the launch of its new solution, Trust Agent: AI.

DevOps Digest: Secure Code Warrior Introduces AI Traceability
Secure Code Warrior announced the launch of a beta program for a major expansion of AI capabilities within its Trust Agent product.

CyberWire: Business Briefing for 09.24.25
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Betanews: AI is an even playing field -- how secure by design can tip the scale [Q&A]
Vibe coding is currently all the rage, with more than 97 percent of respondents to a survey earlier this year reporting having used AI coding tools at work. The adoption of these tools only continues to grow but it comes with a catch, attackers are also employing the same techniques. We spoke to Pieter Danhieux, co-founder and CEO of Secure Code Warrior, to discuss how vibe coding is redefining the software development landscape, how malicious actors are also leveraging this technology and the need for organizations to implement secure by design strategies from the outset.

SD Times: Benchmarking AI-assisted developers (and their tools) for superior AI governance
If the tech stack lacks tools that oversee not only developer security proficiency, but also the trustworthiness of approved AI coding companions each developer uses, then it is likely that efforts to uplift the overall security program and the developers working within it will be short of the appropriate data insights to effect change.

ITWire: The Benefits and Risks of Using AI Tools in Software Development
The process of software development is undergoing a period of expedited change. Thanks to massive advances in artificial intelligence (AI) technology, projects can be completed more rapidly and by people with little or no prior experience.

LeadDev: Ethics are being forgotten as the AI race heats up
Is the tech industry capable of the change needed to curb ethical and environmental concerns?

Secure Code Warrior Expands Commitment to Secure by Design Best Practices with Free Secure Code Video Series for Developers
Launch of new 12-week video series on AI/LLM security empowers developers to safely adopt AI coding and mitigate emerging security risks.

CSO Online: When AI nukes your database: The dark side of vibe coding
As developers lean on Copilot and GhostWriter, experts warn of insecure defaults, hallucinated dependencies, and attacks that slip past traditional defenses.

The AI Journal: Resilience and Developer Risk Management: Two Pillars of Success in the Era of Secure by Design and AI Coding
Change is afoot in cybersecurity governance, and it couldn’t come at a more transformative time for security leaders worldwide. The White House issued a recent Executive Order (EO) designed to “reprioritize cybersecurity efforts to protect America”, and with it, reduce friction related to overzealous government oversight to focus on protecting critical digital assets and enhanced secure technology practices. Coupled with significant cuts to CISA, one could be forgiven for being apprehensive of the right approach going forward, especially in the wake of rapid AI technology progression and Secure by Design initiatives.

SecurityWeek: How to Close the AI Governance Gap in Software Development
Widespread adoption of AI coding tools accelerates development—but also introduces critical vulnerabilities that demand stronger governance and oversight.

teiss: When regulations aren’t enough
Pieter Danhieux at Secure Code Warrior explains why “Secure by Design” has emerged as mission critical for software development

Information Age: Vibe coding is a hot skill – and security experts are worried
GenAI tools are building insecure apps faster than ever.

CXFocus Magazine: Going above and beyond in 2026
Today’s customers are an exacting lot with little tolerance for suppliers that fail to meet their ever-increasing expectations. Almost 94 per cent of Australian consumers stopped purchasing from at least one company after a negative experience, according to CPM’s 2025 The State of Customer Experience in Australia Report.
.avif)
Which AI Model Codes Most Securely?
See how 16 leading AI models actually code, scored across 11 real-world frameworks and 1,760 codebases — the framework matters as much as the model.

Citizen AI by Secure Code Warrior
AI risk doesn't stop at engineering. Get the one-pager on Citizen AI — build AI literacy and safe habits across your whole workforce.

Understand how AI is transforming software development—and how security must evolve with it.
From AI autocomplete to autonomous agents—explore how software development is evolving and what it means for security, governance, and your team.

SCW named in new Agentic Coding Security category
Gartner named SCW twice in the 2026 Hype Cycle for Secure Software Engineering. Here's why it matters for AI-driven development.

SCW Learning Content for KnowBe4
Secure Code Warrior content available through KnowBe4 helps technical teams build secure coding and AI governance awareness through structured learning covering OWASP Top 10 risks, AI-assisted development, and modern secure coding practices.

Secure AI-driven development with KnowBe4 + Secure Code Warrior
Secure Code Warrior joins KnowBe4 to bring hands-on secure coding training into security awareness programs — covering OWASP, AI development, and 10 languages.
Trust Agent:AI - Secure and scale AI-Drive development
AI is writing code. Who’s governing it? With up to 50% of AI-generated code containing security weaknesses, managing AI risk is critical. Discover how SCW's Trust Agent: AI provides the real-time visibility, proactive governance, and targeted upskilling needed to scale AI-driven development securely.

The Power of OpenText Application Security + Secure Code Warrior
OpenText Application Security and Secure Code Warrior combine vulnerability detection with AI Software Governance and developer capability. Together, they help organizations reduce risk, strengthen secure coding practices, and confidently adopt AI-driven development.

Secure Code Warrior corporate overview
Secure Code Warrior is an AI Software Governance platform designed to enable organizations to safely adopt AI-driven development by bridging the gap between development velocity and enterprise security. The platform addresses the "Visibility Gap," where security teams often lack insights into shadow AI coding tools and the origins of production code.

Secure code training topics & content
Our industry-leading content is always evolving to fit the ever changing software development landscape with your role in mind. Topics covering everything from AI to XQuery Injection, offered for a variety of roles from Architects and Engineers to Product Managers and QA. Get a sneak peek of what our content catalog has to offer by topic and role.
Cyber Resilience Act (CRA) Aligned Learning Pathways
SCW supports Cyber Resilience Act (CRA) readiness with CRA-aligned Quests and conceptual learning collections that help development teams build the Secure by Design, SDLC, and secure coding skills aligned with the CRA’s secure development principles.
%20(1).avif)
OWASP Top 10 2025 eBook
Want to dominate the OWASP Top 10? Download the No-BS Guide to Defending Your Applications Against the OWASP Top 10:2025
Trust Agent: AI by Secure Code Warrior
This one-pager introduces SCW Trust Agent: AI, a new set of capabilities that provide deep observability and governance over AI coding tools. Learn how our solution uniquely correlates AI tool usage with developer skills to help you manage risk, optimize your SDLC, and ensure every line of AI-generated code is secure.

AI Coding Assistants: A Guide to Security-Safe Navigation for the Next Generation of Developers
Large language models deliver irresistible advantages in speed and productivity, but they also introduce undeniable risks to the enterprise. Traditional security guardrails aren’t enough to control the deluge. Developers require precise, verified security skills to identify and prevent security flaws at the outset of the software development lifecycle.
Secure by Design: Defining Best Practices, Enabling Developers and Benchmarking Preventative Security Outcomes
In this research paper, Secure Code Warrior co-founders, Pieter Danhieux and Dr. Matias Madou, Ph.D., along with expert contributors, Chris Inglis, Former US National Cyber Director (now Strategic Advisor to Paladin Capital Group), and Devin Lynch, Senior Director, Paladin Global Institute, will reveal key findings from over twenty in-depth interviews with enterprise security leaders including CISOs, a VP of Application Security, and software security professionals.

Turn Awareness Into Action This Cyber Awareness Month
This October, turn awareness into action. Make Cyber Awareness Month memorable for your developers with a high-impact, high-participation experience—led by Secure Code Warrior's Professional Services team.

Professional Services - Accelerate with expertise
Secure Code Warrior’s Program Strategy Services (PSS) team helps you build, enhance, and optimize your secure coding program. Whether you're starting fresh or refining your approach, our experts provide tailored guidance.

Quests: Industry leading learning to keep developers ahead of the game mitigating risk.
Quests is a learning platform that helps developers mitigate software security risks by enhancing their secure coding skills. With curated learning paths, hands-on challenges, and interactive activities, it empowers developers to identify and prevent vulnerabilities.
Benchmarking Security Skills: Streamlining Secure-by-Design in the Enterprise
The Secure-by-Design movement is the future of secure software development. Learn about the key elements companies need to keep in mind when they think about a Secure-by-Design initiative.
Trust Agent in action
SCW Trust Agent gives you the tools you need to deliver secure code faster, ensuring developers have the knowledge and skills to implement security best practices in the specific programming language of their code commits.
.jpeg)
Trust Agent by Secure Code Warrior
Are you confident that every line of code committed is backed by a developer with the necessary secure coding skills? Many organizations face this critical gap, leading to preventable vulnerabilities and reduced development velocity. SCW Trust Agent offers unparalleled visibility across your code repositories, analyzing commits directly against developer security proficiency. With policy gates, Trust Agent enables you to apply governance at the commit level, with policies to ensure code contributors have the secure code knowledge you require for your business-critical applications. Download our one-pager today to learn how SCW Trust Agent can help you strengthen your security posture, optimize your development lifecycle, and significantly reduce vulnerabilities.
SCW Trust Score - The best way to build, measure, and optimize your security program
Learn more about Secure Code Warrior Trust Score, the best way to build, measure and optimize your security program.
Trust Score by Secure Code Warrior
Discover SCW Trust Score, an industry-first benchmark to help measure your security program's effectiveness. Benchmark against industry peers, optimize your security posture, and drive data-driven decisions for enhanced software security.
Preparing for PCI-DSS 4.0 Compliance
Evaluate your software security infrastructure to support PCI-DSS requirements
The ultimate guide to security trends in financial services
Financial services institutions face an array of challenges that hinge on their ability to make efficient, effective use of technology in a fast-evolving financial world. Organizations are operating in a time of rapid changes—both internally and across the industry—in a highly competitive, cloud-based business environment. In pursuing their ongoing digital transformations, for example, organizations are working to get around the organizational friction that hinders investments into new technologies, such as artificial intelligence, that could accelerate payment processes and other procedures.

Predicts 2024: Generative AI is reshaping software engineering
Explore how generative AI is revolutionizing software development across the SDLC, as highlighted in Gartner's report, advising Application Security leaders on the importance of scrutinizing AI-generated software.
PCI DSS 4.0 Unraveled
This guide offers practical strategies to engage development teams in PCI DSS 4.0 compliance. It outlines the modern developer's requirements for compliance, strategies for security professionals and development managers to collaborate on developer-focused security programs, and step-by-step advice on effective training initiatives to mitigate vulnerabilities permanently.

Developer security maturity quiz
Secure Code Warrior outlines three security maturity stages for developer teams: defining, adopting, and scaling. How security-savvy are your developers? Take our quiz to find out.
Script Testing please ignore
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
ROI of Secure Code Learning
Explore the long-term ROI of secure coding education. Learn how investing in agile, proactive learning strategies enhances security and offers cost-effective protection against today's cyber threats.
Why developers need security skills to effectively navigate AI development tools
The promise of artificial intelligence writing complex code at the touch of a button is intriguing, but the reality is that AI will need a lot of help from human developers to craft truly secure and reliable code.
Top 10 predictions for 2024
Check out what SCW experts are predicting in the world of cybersecurity and software security in 2024.
Agile learning platforms: ROI of developer-driven security
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Forge your fortress: Six essential pillars of developer enablement in software security
In this white paper, security expert and Secure Code Warrior CTO & Co-Founder Matias Madou, Ph.D. will discuss:The six pillars you need to roll out effective security education and enablement for your development cohort. Lessons learned from ten executives implementing security programs at the enterprise level, and common pitfalls to avoid on your road to success.
The Agile Learning Platform
Empower your development team with Secure Code Warrior, the agile learning platform designed to tackle the evolving challenges of application security. Stay ahead in the battle against security breaches and regulatory complexities with our industry-leading, up-to-date content, ensuring a proactive and engaging approach to secure code education.

OWASP Top 10 API 2023: A tactical guide for smart developers
Explore the Latest in API Security. Dive into our 2023 OWASP Top 10 guide. Elevate your coding skills, tackle vulnerabilities, and stay agile in the ever-evolving world of API development. Download now for an insightful journey!

The secure code learning blueprint
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Your handbook to developer-driven security and agile learning
Start shifting left with developer-driven security. This handbook will show you how to engage with developers to upskill and increase their security knowledge, as well as how to go about measuring impact to write more secure code.

Software is your colleague: A new perspective to strengthen access control and API security
APIs act like flawed humans; is treating them as such the key to better cybersecurity?

The secure code training blueprint
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
The developer security maturity matrix
Building security maturity in development teams can be approached in stages. Based on our experience with 400+ organizations, we've identified common practices and traits in three different stages of security maturity - defining, adopting, and scaling.
The importance of security maturity in developer teams
By assessing and understanding a development team’s security maturity, organizations can formulate a plan with the right stakeholders, process, and technology to build and support the necessary skills and capabilities.
Development Team Security Maturity
Security maturity in development teams should be a continuous cycle of improvement with realistic goals along the way. As development teams increase their security maturity, they reduce the amount of rework and minimize risk, while also allowing automation to help create efficiency in the SDLC.

Report: The state of developer driven security 2022
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Whitepaper: The challenges (and opportunities) to improve software security
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Brief: A cohesive approach to developer-led security
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Security and privacy at Secure Code Warrior
Secure Code Warrior is committed to safeguarding our information assets, and those of our customers, against misuse, abuse or compromise. We adopt and foster a risk-based approach to managing information security, with the goal of consistently implementing appropriate risk management and mitigation measures to address the threat landscape posed to the security of the platform, customer data and information. As Secure Code Warrior continues to succeed as a major player providing services to our customers, we will continue to build security capabilities as part of our security and privacy programs. Read our whitepaper for more information.
.png)
Shift left (and achieve compliance) with repeatable secure coding skills
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
.png)
Defining secure code
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Why you need more than scanning tools to create secure code
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Your guide to defense against the dark art of zero-day attacks
Zero-day attacks can be the stuff of nightmares, but when an organization commits to using all available tools in their security arsenal towards a preventative strategy, security professionals can sleep a little easier.
A plan to upskill and engage your developers
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
The preventative, developer-driven approach to software security
Learn more about how security-aware developers represent a vast and largely untapped resource that can support cyber defenses by consistently standing against modern threats.

Security and Privacy Whitepaper
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Convince Your CISO/CTO Kit (for starting a demo)
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

OWASP Top 10 API: Strategies for Smart Developers
Download the practical guide to defeating common API security baddies in your code.
How to unify your security and development teams to stand together against security risk
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
How AppSec can reduce vulnerabilities and achieve compliance - leaving them free to tackle larger beasts
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Buyers Checklist: Secure Development Learning Platforms
Buyer’s Checklist: Secure Development Learning Platforms is aimed at decision makers and technology buyers looking to evaluate secure development learning platforms.

Shared Assessments SIG Lite Questionnaire
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

SCW Pen Test Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

SCW Cyber Insurance Certificate
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Shifting from reaction to prevention: The changing face of software security 2021 - Whitepaper
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Cybersecurity Executive Order: A deliberate approach to improve software security with developer skills
While this Executive Order for touches on many aspects of functional cybersecurity, it specifically outlines, for the first time, the impact of developers, and the need for them to have verified security skills and awareness.

FSQS-NL Certificate
Secure Code Warrior is now FSQS-NL registered. This registration is an important milestone in our continuous efforts to being compliant with regulations within the financial industry.

Platform Architecture Diagram
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Information Security Policy
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

CAIQ Questionnaire
Secure Code Warrior has completed a publicly available Consensus Assessment Initiative Questionnaire (CAIQ), based on the results of our due diligence self-assessment.
The DevSecOps Super Bowl: How security champions can support your team to victory against late-stage vulnerabilities
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Executive Roundtable Whitepaper - Visma & Blue Prism
How has 2020 changed the way we look at software security, an executive roundtable with Visma.

The women of mimmit koodaa movement dive into secure coding
Mimmit Koodaa (women who code in Finland) tell us about their secure coding experiences.

Teams in a global financial institution go head-to-head in secure coding contest.
See how a global financial organization promoted the importance of securing their banking applications across the world. With fun interactive tournaments.
Missions - Experience the impact of poor code in real-world simulations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Courses - Build Secure Coding Skills and Competency
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
A Step-By-Step Guide to Tournaments
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

Your Battle Plan to Defeat the OWASP Top 10
The ten most common security vulnerabilities don’t stand a chance against secure development superheroes like you. This free eBook is your ultimate field guide to understanding each infamous entry in the OWASP Top 10 2021, gaining insight into how each bug operates.
Triumph with OWASP and Secure Code Warrior Tournaments - Whitepaper
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Tournaments - Build organizational awareness and developer engagement, making secure coding top of mind
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

The Infamous 8: Infrastructure as Code Vulnerabilities to Find and Fix
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
The Five-Step Road to DevSecOps Success: How AppSec Professionals Can Thrive in Their Dream Team
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

The Fastest and Easiest Way to Improve Your Software Security Program
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
The Creative CISO's Guide to Transforming Their Security Program
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Take the pain out of PCI-DSS Compliance Whitepaper
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Introduction to Secure Code Warrior
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Empowering developers to write secure code
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Empower developers to be the first line of defense and grow your organization's security posture
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Assessments - Benchmark the secure coding skills of your developers, and build your security posture.
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
AppSec Checklist
Download the AppSec checklist and see if you’re in need of a security lifeline.

6 Critical Steps Before You Roll Out a Security Uplift Program
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

2019 AppSec Trend Report
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
%25252520(1).png)







