What do the next 10 years of #AppSec look like?
From better collab between teams to treating vulnerabilities as defects, here’s a glimpse of what security may look like in a few years:
https://t.co/qgOu8e4bnE
Experts know best, and these ones have something to say about you! Here are 4 things that AppSec engineers are doing wrong, according to experts @DinisCruz & Mark Willis: https://t.co/PQA4Qme3i1
From advanced #correlation, to deeper metadata insights such as stage of introduction of a #vulnerability, the #ORL enables #appsec engineers in saving hours of bandwidth and upto 25% increase in efficiency. Learn More - https://t.co/rthp681VjH
How a major #insurance customer saved 7 hours per developer per week, aggregating to over 25% overall savings in resource bandwidth through smart #correlation of #vulnerabilities https://t.co/zpsYG3x3oL
"What problems are solved by #automation are simply replaced by new ones, and it's a problem many #security operations teams aren't yet equipped to handle because of how little they understand" Read More - https://t.co/MvaRBzTbDw
#appsec#devsecops#vulnerabilitymanagement
The Orchestron Risk Language is a massive #vulnerability database designed to make remediation easier for devs. This company used our rich #metadata to bring down their vulnerabilities by 80%. See how they did it: https://t.co/vKDtmOioXh
Presenting our Community (Free) edition. For teams who've adopted #openSource tooling, run fewer testing iterations, or just curious about the possibilities of vulnerability #correlation. Look no more! Download your copy now!
#appsec#vulnerabilitymanagement
What does it mean to 'Shift Security Left'? And why should developers or #security engineers care about it? If you don't want to see months of hard work go down the drain because of one (totally avoidable) #vulnerability, you might want to pay attention.
https://t.co/ZcTyCAhBQO
Sometimes, you can never be sure which #vulnerabilities to fix first. That's why we bring you this handy guide on How to Prioritise Vulnerabilities in your Applications, courtesy of our very own @bondijois! Check it out: https://t.co/ccL5xKpmvc
Last #FridayPopQuiz question: Which test is it wherein pen-testers have partial knowledge about the target system or network?
The answer: Gray box testing. The technique to test apps with partial knowledge of its internal workings.
67% of you got it right. See you next Friday!
Time for the new #FridayPopQuiz!
Which of the following is a test, wherein the pen-tester has partial knowledge about the target system or network?
Answer will be revealed on Monday!