Software Security Blog

A Guide to OWASP’s Secure Coding Practices Checklist
In 2022, 33% of newly discovered vulnerabilities were flagged as critical or high. Explore OWASP’s secure coding practice checklist and learn how to leverage its power to boost your threat protection and reduce attack risks Digitalization is both a blessing and a curse for organizations.…
Blogging About Everything Software Security – Threats, Updates, Best Practices, Tips, & More
Software touches the everyday lives of billions of people around the world. They rely on us (the software industry) to deliver dependable, safe applications for them to use. This blog is dedicated to working together to do our part to make the (software) world a better place…one piece of software at a time!
-

The industry’s security standards body now requires all code signing certificate private keys to be stored on secure hardware. This comprehensive guide walks through the process of setting up your secure USB token. We recently shared that the industry’s standards body (i.e., the CA/B Forum) updated its Code Signing Certificate Baseline Requirements. As of June…
-

To protect signing keys against theft and misuse, the industry rolled out new security requirements for code signing certificates. Here’s what to know about these changes and what they mean to you as a developer or publisher when purchasing a certificate. An Overview of the Changes Effective June 1, 2023, the industry’s standards body issued…
-

What do Sys.exe, AnyDesk.exe, and netscan.exe have in common? They were all exploited by cybercriminals to deploy BlackByte ransomware attacks. Explore whether all executables are viruses and discover an easy way to discern the good .exe files from bad ones For the second consecutive year, SonicWall’s 2023 Cyberthreat report lists .exe as the most common…
-

Looking to strike the perfect balance between speed, quality, and costs like 40% of QA teams? Prepare your software for a successful launch by learning everything you need to know to create a rock-solid software testing strategy. Is your software secure and trustworthy? According to CISCO, 94% of organizations confirmed that customers wouldn’t buy from…
-

75% of developers spend hours fixing production issues. Wondering which software development methodologies can help you identify flaws earlier, save time and money, and achieve excellence? Here’s what to know… This year, 83% of chief information officers were urged to accomplish more with less money. However, developing secure, high-quality software, fast, and without going over…
-

How good is the code your team has written? Find it out by adding nine indispensable points to your code review checklist that’ll help increase the quality of your code, minimize security risks, and reduce technical debt. In 2022, 35% of developers released software twice as fast as the previous year. But speed isn’t everything…
-

In 2022, 33% of newly discovered vulnerabilities were flagged as critical or high. Explore OWASP’s secure coding practice checklist and learn how to leverage its power to boost your threat protection and reduce attack risks Digitalization is both a blessing and a curse for organizations. From automation to fantastic new technologies and revenue streams, the…
-

PMI research shows that 35% of software development projects failed and suffered budget losses in 2020. Looking for ways to change this trend, and make the grade? Learn what a software development strategy is and get access to a few best-in-class examples that’ll put you on the path to success. With our world becoming increasingly…
-
-

41% of tech organizations are planning to increase investments in cloud-based services and products in 2023. Want to get a piece of the pie? Uncover the power of the Docker registry for building, sharing, running, and quickly scaling cloud-native applications and learn how it can boost the security of your applications. 68.57% of professional developers…
-

Tired of maintaining and securing too many digital certificates and keys? You’re not alone. 72% of organizations say the increasing number of keys and certificates they use is driving them crazy. To ease the pain, learn how to create a PFX file to bundle your certificate and its related key in a single, secure file…
-

Four and a half minutes: This is the amount of time it takes to make a real Italian espresso and how long it takes the newly discovered Rorschach malware to lock customers out of their files & devices. Explore how releasing signed code can help protect your customers and reputation from these types of attacks.…
-

Code signing is a critical step in releasing secure, trusted software. Here’s a step-by-step guide to signing application executables or DLL files in Visual Studio. Visual Studio simplifies software development and is essential for creating .NET applications. As developers increasingly distribute executable software, securing the exchange process is crucial. Code signing is vital to this…
-

Discover the causes of technical debt and learn how to mitigate them before attackers exploit these security flaws to get into your network. (Considering they did this to a U.S. federal agency, surely bad guys can do it with your company, too.) On average, developers spend up to 42% of their time dealing with technical debt. That’s a…
-

According to Veracode, one-third of applications are released with security flaws. Five years after publishing, 70% contain at least one vulnerability. Learn what tech debt is and how tackling it will help you reduce vulnerabilities that could put at risk the security of your organization, products, and customers Technical debt, an Agile term coined by the software developer Ward Cunningham,…
