Software Security Blog

A Guide to OWASP’s Secure Coding Practices Checklist
In 2022, 33% of newly discovered vulnerabilities were flagged as critical or high. Explore OWASP’s secure coding practice checklist and learn how to leverage its power to boost your threat protection and reduce attack risks Digitalization is both a blessing and a curse for organizations.…
Blogging About Everything Software Security – Threats, Updates, Best Practices, Tips, & More
Software touches the everyday lives of billions of people around the world. They rely on us (the software industry) to deliver dependable, safe applications for them to use. This blog is dedicated to working together to do our part to make the (software) world a better place…one piece of software at a time!
-

Are you trying to sign your code in Visual Studio and the message ‘An error occurred while signing: SignTool.exe not found’ keeps popping up? Discover how to fix it in a blink of an eye, without compromising the security of your software In 2022, SonicWall identified 6.3 trillion intrusion attempts and 112.3 million examples of IoT malware.…
-

Did you try to sign your code and got stuck on the ‘No certificates were found that met all the given criteria’ error? Find out what causes this mysterious issue and discover the solution that’ll enable you to wave goodbye to it Since its release in 1997, Visual Studio conquered the hearts of developers worldwide. Twenty-six years later,…
-
‘PowerShell Script Is Not Digitally Signed.’ Sounds familiar? Find out what it means, the best way to fix it, and why bypassing this error generated by one of the most exploited attack vectors, could put your organization at risk of attacks PowerShell is a popular command-line shell and scripting language. It’s versatile, easy to use and learn,…
-

In July 2022, ethical hackers identified 648 vulnerabilities in the U.S. Department of Defense’s (DoD) systems during a 7-day bug bounty challenge. Would your web app pass the test? Discover 8 cutting-edge best practices that’ll help you develop secure web apps, minimizing the risk of vulnerabilities and data breaches The 2022 Verizon Data Breach Investigation Report confirmed web applications…
-
In 2022, Google Play and App Store hit the mark of 142 billion downloads. Have you just downloaded software and Windows blocked it because the publisher could not be verified? Are your customers complaining about the same security warning when trying to install your new app? Discover what lies behind this error and how its tie…
-
Authentication, integrity, non-repudiation. Three magic words that could help your organization save an average of $18,000 in case of a cyberattack. Learn everything about three digital signature uses and find out how, together, they can boost the security of your digital assets From October 2021 to September 2022, Zscaler analyzed billions of encrypted traffic threats. The outcome? 89.9%…
-
How do you spot fake software, emails, and files among the colossal amounts of data consumed every year (e.g., more than 100k exabytes in 2022 alone, according to IDC)? Explore how digital signatures can help your organization to guarantee the security, integrity, and authenticity of products and data in the digital world 2023 has barely started and…
-
Are you ready for a year when multifactor authentication may become ineffective and attackers will adopt new hacking vectors like cloud-aware ransomware to get to your data? Learn how to enhance your database security now to stay ahead of cyber threats January isn’t just the first month of the year. It’s the time when organizations start planning their security…
-
Not sure how to bundle a certificate and private key into a .PFX file? We’ll walk you through how to merge your OV code signing certificate and cryptographic private key using OpenSSL As a reputable software developer or publisher, it’s crucial to have a way to show users that your software is authentic and came…
-
Welcome to 2023, a year full of new technology trends. Software development is continually evolving — are you ready to take on the challenge? Let’s start the year with a bang with this list of best software developer courses and training that will help make it the year you’ll take your software developer career to the next level…
-
Do you think that the purpose of hashing is limited to password security? Think again — hashing is much more than that. Discover how, in a world where 82% of breaches involve human elements like errors and misuse, the power of hashing can boost your organization’s security posture in multiple ways €600,000 (more than $637,000 in U.S. dollars).…
-
Get Your Code Signing Certificate Issued in Just 3 Steps It’s great to see that you’ve decided to get that mandatory trust factor: a code signing certificate, which is needed for signing an application or software package to prevent those pesky warning messages which make users run away. For digitally signing your software and apps, using a…
-
Combining your OV code signing certificate and a cryptographic private key is virtually as easy as one, two, and three! Here’s how you can quickly do it using SSL Shopper’s converter tool Code signing certificates enable you to attach your verified digital identity to your software, code, and executables. But before you can use your code…
-
F4baaa8135e0f9a993f0258a4d095db475096896bd3adb48369f1f70c1f0d9d4. Wondering what that is? It’s the file hash for VLC for Windows. Explore the meaning behind gibberish strings like this that are used by many but known by few In 2021, IBM reports that organizations took an average of nine months to identify and contain a data breach. That’s 277 days — more than enough time even for…
-
Have you published or downloaded code today? Did you know that 79.1% of the malware samples reported to Spamhaus in October 2022 were infected .exe files? Discover the potential consequences of releasing or downloading unsigned codes. Find out if, in the digital “wild west,” there’s still a place for unsigned software. Because what you don’t know can…