As software systems grow more complex, proving that they are secure has become as important […]
Automated Application Security Testing (AAST) refers to the use of software tools to identify vulnerabilities[…]
Developers are under pressure to deliver fast, but often without the tools to build securely.[…]
Application security (AppSec) remains one of the toughest challenges modern organizations are facing. Despite heavy[…]
Finding vulnerabilities is not the hard part anymore. Every build and every pipeline produces a[…]
Your DevSecOps pipeline is fast, automated, and built to scale. But is security truly integrated,[…]
About 4 years ago I have joined the OWASP Software Assurance Maturity Model (SAMM) project[…]
In this technical article, we will explore how to improve your DevSecOps processes by integrating[…]
Most security issues in software stem from one simple problem: teams try to fix them[…]
Dependency management has become one of the most critical aspects of modern software development. Third-party[…]
Official framework, regulation and standard pages mentioned in this article CRA GDPR OWASP SAMM[…]
Threat modeling shaped my AppSec career. It helped me wrestle with one of security’s most[…]











