August 4, 2022

Post-quantum algo ‘SIKE’ dead: Did math geeks find key-encap back door?

Here’s more on NIST’s search for post-quantum cryptography: This week, is it in trouble?
August 2, 2022

OpenSSF's open source security mobilization initiative: Inside the 10-point action plan

Here is a run-down of the 10 streams from OpenSSF's Open Source Software Security Mobilization Plan.
July 28, 2022

Carbon aims to fix C++ memory safety (and other big flaws)

C++ sucks: It’s unsafe, unergonomic, has far too much legacy cruft and suffers from gatekeepers who won’t move with the times. Enter: Carbon.
July 26, 2022

5 best practices for modern DevSecOps

Here are five best practices that can help you deliver on the potential of DevSecOps to enable better security at the speed of today's software delivery.
July 21, 2022

AI ethics for DevOps: Diversity and ‘Kill All Humans’

AI has a big ethics problem—and it’s down to Dev and Ops to fix it.
July 14, 2022

The state of DevSecOps: Where teams and tools are at—and where they're going

Making security part of development and release demands modern tools — and empowering your software team. Here's what you need to know.