June 10, 2022
MITRE’s System of Trust framework is aiming to standardize how software supply chain security is assessed. MITRE's Robert Martin explains.
June 7, 2022
The solution to use-after-free bugs is to *not* free memory. Google’s Chrome team is the latest group to jump on the “temporal memory safety” bandwagon.
June 2, 2022
The growing number of software supply chain attacks is putting pressure on validation of software integrity
June 2, 2022
Software engineers are engineers. So why don’t we regulate them—as we do other professions that build critical infrastructure?
June 1, 2022
Source code analysis is always useful. It helps you detect threats early in the dev process. But it shouldn’t be the only tool in your security arsenal.
June 1, 2022
Here's why your software development team needs to think twice before using a powerful third-party plug-in.