ForAllSecure

article thumbnail

Meet The Team Behind Mayhem: Come See Us At These Upcoming June 2023 Events

ForAllSecure

June is here, and we have exciting news queued up for the middle of the month. Stay tuned! Last month, we participated in GlueCon and hosted a webinar on uncovering vulnerabilities in open source software. We have 4 upcoming events planned for June 2023: Mayhem Unleashed Webinar: Discover our Next Generation Security Testing Solution DevSecOps Roundtable CyberSecurity Summit Hartford ForAllSecure APFT (Adversary, Penetration, and FuzzTesting) Training Read on to learn more about June’s eve

article thumbnail

Certificate Transparency Does More Harm Than Good - Here's Why

ForAllSecure

With Google’s recent decision to change the lock icon , I’ve been spending a lot of time thinking about TLS/SSL - and certificate transparency in general. Certificate transparency (CT) mandates the inclusion of TLS/SSL certificates in a global, public registry. First introduced in 2013 by researchers from Google, Certificate transparency (CT) was proposed after the researchers observed that the traditional Certificate Authority model, which relied on a few trusted third-party CAs, su

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

SCA, SBOM, Vulnerability Management, SAST, or DAST Tools: Which Is Best for Your Team?

ForAllSecure

There are a lot of options for software security testing tools. How do you know which ones are right for you? Some types of tools, such as SCA tools, are made to find vulnerabilities in existing code, while others, such as DAST tools, are more useful for finding vulnerabilities in your own code. Some tools only find potential vulnerabilities, while others find confirmed vulnerabilities.

article thumbnail

3 Reasons Your Security Testing Tool Needs To Do Regression Testing

ForAllSecure

You knew that your application was secure when you scanned it for vulnerabilities prior to deploying it into production. But was it also secure when you applied an update or made a configuration change within the production environment? Unless you've performed regression testing, you don't know. Regression testing is the only way to ensure that your software remains secure after you make changes.

article thumbnail

The Hacker Mind Podcast: The Internet As A Pen Test

ForAllSecure

Small to Medium Business are, today, the target of APTs and ransomware. Often they lack the visibility of a SOC. Or even basic low level threat analysis. Chris Gray of Deep Watch talks about the view from the inside of a virtual SOC, the ability to see threats against a large number of SMB organizations, and the changes to cyber insurance we’re seeing as a result.

article thumbnail

Life at ForAllSecure: Robert Vamosi, Director of Product Marketing

ForAllSecure

“Life at ForAllSecure” is a Q&A series dedicated to our growing company. For this month’s profile, we talked with Robert Vamosi , Director of Product Marketing at ForAllSecure and the host of our popular podcast, “The Hacker Mind” Robert joined ForAllSecure in 2020 and is based out of northern California. He is celebrating three years with the company this month.

article thumbnail

Who Shift Left Really Benefits: 4 Responsibilities DevSecOps Shifts Onto Developers

ForAllSecure

DevSecOps has transformed the software development landscape, embedding security practices at each stage of the development and delivery pipeline. While the DevSecOps approach has (rightfully) been lauded for helping teams produce safer software, it has come with its own set of problems. With this “shift left” has come a slew of new processes and tools that have become the responsibility of development teams to learn, follow and use.

Risk 52