Security news aggregator

Latest coverage for DevSecOps

Explore the latest DevSecOps trends and insights in cybersecurity, integrating secure development into your IT operations and software delivery.

38 headlines in this view

Refine the feed

Search across headline titles and summaries.

Tag briefing

Background for this topic.

DevSecOps is the philosophy and practice of integrating security measures seamlessly into the DevOps process. It embodies the idea of incorporating security principles and controls from the very beginning of the software development lifecycle, ensuring that every part of the process from design to deployment considers security implications. This approach enables organizations to create secure software faster and more efficiently by breaking the traditional silos between development, security, and operations teams.

In the context of information security, DevSecOps represents a cultural shift that emphasizes the importance of security as a shared responsibility within the software development process. It leverages automation to implement security checks, threat modeling, code analysis, and vulnerability assessments as part of the continuous integration/continuous delivery (CI/CD) pipeline. The aim is to detect and mitigate security issues early on, thus reducing the risk of security incidents after deployment while maintaining the speed and agility that is characteristic of DevOps practices.

Volume over time

Weekly headline count for the current query.

Showing 20 most recent headlines of 38 Filtered view
Bank Info Security 5 months, 3 weeks ago

Harness Nets $240M at $5.5B Valuation to Advance DevSecOps

Goldman Sachs-Led Round Supports Harness's Push Into AI Security and AutomationWith $200 million in Series E funding and a new $5.5 billion valuation, Harness will scale its AI-powered platform for security, compliance and reliability in software development. The investment will support R&D into AI agents, testing, cost optimization and security for AI workloads.

Prompt Injection, HTML Output Rendering Could Be Used for ExploitHackers can exploit vulnerabilities in a generative artificial intelligence assistant integrated across GitLab's DevSecOps platform to manipulate the model's output, exfiltrate source code and potentially deliver malicious content through the platform's user interface.

Security shouldn't wait until the end of development. Wazuh brings real-time threat detection, compliance, and vulnerability scanning into your DevOps pipeline—powering a stronger DevSecOps strategy from day one. Learn more about how Wazuh can help secure your development cycle. [...]

Merger Combines Application Protection and DevOps to Secure Software at ScaleHarness and Traceable are combining forces to create a DevSecOps platform that seamlessly integrates software delivery with security. The merger addresses the growing need for continuous security along with continuous delivery, ensuring applications remain protected from development to deployment.

Deal Targets Open Source Library Risks in Software Supply Chain, Boosts DevSecOpsThe integration of Tidelift into Sonar's ecosystem will enhance software supply chain security by leveraging human-verified insights from maintainers of popular open source libraries. Developers can expect comprehensive tools to address vulnerabilities in first-party, AI-generated, and third-party code.

Bank Info Security 1 year, 11 months ago

JFrog Acquires Qwak to Strengthen MLOps, DevOps Integration

$230 Million Acquisition of Qwak Enhances Model Deployment and Security FeaturesJFrog's acquisition of Qwak will integrate advanced MLOps capabilities into the company's existing DevSecOps platforms. The transaction aims to improve model deployment efficiency, enhance security measures and integrate AI development features for end-to-end offerings.

Traditional application security practices are not effective in the modern DevOps world. When security scans are run only at the end of the software delivery lifecycle (either right before or after a service is deployed), the ensuing process of compiling and fixing vulnerabilities creates massive overhead for developers. The overhead that degrades velocity and puts production deadlines at risk.

Army Seeking Public Input on $1 Billion Software Modernization Contract VehicleThe U.S. Army is seeking public input on a software development procurement vehicle that aims to enable the rapid development and deployment of secure, modern software as the military branch reforms institutional practices to incorporate DevSecOps into its software development processes.

One of the enduring challenges of building modern applications is to make them more secure without disrupting high-velocity DevOps processes or degrading the developer experience. Today’s cyber threat landscape is rife with sophisticated attacks aimed at all different parts of the software supply chain and the urgency for software-producing organizations to adopt DevSecOps practices that deeply

Bank Info Security 2 years, 2 months ago

GitLab Acquires Oxeye to Bolster SAST in DevSecOps Workflow

Acquisition Promises Enhanced Application Security and Reduced False PositivesThe integration of Oxeye into GitLab’s suite marks a significant leap in the accuracy and efficiency of security scans, directly addressing the challenge of false positives in static application security testing and enhancing software security across development stages, according to GitLab.

In the fast-paced cybersecurity landscape, product security takes center stage. DevSecOps swoops in, seamlessly merging security practices into DevOps, empowering teams to tackle challenges. Let's dive into DevSecOps and explore how collaboration can give your team the edge to fight cyber villains

Loading more headlines...