DevOps combines culture, skills and tools nicely. But how does security fit in?
We answer this question by keeping our eyes on both — whether it's DevSecOps or SecDevOps, it's about integrating security into DevOps workflows as soon as possible. Find the latest DevOps security trends and challenges in the articles below.
The aftershocks of Log4Shell: RMI and beyond
February 23, 2022, 12:54 am
Developers
Devops
Testers
Java
The SSRF-ability of JNDI has implications beyond Log4Shell - as proven by other, similar vulnerabilities popping up recently.
Read more
The cautionary saga of Log4Shell – Part 3
February 11, 2022, 6:25 pm
Developers
Devops
Testers
Java
What we can learn from the problems that put log4j into the spotlight of software security in the past months.
Read more
The cautionary saga of Log4Shell – Part 2
January 26, 2022, 2:21 pm
Developers
Devops
Testers
Java
Learn why JNDI and LDAP are two flavors that go great together, and what makes Log4Shell important from a secure coding perspective.
Read more
The cautionary saga of Log4Shell – Part 1
January 14, 2022, 1:28 pm
Developers
Devops
Testers
Java
log4j is a popular Java logging component. Let's deep dive into the vulnerabilities that put it in the crossfire recently.
Read more
The science and art of authentication
August 26, 2021, 5:33 pm
Developers
Devops
Securing software is a must, but users also must take care not to expose their credentials. Find out about authentication and password security.
Read more
How account takeover led to the Marriott data breach
June 25, 2021, 8:45 am
Developers
Devops
Case study
Account takeover led to sensitive information leakage at Marriott. Let's see what we can learn from this breach.