
State of development: 5 key AppSec steps
Application security pros need to be ready to cope with security at the speed of code. Here's how to get a handle on modern software risk.

Freelance technology writer. John's work has appeared in the The Boston Globe and Boston Herald, as well as CFO, CIO, CSO, and Inc. magazines. He is a former managing editor of the Boston Business Journal and Boston Phoenix, as well as a staff writer for Government Security News.
find John P. Mello Jr. on:

Application security pros need to be ready to cope with security at the speed of code. Here's how to get a handle on modern software risk.

The new AI Vulnerability Scoring System (AIVSS) picks up where the Common Vulnerability Scoring System (CVSS) falls short.

Triaging and patching, plus meeting compliance demands, all bog down modern software teams — and divert time away from development.

Replacing software engineers with AI won't be happening soon — but AI coding is already changing the software risk landscape. Is your company prepared?

EU steps up to fill gaps from the US NVD and CVE. Here's what you need to know — and why you need to think beyond vulnerabilities.

Agentic AI is a different animal for application security red teams. Here are key takeaways from the Cloud Security Alliance's new guide.

The new tool provides a low-cost approach to testing the security of generative AI chat experiences — though it lacks out-of-band AI controls.

Experts say scan-and-fix will remain for some time. But application security tools are evolving to provide prioritization and automation.

Virtual-machine ubiquity requires rethinking traditional AppSec controls — and modernizing your approach. Here are essential considerations.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial