Tag: programming
-
The number of Android memory safety vulnerabilities has tumbled, and here’s why
Google’s decision to write new code into Android’s codebase in Rust, a memory-safe programming language, has resulted in a significant drop in memory … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/09/26/android-memory-safety-vulnerabilities/
-
Google’s Shift to Rust Programming Cuts Android Memory Vulnerabilities by 52%
Google has revealed that its transition to memory-safe languages such as Rust as part of its secure-by-design approach has led to the percentage of me… First seen on thehackernews.com Jump to article: thehackernews.com/2024/09/googles-shift-to-rust-programming-cuts.html
-
Google Pushes Rust in Legacy Firmware to Tackle Memory Safety Flaws
Google’s adoption of memory safe programming languages now includes the deployment of Rust in legacy low-level firmware codebases. The post Google Pus… First seen on securityweek.com Jump to article: www.securityweek.com/google-pushes-rust-in-legacy-firmware-to-tackle-memory-safety-flaws/
-
The Hidden Costs of Progress: Navigating the Challenges of Upgrading from Spring Framework and Spring Boot EOL Versions
Software development is a fast-paced world where progress is both a blessing and a curse. The latest versions promise new features, improved performan… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/08/the-hidden-costs-of-progress-navigating-the-challenges-of-upgrading-from-spring-framework-and-spring-boot-eol-versions/
-
How to Choose an LLM in Software Development
With so many Large Language Models (LLMs) out there, selecting the right LLM is crucial for any organization looking to integrate AI into its operatio… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/08/how-to-choose-an-llm-in-software-development/
-
Survey Surfaces Growing SaaS Application Security Concerns
A survey of 300 application and software development, IT and security leaders finds nearly half (45%) working for organizations that, in the past year… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/08/survey-surfaces-growing-saas-application-security-concerns/
-
CrowdStrike pursuing deal to buy patch management specialist Action1
The security firm;is still working to overhaul its internal software development practices following the July 19 global IT outage involving millions o… First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/crowdstrike-pursuing-deal-action1/723849/
-
Navigating Security Threats with Return-Oriented Programming
Assistant Professor Bramwell Brizendine on Process Injection, Advanced Mitigation. Return-oriented programming continues to pose significant security … First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/navigating-security-threats-return-oriented-programming-a-26035
-
Strobes Integrates with Azure Repos: Enhancing Code Security
As software development reaches new heights, ensuring the security and management of your code is more crucial than ever. Seeing the need of the hour,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/08/strobes-integrates-with-azure-repos-enhancing-code-security/
-
Two Python Vulnerabilities Addressed in Ubuntu
Canonical has released critical security updates to address two vulnerabilities in Python, a popular programming language. These vulnerabilities pose … First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/08/two-python-vulnerabilities-addressed-in-ubuntu/
-
15 vulnerabilities discovered in software development kit for wireless routers
Talos researchers discovered these vulnerabilities in the Jungle SDK while researching other vulnerabilities in the LevelOne WBR-6013 wireless router…. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/vulnerability-roundup-july-10-2024/
-
DARPA Unveils TRACTOR Initiative: Transforming Legacy C Code to Rust with AI
In a groundbreaking move, the US Defense Advanced Research Projects Agency (DARPA) is embarking on an ambitious project to modernize programming pract… First seen on thecyberexpress.com Jump to article: thecyberexpress.com/darpas-tractor/
-
Coding practices: The role of secure programming languages
Tags: programmingSafety and quality are not features that can be added through testing, they must be integral to the design. Opting for a safer or more secure language… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/07/30/secure-programming-languages/
-
Nearly 1 in 3 software development professionals unaware of secure practices
<p>The knowledge gap, identified in a Linux Foundation report, comes as malicious hackers increasingly target critical vulnerabilities.</p>… First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/1-in-3-software-unaware-secure-practice/721481/
-
ShapeUp at Flare: A Game-Changer for Project Management
By Benoit Doyon, Software Development Team Lead I first encountered ShapeUp during one of my initial interviews for a position at Flare. My soon-to-be… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/shapeup-at-flare-a-game-changer-for-project-management/
-
Crossbeam Leverages DataGuard to Ensure HighLevel Data Protection
ABOUT Industry:Software Development Size:115 employeesPrivate Team:Chris Castaldo, CISO ABOUT CROSSBEAM Crossbeam is a collaborative ¨data platform th… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/crossbeam-leverages-dataguard-to-ensure-highlevel-data-protection/
-
Week in review: A need for a DDoS response plan, human oversight in AI-enhanced software development
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: 4 key steps to building an incident response plan In… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/07/07/week-in-review-a-need-for-a-ddos-response-plan-human-oversight-in-ai-enhanced-software-development/
-
Critical GitLab Bug Threatens Software Development Pipelines
First seen on darkreading.com Jump to article: www.darkreading.com/application-security/critical-gitlab-bug-threatens-software-development-pipelines
-
Maintaining human oversight in AI-enhanced software development
In this Help Net Security, Martin Reynolds, Field CTO at Harness, discusses how AI can enhance the security of software development and deployment. Ho… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/07/03/martin-reynolds-harness-rogue-ai-generated-code/
-
Understanding the Risks of Transitive Dependencies in Software Development
Transitive dependencies are one of the biggest headaches software developers must manage. Relationships between software components are complex (to sa… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/understanding-the-risks-of-transitive-dependencies-in-software-development/
-
What Building Application Security Into Shadow IT Looks Like
AppSec is hard for traditional software development, let alone citizen developers. So how did two people resolve 70,000 vulnerabilities in three month… First seen on darkreading.com Jump to article: www.darkreading.com/application-security/building-application-security-into-shadow-it
-
eBook: The Art Science of Secure Software Development
Software security requires a creative and disciplined approach. It involves having the vision to develop secure strategy, tactics, and execution. Exce… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/18/secure-software-development-ebook/
-
US Army Unveils $1B Modern Software Development Initiative
Army Seeking Public Input on $1 Billion Software Modernization Contract Vehicle. The U.S. Army is seeking public input on a software development procu… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/us-army-unveils-1b-modern-software-development-initiative-a-25357
-
Can memory-safe programming languages kill 70% of security bugs?
The Office of the National Cyber Director (ONCD) recently released a new report, “Back to the Building Blocks: A Path Toward Secure and Measurab… First seen on securityintelligence.com Jump to article: securityintelligence.com/news/memory-safe-programming-languages-security-bugs/
-
New R Programming Vulnerability Exposes Projects to Supply Chain Attacks
A security vulnerability has been discovered in the R programming language that could be exploited by a threat actor to create a malicious RDS (R Data… First seen on thehackernews.com Jump to article: thehackernews.com/2024/04/new-r-programming-vulnerability-exposes.html
-
R Programming Bug Exposes Orgs to Vast Supply Chain Risk
The CVE-2024-27322 security vulnerability in R’s deserialization process gives attackers a way to execute arbitrary code in target environments via sp… First seen on darkreading.com Jump to article: www.darkreading.com/application-security/r-programming-language-exposes-orgs-to-supply-chain-risk
-
The Persistent Threat of Path Traversal Vulnerabilities in Software Development
Path traversal vulnerabilities, or directory traversal, are now subject to a government advisory for obligatory consideration We live in an environmen… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/05/the-persistent-threat-of-path-traversal-vulnerabilities-in-software-development/
-
A flaw in the R programming language could allow code execution
A flaw in the R programming language enables the execution of arbitrary code when parsing specially crafted RDS and RDX files. A vulnerability, tracke… First seen on securityaffairs.com Jump to article: securityaffairs.com/162591/security/r-programming-language-flaw.html
-
R language flaw allows code execution via RDS/RDX files
A new vulnerability has been discovered in the R programming language that allows arbitrary code execution upon deserializing specially crafted RDS an… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/r-language-flaw-allows-code-execution-via-rds-rdx-files/

