Feb 05, 2026/6 min read Event-driven AppSec is here: Thoughtful automation finds risk earlier Feb 05, 2026 | 6 min read
Feb 04, 2026/2 min read The BSIMM16 report: What today’s software security programs are really doing—and why it matters Chai Bhat Feb 04, 2026 | 2 min read
Jan 13, 2026/2 min read CyRC advisory: Vulnerability in Broadcom chipset causes network disruption and client disconnection on wireless routers Kari Hulkko Jan 13, 2026 | 2 min read
Dec 16, 2025/4 min read Bridging the divide: Why friction between dev and security persists (and how to fix it) Steven Zimmerman Dec 16, 2025 | 4 min read
Sep 18, 2025/2 min read The Shai-Hulud npm malware attack: A wake-up call for supply chain security Mike McGuire Sep 18, 2025 | 2 min read
Aug 04, 2025/3 min read The Importance of a Third-Party Due Diligence Perspective on Code Risk Phil Odence Aug 04, 2025 | 3 min read
Jul 31, 2025/5 min read Faster, Smarter Vulnerability Alerts: AI in Black Duck Security Advisories Mike McGuire Jul 31, 2025 | 5 min read
Jul 17, 2025/7 min read Navigating the EU Cyber Resilience Act Corey Hamilton, Fred Bals Jul 17, 2025 | 7 min read
May 22, 2025/5 min read Q&A: What You Need to Know About Open Source Software Risk in 2025 Fred Bals May 22, 2025 | 5 min read
Nov 04, 2024/6 min read Major changes and challenges of PCI DSS 4.0 John Waller Nov 04, 2024 | 6 min read
Oct 24, 2024/3 min read Understanding generative AI risks in software development Phil Odence Oct 24, 2024 | 3 min read