AppSec Observer

Contrast's application security blog provides the latest trends and tips in DevSecOps through instrumentation and security observability.

Subscribe Now
    Topics

    DevOpsCon keynote: CISO Brian Vlootman on defending Backbase banking applications in production

    Read more

    What is Automated Penetration Testing? A Complete Guide for Modern AppSec Teams

    Read more

    Accelerate response with Contrast Security and Datadog SIEM

    Read more

    Vulnerability Escape Rate: Why 17 New Vulnerabilities Per Month Demands Graph Intelligence

    Read more

    How Runtime Intelligence Transforms AI Vulnerability Remediation

    Read more

    Application Attack Patterns: Understanding the Runtime Visibility Gap

    Read more

    Log4j Vulnerability: Complete Guide to Detection and Protection

    Read more

    Contrast and Microsoft Sentinel: Closing the Application-Layer Blind Spot

    Read more

    How Real Teams Are Powering AI Security with the Contrast MCP Server

    Read more

    Dynamic Application Security Testing (DAST) Can't Keep Pace with AI-Generated Code: The Runtime Security Imperative

    Read more

    How Runtime Intelligence Transforms AI Vulnerability Remediation

    Read more

    48-Hour Case Study: Analyzing Coordinated Attacks from Mumbai, India

    Read more

    Slopsquatting: How Attackers Exploit AI-Generated Package Names

    Read more

    Contrast Named a Visionary in the 2025 Gartner® Magic Quadrant™ for Application Security Testing

    Read more

    Contrast Security Collaborates with IBM Consulting to Tackle the Application-Layer Blind Spot

    Read more

    Beyond SAST & DAST: Using IAST to Pinpoint Exploitable Application Vulnerabilities

    Read more

    Beyond the perimeter: Bringing application context into IBM QRadar with Contrast ADR

    Read more

    Why Security Tool Consolidation Fails: Your Tools Can't See Where Attacks Happen

    Read more

    Runtime Application Security: Why EDR and WAF Can't See Application Attacks

    Read more

    NPM Supply Chain Hijack: How ADR Transforms Incident Response

    Read more

    Defending Education: How ESC-20’s Martha Gamez-Smith Is Protecting Students and Teachers from Rising Cyber Threats

    Read more

    July ADR Report: Concentrated, targeted attacks and a 2-million-attack surge, all stopped in real-time

    Read more

    New Partnership: Contrast and Sumo Logic Unite to Close the Application Layer Attack Gap

    Read more

    Making Sense of the SharePoint 'ToolShell' Zero-Day and Insecure Deserialization

    Read more

    Contrast Report: Software Under Siege 2025. What trillions of security signals teach us about today’s application and API threats

    Read more

    Runtime & ADR are reshaping security for applications and APIs: What CISOs should take from IDC’s commentary on Contrast

    Read more

    Virtual patching surges: How Contrast ADR is defending apps in real-time amid rising retail attacks

    Read more

    Perimeter defenses aren’t enough — Why in-app security and ADR are the future

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 06/13/25

    Read more

    ADR catches the SQLi, unsafe deserialization & path traversal attacks WAFs/EDRs miss

    Read more

    The future of AppSec is here. Contrast Northstar: Unified, real-time and AI-powered

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 06/06/25

    Read more

    AI's speed paradox: Security is being left behind

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 05/30/25

    Read more

    Go Agent Dev Diary: Navigating os.Root and path-traversal vulnerabilities

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 05/23/25

    Read more

    Forrester’s 2025 SAST Landscape report explains urgency of security software

    Read more

    Supercharge your vulnerability remediation with Contrast MCP

    Read more

    Monthly ADR Report for April: 2 million attacks in a day, all blocked!

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 05/16/25

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 05/09/25

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 05/02/25

    Read more

    Fixing the application security blindspot with Contrast ADR

    Read more

    Research uncovers: EDR's blindness to application exploits, WAF's inability to cut through the noise

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 04/25/25

    Read more

    Wiz and Contrast Security join forces to deliver clear visibility into application vulnerabilities

    Read more

    The unseen threat: Why reactive security fails against the rising tide of zero-day attacks

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 04/18/25

    Read more

    From chasing dragons to streamlined incident response: Speeding up SOC threat detection while reducing frequency

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 04/11/25

    Read more

    Monthly ADR Report: Untrusted deserialization tops March’s application attacks chart

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 04/04/25

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 03/28/25

    Read more

    From chasing dragons to streamlined incident response: Speeding up SOC threat detection while reducing frequency

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 03/21/25

    Read more

    Application Detection and Response analysis: Why ADR? How ADR works and ADR benefits

    Read more

    The Top 6 big PCI DSS 4.0 changes and how to prepare your security teams

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 03/14/25

    Read more

    Monthly ADR Report: Application attacks jump 30%; method tampering up 800%

    Read more

    Software defects = potential lawsuits

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 03/07/25

    Read more

    Enhancing Application Security with Contrast ADR and Splunk

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 02/27/25

    Read more

    4 ways ADR will slash workload and speed incident response for IR teams

    Read more

    Monthly ADR Report: Attacks up month to month, but especially one app

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 02/21/25

    Read more

    AI Remediation: Introducing intelligent remediation guidance

    Read more

    How the SOC can navigate the treacherous waters of application threats with ADR

    Read more

    Application Detection and Response: 12 things to know about ADR

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 02/07/25

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 01/31/25

    Read more

    DORA mandates have landed: Ready for a 4-hour incident reporting window?

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 01/24/25

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 01/17/25

    Read more

    Silent but deadly: December sees deserialization attacks surge despite overall lull in app attacks

    Read more

    Unpacking the SEC cybersecurity reporting rules: Enhance compliance efforts and reduce risk with ADR

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 01/10/25

    Read more

    Experts: Why the Log4Shell Grinch is still hanging around

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 12/20/24

    Read more

    Contrast One: Managed AppSec Service. We built it. Now we'll run it for you.

    Read more

    Log4Shell Vulnerability: Three years later & Log4j is still burning down the house

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 12/13/24

    Read more

    November: The top attacks ADR caught on the brink of exploit

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 12/06/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 11/22/24

    Read more

    Ensuring vigilant digital transformation in the financial sector

    Read more

    Smarter AppSec: How ADR, secure by design and 'shift smart' are redefining cybersecurity

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 11/15/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 11/8/24

    Read more

    October attack data: The Expression Language injection attacks that skipped past SAST/DAST/WAFs

    Read more

    Preparing for PCI DSS v4.0.1, the latest version of PCI

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 11/1/24

    Read more

    If only I’d known ADR was possible when I was a SOC analyst!

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 10/25/24

    Read more

    Bringing the application layer into cybersecurity monitoring and response

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 10/18/24

    Read more

    Wake up, CISOs: You need an ADR flashlight to see into critical application blindspots

    Read more

    September attack data: Spotlight on path traversal, one of the gnarliest application attack types

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 10/11/24

    Read more

    Analyst: Application Detection and Response is an ‘emerging category’

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 10/04/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 09/27/24

    Read more

    Anatomy of an attack

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 09/20/24

    Read more

    August attack data: A look beyond the numbers

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 09/13/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 9/6/24

    Read more

    Award Finalist: Contrast Security Application Detection and Response

    Read more

    Understanding ADR’s detection and response layers

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 8/30/24

    Read more

    Why Application Detection and Response (ADR) is sparking excitement in cybersecurity

    Read more

    5 ways Contrast Security ADR closes the App and APIs gap in EDR, NDR and XDR tools

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 8/16/24

    Read more

    Contrast Security founder Jeff Williams explains how to fix AppSec in production

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 8/9/24

    Read more

    Why Contrast Security is making the case for Application Detection and Response (ADR) in AppSec

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 8/2/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 7/26/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 7/19/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 7/12/24

    Read more

    Contrast discovers CSRF vulnerability in NSA’s SkillTree training platform that allows attackers to modify content

    Read more

    Cybersecurity Insights with Contrast SVP of Cyber Strategy Tom Kellermann | 6/28

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 6/21/24

    Read more

    Contrast wins 2024 PwC Luxembourg Award for Cybersecurity & Privacy Solution of the Year

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 6/14/24

    Read more

    How Contrast ‘secures from within:’ Code vulnerabilities set off smoke alarms; runtime incidents & cyberattacks trigger the sprinklers

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 6/07/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 5/31/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 5/24/24

    Read more

    Contrast Security discovers Netflix OSS Genie bug that can lead to RCE during file upload

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 5/17/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 5/10/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 5/3/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 4/26/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 4/19/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 4/12/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 4/5/24

    Read more

    CISA asks software devs to stamp out ‘unforgivable’ SQL injection vulnerabilities

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 3/29/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 3/22/24

    Read more

    What’s a basketball got to do with Application Security instrumentation?

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 3/15/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 3/8/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 3/1/24

    Read more

    How to use Runtime Security to protect risks to both APIs and legacy COTS

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 2/23/24

    Read more

    Elevating Node.js security with the latest v5 Node agent

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 2/16/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 2/9/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 2/2/24

    Read more

    Critical zero-day Confluence RCE vulnerability blocked by Contrast Runtime Security

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 1/26/24

    Read more

    6 cybersecurity best practices for safeguarding sensitive data

    Read more

    Data Privacy Week: Are you ready to become a data privacy snob?

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 1/19/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 1/12/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 1/5/24

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 12/15/23

    Read more

    It’s time to replace our broken AppSec tools with something that actually works: Runtime Security

    Read more

    Cybersecurity Insights with Contrast SVP of Cyber Strategy Tom Kellermann | 12/8

    Read more

    Contrast Security recognized in the 2023 Gartner® AppSec Testing Voice of the Customer report

    Read more

    Contrast discovers MLflow framework zero-day that threatens to poison machine language models

    Read more

    Cybersecurity Insights with Contrast SVP of Cyber Strategy Tom Kellermann | 12/1

    Read more

    Don’t throw good AppSec money after bad

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 11/24

    Read more

    Let’s talk stats: Why AppSec’s running on broken math

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 11/17

    Read more

    False positives + false negatives = real costs

    Read more

    Attack-path mapping your applications

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 11/10

    Read more

    Four things CISOs should do NOW to protect from being scapegoated

    Read more

    Contrast expands SAST coverage to 30 new languages

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 11/3

    Read more

    Security Observability: Intelligent security assessment = seeing what others can’t

    Read more

    Cybersecurity Awareness Month: How Contrast & the threat landscape have evolved

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 10/27

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 10/20

    Read more

    The evolution of island hopping

    Read more

    3 ways Contrast helps to build digital resilience

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 10/13

    Read more

    6 of the biggest GitHub application security threats

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 10/6

    Read more

    The top 8 AWS root user account best practices

    Read more

    Contrast Security champions Cybersecurity Awareness Month: #SecureOurWorld

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 9/29

    Read more

    Runtime Security Tools: Learn about the hidden dangers of traditional AppSec tools and why Runtime Security is replacing them

    Read more

    Your WAF doesn't have your back

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 9/22

    Read more

    Contrast Security serves up vulnerability data integrated into AWS Security Hub

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 9/15

    Read more

    Why we shouldn't treat the CVSS base score as gospel

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 9/8

    Read more

    Trust ‘zero trust’ for Application Security

    Read more

    3 reasons why upskilling the nation’s cybersec savvy won’t solve the skills gap

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 9/1

    Read more

    Contrast Assess uncovers Spring-Kafka deserialization zero day

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 8/25

    Read more

    Legal liability for insecure software might work, but it's dangerous

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 8/18

    Read more

    Cybersecurity Insights with Contrast CISO David Lindner | 8/11

    Read more
    1 2