Skip to content

AppSec Observer

Contrast's application security blog provides the latest trends and tips in DevSecOps through instrumentation and security observability.

Subscribe Now
    Topics
    How to protect against CVE-2022-42889

    How to protect against CVE-2022-42889

    A new Common Vulnerability and Exposure (CVE) — CVE-2022-42889, aka Text4Shell — was recently released, adding to the..

    OMB M-22-18: Get ready for grilling

    OMB M-22-18: Get ready for grilling

    Do you swear to tell the truth about your secure software development, the whole truth and nothing but the truth?

    Code Patrol: And now our watch begins!

    Code Patrol: And now our watch begins!

    Welcome to Code Patrol: a new podcast from Contrast Security that scrutinizes the tech scene with what I like to call..

    Cybersecurity Insights with Contrast CISO David Lindner | 10/28

    Cybersecurity Insights with Contrast CISO David Lindner | 10/28

    Insight #1 " CVSS score does not directly relate to the risk to your organization. Please for everyone’s sake,..

    Cybersecurity Insights with Contrast CISO David Lindner | 10/21

    Cybersecurity Insights with Contrast CISO David Lindner | 10/21

    Insight #1 "Contrast Labs has been monitoring the new CVE, Apache Commons Text interpolation CVE-2022-42889. While..

    AppSec and the ‘Ugly-Baby' syndrome

    AppSec and the ‘Ugly-Baby' syndrome

    As a developer, have you ever been told your baby is ugly?

    It’s SBOM time!

    It’s SBOM time!

    A new memo (PDF) from the Office of Management and Budget (OMB) — M-22-18, published last month — is clear in setting..

    Does Cybersecurity Awareness Month matter?

    Does Cybersecurity Awareness Month matter?

    This year, as Contrast Security Chief Information Security Officer David Lindner announced last week, Contrast was once..

    CVE-2022-42889: Don’t panic, do patch

    CVE-2022-42889: Don’t panic, do patch

    There’s a new Common Vulnerability and Exposure (CVE) getting some buzz: Apache Commons Text, which is exploitable via..