Securing the App Lifecycle: Strategies for Long-Term Software Security and Mitigating the Threat of Malicious Packages - ASW #241
Securing the App Lifecycle: Strategies for Long-Term Software Security and Mitigating the Threat of Malicious Packages - ASW #241

Securing the App Lifecycle: Strategies for Long-Term Software Security and Mitigating the Threat of Malicious Packages - ASW #241

๐”ธ๐•ฉ๐•Ÿ๐•š๐•ช๐•’>33

69 min
News
Play

Description

<p>What happens to an app's security after six months? What about a year or two years? A Secure SDLC needs to maintain security throughout an app's lifetime, but too often the rate of new flaws can outpace the rate of new code within an app. Appsec teams need strategies and processes to keep software secure for as long as possible.</p> <p>Segment Resources:</p> <p><a href= "https://www.veracode.com/state-of-software-security-report">https://www.veracode.com/state-of-software-security-report</a></p> <p>ย </p> <p>Learn how hackers are exploiting the trust that mobile app owners place in their customers. Hackers are increasingly modifying app code, posing as trusted customers, and infiltrating IT infrastructure.</p> <p>This segment is sponsored by Verimatrix. Visit <a href= "https://securityweekly.com/verimatrixrsac">https://securityweekly.com/verimatrixrsac</a>ย to learn more about them!</p> <p>ย </p> <p>Unlike vulnerabilities, which can and do often exist for months or years in application code without being exploited, a malicious package represents an immediate threat to an organization, intentionally designed to do harm. In the war for cybersecurity, attackers are innovating faster than companies can keep up with the threats coming their way. A new approach is needed to stay ahead of the impacts of malicious packages within applications. Findings from our latest report "Malicious Packages Special Report: Attacks Move Beyond Vulnerabilities" illustrate the growing threat of malicious packages. From 2021 to 2022, the number of malicious packages published to npm and rubygems alone grew 315 percent. Mend.io technology detected thousands of malicious packages in existing code bases. The top four malicious package risk vectors were exfiltration, developer sabotage, protestware, and spam. Nearly 85 percent of malicious packages discovered in existing applications were capable of exfiltration โ€“ causing an unauthorized transmission of information. Threat actors leveraging this type of package can easily collect protected i

Uploader

JoanneHill

JoanneHill

Securing the App Lifecycle: Strategies for Long-Term Software Security and Mitigating the Threat of Malicious Packages - ASW #241 - Listen Free | WowFM