ZeroDay Labs blog

ZeroDay Labs blog

Read our blog for the latest on application security testing, analysis, and metrics.

  • The Sad Story of Mr. Fails!
    As you know, we love Security Testing! But there is a whole other world of software testing out there ? functional, black box, white box, integration, unit, you know what I mean… One of my favorite resources on software testing is the Software Testing Club. They have a great blog, a quarterly printed publication called [...]
  • A Tale of Two Market Sizes
    According to market researcher DataMonitor the size of the global software market is forecast to have a value of $299.1 billion in 2014, an increase of 32.6% since 2009. According to them, the computer software market consists of systems and application software. Systems software comprises operating systems, network and database management and other systems software. [...]
  • FBI Gets Bitten by Operational Security
    At corporations and government offices around the world a security failure happens every day. Employees forward confidential calendar events and messages to personal calendars and personal email accounts. This may make their jobs easier but it can put their companies at risk. A recent security incident involving the FBI can teach us something about corporate [...]
  • Weekly News Roundup
    Welcome to our Weekly News Roundup. Read on to learn about the latest this week in the world of security, put together for you by our marketing team. Enjoy! 1. Android users potentially hit by malware attacks: Two possible Android attacks, one, according to Symantec, due to thirteen applications from three different developers that have [...]
  • Penny Wise, Pound Foolish ? Avoiding Security Spend Pitfalls: A Conversation with Wendy Nather
    If your organization had an unlimited budget to spend on your enterprise security program, in what areas would you focus investments? Application security? Mobile strategy? Web Application Firewalls? Wendy Nather from the 451 Group and Veracode?s CTO Chris Wysopal presented the latest research on enterprise security spend, and discussed how to “make the case” for [...]
  • Answering Customer Questions ? What is an application?
    One re-occurring question we get is ?What is an application?? which on the surface of things sounds trite ? after all, every one of us uses applications every day for one thing or another. Yet the initial success of a fledging application security program often depends on answering that question. When discussing software that runs [...]
  • Top Ten Java Frameworks Observed in Customer Applications
    One of the great things about the Veracode platform is the insight we get from examining our anonymized customer data – not only information about the vulnerability landscape (as published in the State of Software Security report) but insight into the composition of the applications that we scan. As I alluded in my last post, [...]
  • Weekly News Round Up
    Happy Friday everybody, and welcome to another installment of our Weekly News Roundup. It certainly was another busy week in the application security world, with several cyber attacks, new regulations, and updated security measures making headlines. Veracode?s Marketing team rounded up some interesting articles on some of the biggest topics of the week. Give them [...]
  • A Conversation With Richard Clarke ? Part II
    In continuation of yesterday?s piece on Chris Wysopal?s discussion with cyber-security guru Richard Clarke, this second installment focuses on questions asked by webinar participants in the live webcast. Remember, you can always download and view the recorded versions of our webinars here. Q: Are you concerned about the merge to electronic healthcare records? RC: Yes [...]
  • A Conversation with Richard Clarke ? Part I
    Following a dramatic increase in the number and severity of breaches in 2011, Chris Wysopal and internationally-renowned cyber security expert Richard Clarke discuss the changing cyber threat environment, the evolving cyber legislation landscape, and steps you can take to strengthen your organization?s resilience to the current threat environment while complying with evolving regulations. This well-attended [...]