Please download one of these browsers:
Keep your browser version up-to-date for a fast, secure, web experience.
Secure Development
Building software with security best practices to prevent vulnerabilities.
Tal Kollender highlights how human errors and default settings lead to 80% of ransomware attacks. Discover the risks of manual remediation and how automation can reduce misconfigurations, shrinking the attack surface and enhancing network protection.
Version control is a cryptic yet essential part of a software development team. Git is a distributed version control system that allows collaboration and management of large scale software products (as well as other types of projects)
The AWS Certified DevOps Engineer professional certification is a course from Amazon Web Services (AWS) that tests a candidate's ability to deploy, manage, and maintain distributed applications on AWS.
Learn about types of vulnerabilities, the exploits that can occur from those vulnerabilities, and the programming practices that will help prevent exploitation in an application!
Jonathan Andresen, Senior Director, Marketing and Products, Asia Pacific and Japan, Bitglass examines the shift to Secure Access Service Edge (SASE) architecture in response to evolving cyber threats like the SolarWinds breach. Learn about modern breach trends, SASE's key pillars, and the cost-benefit analysis of SASE protection versus data breaches.
Learn DevOps concepts and principles. Become a DevOps Professional. Prepare for the EXIN DevOps Professional certification exam.
Prepare for the EXIN DevOps Professional certification. Learn DevOps concepts, principles, and practice with sample exams.
In this series, we are going to take a look at programming using the Python programming language. If you have tried to start before and just spun your wheels, then you should give it a try again.
In this series we expand on our Agile Foundation qualification and look at the specific role of the Scrum Master in Agile project management. We also prepare for the EXIN accredited Agile Scrum Master certification.
The Cisco Certified DevNet Associate (200-901) show is produced to help the software developer, networking professional and IT professional to achieve the latest Cisco certification offer, the Cisco Certified DevNet Associate certification.
This course is designed to teach you about the 2021 version of the OWASP Top 10 Web Application Vulnerabilities. The OWASP Top 10 is a list of the most critical security risks to web applications, and it is widely used by organizations to improve their web application security.
Learn how to do more with less! Join Vishak Raman in a discussion of cybersecurity mesh architecture, designed to make security more composable and scalable.
Join Prem Nithin R in an exploration of Fortinet and mesh architecture.
Join a conversation with healthtech cybersecurity experts Phil Englert, Patty Ryan, Anahi Santiago and Luisa Soares de Brito in a conversation about managing hospital device security.
Dive into the world of MinIO security as we uncover and exploit an information disclosure vulnerability, gaining access to sensitive data.
James Kettle of PortSwigger reveals sophisticated web race condition exploits, demonstrating how attackers can manipulate state machines and create backdoors through precise timing attacks.
Security researcher Nemo examines UPI's security architecture, revealing critical vulnerabilities in mobile number verification and offering recommendations to strengthen India's digital payment ecosystem.
Veracode CISO Sohail Iqbal provides guidance on prioritizing software security and effectively communicating metrics to board members.
Learn from Christophe Barel about securing supply chains, adopting shift-left strategies, and managing open-source risks. Explore frameworks for secure coding, automated security-by-design, and faster detection and remediation of supply chain attacks.
Bryan Rosensteel of Wiz explains how AI has collapsed the time to exploit, why siloed security fails in the cloud, and how visibility and context let defenders prioritize true risk.
Don Codling and Craig Darling examine security-by-design principles for AI, cloud and enterprise architecture, covering governance, compliance, identity security, threat modeling and strategies for building resilient technology environments.
Chip Witt of Radware examines how AI is expanding the healthcare attack surface, accelerating cyberattacks and introducing prompt injection risks, while outlining practical strategies to secure APIs and AI-powered applications.
Allan Tay of Singapore Pools makes the case for security-by-design as a leadership mandate, showing how governance, cloud accountability and responsible AI adoption protect enterprises from costly breaches.
Will Eatherton of Cisco examines why hardware reliability has become strategically critical in the AI era, covering defensive design, observability at hyperscaler scale and lessons from access to Anthropic's Mythos model.
Marcus Richerson, James DeLuccia and Aaron Guzman walk through a supply chain firmware implant from three perspectives - builder, assessor and product security team - and ask why hardware security still has no equivalent of EDR.
Visagan Subburayalu, Dr. Vishal Saraswat and Amol Naik debate who owns AI-generated code security and how organizations can balance developer velocity with accountability, guardrails and human-in-the-loop controls.
Sonya Moisset of Snyk breaks down the security risks of AI-assisted engineering - from slopsquatting to weaponized agents - and shares a five-layer playbook to secure your AI-powered software development life cycle.
Denis Maligin of Chainguard examines how open-source supply chain attacks reach production environments and how zero-CVE images and software bills of materials address the Cyber Resilience Act.
Intuitive's David Scott explores how secure-by-design practices, governance, supply chain assurance and incident readiness help build trust, resilience and safer outcomes.
Daniella Drori traces AppSec's evolution from siloed, alert-heavy scanners to context-aware security, showing how cross-scanner correlation and AI-aware tooling close the gap between what gets detected and what actually gets fixed.
Carlos Luque Dengra, Cristina Domingo, Manuel Asenjo, Miguel Cebrián Lindström, Angel Arias Baelo and Jorge Baena examine the blind spots, regulatory pressures and practical approaches shaping supply chain security in 2026.
Thejes Sree Satheesh Kumar and Srinivasan Sekar examine how AI agents using protocols like MCP create unmonitored toolchain attack surfaces and why traditional security models are unequipped to defend them.
Rishav Raj and Rajkumar Rathod of FIS demo VISTA, an open-source Burp Suite extension that integrates LLM reasoning into penetration testing workflows without replacing human judgment.
Ashish Kataria of Synacor examines how modern sanitization pipelines can inadvertently introduce XSS vulnerabilities through structural mutations, namespace confusion and multi-stage parser mismatches.
SoYeon Kim, Hea-Eun Moon and Sang-tae Woo of NSHC share lessons from organizing ACDC 2025, Korea's first AI security CTF, covering challenge design, unintended AI-powered solutions and format pitfalls.
Venkatesh Vanjaku of CloudSEK discusses proactive measures for identifying and mitigating software supply chain risks in the modern digital ecosystem.
The transition from DevOps and CI/CD to cloud-native technologies, microservices architecture, security, and governance, and ultimately automation and artificial intelligence, necessitates a modern approach to software supply chain management.
Gaetan Labat shares cost-effective strategies for embedding security into projects, covering early visibility techniques, risk prioritization, streamlined documentation and practical acceptance procedures.
Snyk's Shilpa Raghunathan explores effective ways to identify malicious code and secure first-party code in supply chains using security-by-design principles.
Panelists Pramod Kumar Dubey, Pradipta Patro and Lalit Trivedi discuss C-suite priorities, tool integration, and automation in DevSecOps implementation.
Theresa Lanowitz reveals key findings from LevelBlue's 2024 research on healthcare cyber resilience, exploring barriers, priorities and strategic solutions for the evolving digital landscape.
Damian Stephenson examines the dramatic shift from AI skepticism to adoption, exploring strategic transformation approaches across the AI capability spectrum.
Ian Bramson of Black & Veatch explores building security into new industrial construction projects using Cyber Asset Lifecycle Management frameworks.
Sean Mack shares how DevSecOps transforms security from obstacle to competitive advantage by embedding protection into development workflows, enabling teams to move faster while reducing risk through proper road maps and guardrails.
Imran Khan examines the latest supply chain attack tactics, revealing hidden vulnerabilities in vendor relationships and third-party dependencies that can lead to catastrophic breaches in financial services.
Theresa Lanowitz of LevelBlue presents 2025 research on AI attack preparation, software supply chain management and risk mitigation strategies for healthcare innovation.
Nathan Haselhorst, Jack Leidecker, Sean D. Mack and William Clark explore balancing rapid innovation with cybersecurity, discussing leadership's role in aligning goals and fostering collaboration between security and development teams.
Sean D. Mack explores integrating security into software delivery without sacrificing speed, examining evolving threat landscapes, fostering shared security ownership models, and adopting best practices for prioritizing security findings at scale.
Gabriela Ciocarlie, Patrick Dunphy, Michael Spaulding, Zefren Edior and Albert Rooyakkers explore supply chain defense priorities, digital twin applications and business continuity frameworks for supplier breach scenarios.
Michael Schwab outlines AI governance frameworks for government entities, covering data accountability, human-in-the-loop requirements and executive support for enterprise AI programs.
1 2 Next