Legit Security Blog

Best Practices

The Top 8 Cloud Application Threats in 2023

In this blog post, we'll discuss 8 of the top threats targeting cloud applications in 2023. Taking steps to protect your cloud applications against...

Read More

Top Open Source Software Supply Chain Security Tips

As more organizations and applications rely on open-source software, it is crucial to ensure that the software is secure and free from...

Read More

What is a Secure SDLC?

SDLC (Software Development Life Cycle) is a breakdown of all the stages involved in software creation. There are distinct SDLC stages and many...

Read More

What are the Five Elements of the NIST Cybersecurity Framework?

A cybersecurity framework is a group of documents outlining guidelines, security-related standards, and best practices to help organizations manage...

Read More

2023 Predictions for Modern Application Security

Software dominates the world and remains abig and accessible attack surface.In 2022, an estimated $6Bwas invested in Application Security, with that...

Read More

How to Continuously Detect Vulnerable Jenkins Plugins to Avoid a Software Supply Chain Attack

Jenkins is an open-source automation and build platform that allows for automated tests, integrations, builds, and much more. However, Jenkins also...

Read More

Modern AppSec Requires Extending Beyond SCA and SAST

Once upon a time in Application Security, times were simpler. Not long ago security and development teams could simply scan their code for...

Read More

Integrating Security into DevOps: A Step-By-Step Guide

If you haven’t already been integrating security into DevOps, we've provided this 4-step guide to help smooth the transition as well as describe the...

Read More

GitHub Codespaces Security Best Practices

When GitHub released Codespaces last year it was touted as their best release since GitHub Actions. If you’re using Codespaces or thinking about it,...

Read More

Software Supply Chain Risks: What Every CISO Needs to Know

Today most business leaders realize that no matter what industry they operate in, their organizations are truly technology companies that serve...

Read More

Why You Can Still Get Hacked Even After Signing Your Software Artifacts

Malicious actors are poisoning your artifacts in an attempt to infect your software supply chain so that you deploy those compromised (i.e.,...

Read More

8 Best Practices in Cyber Supply Chain Risk Management to Stay Safe

In this blog post, we'll discuss the four types of software supply chain threats businesses face. Use these 8 best practices in cyber supply chain...

Read More

10 Agile Software Development Security Concerns You Need to Know

Agile software development is a type of methodology that centers around the core principle of flexibility. Agile development methods recognize that a...

Read More

1 min read

LastPass Software Supply Chain Attack: What Happened and Tips to Protect Against Similar Attacks

LastPass, one of the world's largest password managers with 25 million users, disclosed that an unauthorized party had gained access to portions of...

Read More

5 Things You Need to Know About Application Security in DevOps

Application Security (AppSec) is the process of identifying, testing, and fixing security flaws in an application. Although it may be tempting to...

Read More

How to Secure Your Software Supply Chain in 10 Steps

A software supply chain is the list of components, libraries, and tools used to build a software application. Software vendors often create products...

Read More

A Complete Guide to the Secure Software Development Lifecycle (SDLC)

Development teams already work in a very methodical repeating process – the Software Development Lifecycle (SDLC) – and a huge opportunity exists to ...

Read More

Secure SDLC: The Best Advice for Securing Your Code and Application Data in 2022 and Beyond

The principles of data security are pretty simple, although organizations have a tendency to short cut them in their SDLCs. Data security is defined...

Read More

Securing GitHub: How to Keep Your Code and Pipelines Safe from Hackers

GitHub is one of the most widely used software development platforms. You’d be hard-pressed to find a developer or a business that has never used or...

Read More

A 10-Step Application Security Risk Assessment Checklist

What is an Application Security Risk Assessment?

An application security risk assessment is a process of identifying, assessing, and managing the...

Read More

GitHub Security Best Practices Your Team Should Be Following

Configuring security in GitHub correctly can offer strong protection against breaches related to application vulnerabilities. The platform comes with...

Read More

How to Use DevOps Security Tools to Protect Your Business

DevOps is a practice used to deliver software and services faster. As more businesses adopt DevOps, they are also adopting DevOps security tools to...

Read More

Forget Everything You Thought You Knew About DevOps and Security

DevOps isn’t a new concept. The term was first coined around 2009 by Patrick Debois as a way to describe not only technology and standards, but also...

Read More

What Are Immutable Tags And Can They Protect You From Supply Chain Attacks?

Artifacts, such as container images, are referenced during the development lifecycle using tags – a readable short name (usually a version like...

Read More

Vulnerable GitHub Actions Workflows Part 2: Actions That Open the Door to CI/CD Pipeline Attacks

In this blog post, we’ll explore a bug we’ve found in a popular third-party action and how in some cases it could lead to your SDLC pipeline being...

Read More

Vulnerable GitHub Actions Workflows Part 1: Privilege Escalation Inside Your CI/CD Pipeline

At Legit Security, we’re focused on preventing software supply chain attacks and securing the SDLC for our customers and the broader cybersecurity...

Read More

Software Supply Chain Security: How To Get Started?

In response to a rapid increase in software supply chain attacks, Security Professionals and Software Development Leaders are increasingly motivated...

Read More

Stay Connected

 Please join our mailing list for future updates and announcements.