Sep 19, 2025/3 min read The next frontier in AppSec: Context-aware risk scoring Chai Bhat Sep 19, 2025 | 3 min read
Aug 12, 2025/5 min read What you need to know about the NIST Secure Software Development Framework Fred Bals Aug 12, 2025 | 5 min read
Jul 31, 2025/5 min read Faster, Smarter Vulnerability Alerts: AI in Black Duck Security Advisories Mike McGuire Jul 31, 2025 | 5 min read
Jul 24, 2025/4 min read Unlocking the full potential of application security: Key findings from the Black Duck customer value study Jason Schmitt Jul 24, 2025 | 4 min read
Jul 17, 2025/7 min read Navigating the EU Cyber Resilience Act Corey Hamilton, Fred Bals Jul 17, 2025 | 7 min read
Jul 06, 2025/2 min read Scaling application security across borders: Black Duck Polaris Platform empowers Saudi Arabian enterprises with in-region SaaS hosting Black Duck Editorial Staff Jul 06, 2025 | 2 min read
May 22, 2025/5 min read Q&A: What You Need to Know About Open Source Software Risk in 2025 Fred Bals May 22, 2025 | 5 min read
Mar 18, 2024/8 min read Six Python security best practices for developers Boris Cipot Mar 18, 2024 | 8 min read
Nov 14, 2023/4 min read Why cross-site scripting still matters Charlotte Freeman Nov 14, 2023 | 4 min read
Jun 25, 2023/1 min read Podcast: The current state of DevOps Black Duck Editorial Staff Jun 25, 2023 | 1 min read
Apr 25, 2023/3 min read We’re one step closer to knowing how to comply with EO 14028 Tim Mackey Apr 25, 2023 | 3 min read
Nov 08, 2022/11 min read JavaScript security best practices for securing your applications Black Duck Editorial Staff Nov 08, 2022 | 11 min read
Oct 11, 2022/5 min read Open source dependency best practices for developers Charlotte Freeman Oct 11, 2022 | 5 min read
Aug 23, 2022/7 min read API authentication and authorization best practices Charlotte Freeman Aug 23, 2022 | 7 min read
Jan 18, 2022/6 min read Five cryptography best practices for developers Charlotte Freeman Jan 18, 2022 | 6 min read
Nov 01, 2021/4 min read Top seven logging and monitoring best practices Ashutosh Rana Nov 01, 2021 | 4 min read
Oct 16, 2021/7 min read Top 10 Spring Security best practices for Java developers Black Duck Editorial Staff Oct 16, 2021 | 7 min read
May 06, 2021/8 min read Top 10 DevSecOps best practices for building secure software Sneha Kokil May 06, 2021 | 8 min read
Jan 26, 2021/7 min read Securing your code: GDPR best practices for application security Taylor Armerding Jan 26, 2021 | 7 min read
Jan 03, 2021/6 min read Don’t get overwhelmed with trivial defects. Manage them! Taylor Armerding Jan 03, 2021 | 6 min read
Dec 07, 2020/4 min read 6 Findings from DevSecOps Practices' Survey Fred Bals Dec 07, 2020 | 4 min read
Sep 17, 2020/5 min read MITRE releases 2020 CWE Top 25 most dangerous software weaknesses Taylor Armerding Sep 17, 2020 | 5 min read
Jun 28, 2020/4 min read Are you following the top 10 software security best practices? Black Duck Editorial Staff Jun 28, 2020 | 4 min read
May 13, 2020/3 min read Critical gap in developer security training puts applications at risk Black Duck Editorial Staff May 13, 2020 | 3 min read
May 05, 2020/4 min read 3 ways to boost your security with role-based security compliance training Black Duck Editorial Staff May 05, 2020 | 4 min read
Feb 03, 2020/4 min read Mobile security app-titude best practices for secure app design and data privacy Black Duck Editorial Staff Feb 03, 2020 | 4 min read
Jan 06, 2020/7 min read The journey to better medical device security: Still slow, still bumpy Taylor Armerding Jan 06, 2020 | 7 min read
Oct 09, 2019/8 min read Best practices for secure application development Taylor Armerding Oct 09, 2019 | 8 min read
Nov 29, 2017/4 min read Navigating responsible vulnerability disclosure best practices Black Duck Editorial Staff Nov 29, 2017 | 4 min read
Mar 21, 2017/3 min read Vulnerability management and triage in 3 steps Black Duck Editorial Staff Mar 21, 2017 | 3 min read
Nov 28, 2016/3 min read Here are the top 10 best practices for securing Android apps Black Duck Editorial Staff Nov 28, 2016 | 3 min read
Jun 13, 2016/5 min read How to mitigate the Java deserialization vulnerability in JBoss application servers Black Duck Editorial Staff Jun 13, 2016 | 5 min read
May 17, 2016/4 min read 10 ways to infuse security into your software development life cycle Kris Balarama May 17, 2016 | 4 min read
May 14, 2016/5 min read Best practices for free and open source software vulnerability management Black Duck Editorial Staff May 14, 2016 | 5 min read
Mar 15, 2016/3 min read How to do static analysis testing in 6 easy steps Black Duck Editorial Staff Mar 15, 2016 | 3 min read
Jan 18, 2016/4 min read Pen testing best practices to take the pain out of penetration testing Black Duck Editorial Staff Jan 18, 2016 | 4 min read
Oct 22, 2015/5 min read Software security myth #3: Penetration testing solves everything Black Duck Editorial Staff Oct 22, 2015 | 5 min read