What Is SAST β Static Application Security Testing
Learn about Static Application Security Testing (SAST).
AI Governance in AppSec: The More Things Change, The More They Stay the Same
Learn how AppSec teams can extend existing security and compliance practices seamlessly to AI.
2025 OWASP Top 10 for LLM Applications: A Quick Guide
An overview of the top vulnerabilities affecting large language model (LLM) applications.
AI Powered Remediation: Mend SAST Performs +46% Better Than Competitors
See how Mend SAST's AI powered automated remediation eliminates vulnerabilities with speed & accuracy.
CVSS 3.1 vs CVSS 4.0: A Look at the Data
CVSS base scores are up in the latest version of the scoring system. What does that mean for AppSec practitioners?
Mend.io β Backstage Integration: Bringing Security Insights Where You Need Them
Backstage offers wide views and controls across the development process and with the Mend.io plugin, deep insights into application risks overall or by project.
What is the KEV Catalog?
A quick guide to the Known Exploited Vulnerabilities (KEV) catalog.
What Is Application Security? Types, Tools and Best Practices
Explore our application security complete guide and find key trends, testing methods, best practices, and tools to safeguard your software.
A Guide to Open Source Software
Explore how to use open source software to innovate while minimizing risk.
Dependency Management: Protecting Your Code
Learn how to protect your applicationβs code with dependency management.
Dependency Management vs Dependency Updates: What’s the Difference?
Keeping dependencies up to date is a big part of dependency management, but it's not everything. Learn more about the differences between the two.
Hallucinated Packages, Malicious AI Models, and Insecure AI-Generated Code
Worried about attackers using AI models to write malicious code? Here are three other ways AI model use can lead to attacks.
Quick Guide to Popular AI Licenses
Not all "open" AI licenses are truly open source. Learn more about the most popular licenses on Hugging Face.
Threat Hunting 101: Five Common Threats to Look For
Learn more about supply chain threats and where to find them.
Responsible AI Licenses (RAIL): Hereβs What You Need to Know
Learn about this family of licenses that seek to limit harmful use of AI models.
NVD Update: More Problems, More Letters, Some Questions Answered
We're not saying the NVD is dead but it's not looking good.
Join our subscriber list to get the latest news and updates
Thanks for signing up!Β