Blog Lisa Haas

Rami Sass 1
Lisa Haas

Podcast Thumbnail What AppSec Teams Get Wrong 1000x650

Securing The Build. RSAC 2026: What AppSec Teams Get Wrong

AppSec misconceptions about AI security and the build-time choices that matter.

Read More
Podcast Thumbnail Why AI Changed the AppSec Threat Model 1000x650

Securing The Build. RSAC 2026: Why AI Changed the AppSec Threat Model

AI broke AppSec’s assumptions: non-determinism, agent overreach, black-box models.

Read More
Resource Center Webinar AI Under Attack 1000x650 1

AI Under Attack – Lessons from Real-World AI Security Incidents

Real AI security incidents and what they reveal about traditional security control gaps.

Read More
hype cycle ASPM overview blog post

ASPM and Modern Application Security

Gartner’s 2024 Hype Cycle for Application Security: ASPM moves from peak to trough.

Read More
gartner mq blog image

Magic Quadrant™ for Application Security Testing, 2023 Gartner® report

Mend.io is recognized as a Visionary in the 2023 Gartner Magic Quadrant for Application Security Testing. Learn about their approach.

Read More
Blog 1

Mend SCA Action within Amazon CodeCatalyst Brings Additional Application Security to Developers

Learn about Mend SCA integration within Amazon CodeCatalyst for enhanced application security. Simplifying AWS vulnerability detection.

Read More
Brand Announce navy 1920 1080 scaled 1

WhiteSource is Now Mend.io: You Code, We Cure

Mend, formerly WhiteSource, focuses on automating application security with a remediation-first approach for open source and custom code.

Read More
SAST blog hero

Mend SAST: The Next Generation of Application Security

Learn about our innovative approach to detecting and remediating custom code vulnerabilities for a more secure future.

Read More
bsd screen

Top 8 BSD License’s Questions Answered

Get answers to the top 8 BSD License questions in this blog. Learn about the terms, compatibility with GPL, copyleft status, and more.

Read More
cddl

Top 10 Common Development and Distribution License Questions Answered

Get answers to the top 10 Common Development and Distribution License questions. Learn about CDDL terms, compatibility, and more.

Read More
openssourcewin2

Top 10 Microsoft Public License (Ms-PL) Questions Answered

Discover the top 10 Microsoft Public License (Ms-PL) questions answered on this blog. Learn about terms, copyleft, compatibility, and more.

Read More
eclipse logo

Top 10 Eclipse Public License Questions Answered

Get all your questions about the Eclipse Public License answered. Learn about its terms, compatibility, and differences with other licenses.

Read More
Knight on rope balance2222

How to Balance Between Security and Agile Development the Right Way

What can be done to better balance between security and agile development? What steps can be taken to ensure agile development processes are done in a secure manner?

Read More
owasp a9 1

You Can’t Ignore Using Components With Known Vulnerabilities

Learn why using components with known vulnerabilities is a major issue in application security and how to address it with OWASP guidelines.

Read More
Heartbleed 3 years later

Back To Heartbleed. Three Years Later.

Explore the aftermath of Heartbleed, and the importance of managing open source components for security.

Read More

Top 9 GPL With The Classpath Exception Questions Answered

The top 9 questions about GNU GPL with the Classpath exception. Learn how to use GPL’ed license components without risking your IP.

Read More

Subscribe to our Newsletter

Join our subscriber list to get the latest news and updates

Thanks for signing up!