Guides
Protect AI models, data, and systems
Test for behavioral risks in conversational AI
Mitigating risks and future trends
AppSec types, tools, and best practices
Automating dependency updates
Manage open source code
Keep source code safe
Improve transparency, security, and compliance
Pre-production scanning and runtime protection
Secure containerized applications
What Is Application Security? Types, Tools and Best Practices
Explore our application security complete guide and find key trends, testing methods, best practices, and tools to safeguard your software.
ASPM and Modern Application Security
Gartner's 2024 Hype Cycle for Application Security: ASPM moves from peak to trough.
Dude, Where’s My Documentation?
When the zero day hits the fan, can you find the information you need?
Bigger Data, Bigger Problems: Three Major Challenges in Big Data Security
Discover the challenges of big data security: data sources, infrastructure, and technology issues, and how to keep your big data secure.
NVD Update: Help Has Arrived
There's hope yet for the world's most beleaguered vulnerability database.
NVD Update: More Problems, More Letters, Some Questions Answered
We're not saying the NVD is dead but it's not looking good.
Quick Guide to the OWASP OSS Risk Top 10
Learn about the top 10 risks of open source software, beyond just CVEs. From known vulnerabilities to unapproved changes.
What Makes Containers Vulnerable?
Learn about the vulnerabilities that containers bring to your applications and how to address them to keep attackers at bay.
NVDβs Backlog Triggers Public Response from Cybersec Leaders
The National Vulnerability Database's backlog triggers a public response from cybersecurity leaders. Concerns raised, open letter to Congress
Container Security: Creating an Effective Security Program with Reachability Analysis
Learn how to create an effective container security program with reachability analysis to protect your applications from vulnerabilities.
Breaking: What is Going on with the NVD? Does it Affect Me?
Learn about the current issues with the National Vulnerability Database, how it affects vulnerability reporting, and how Mend SCA can help.
What is the difference between an SCA scan and a container scan?
Learn about the difference between SCA scans and container scans, why scanning containers for vulnerabilities is important.
How is a Container Scan Done?
Learn the importance of scanning container images for vulnerabilities to keep your containerized environments safe.
Secrets Management vs Secrets Detection: Hereβs What You Need to Know
Learn about the importance of secrets management vs secrets detection in application security. Protect your sensitive data.
CVSS 4.0 is Here: How to Make the Most of It
Learn about the latest version of CVSS 4.0. Understand the new metrics and how to use them in your org's vulnerability remediation strategy.
Quality vs. Quantity: How to Get the Most Out of SAST
Learn how to make the most out of Static Application Security Testing (SAST) without overwhelming developers.