Mend.io Application Security

Quick Guide to the OWASP OSS Risk Top 10 - owasp oss risk top ten blog

Quick Guide to the OWASP OSS Risk Top 10

Learn about the top 10 risks of open source software, beyond just CVEs. From known vulnerabilities to unapproved changes.

Read More
Quick Guide to the OWASP OSS Risk Top 10 - large Blog

Why an SBOM Audit is Vital to Application Security and Compliance

Learn the importance of an SBOM for enhancing application security and compliance. Explore best practices for creating and auditing SBOMs effectively.

Read More
Quick Guide to the OWASP OSS Risk Top 10 - what makes containers vulnerable

What Makes Containers Vulnerable?

Learn about the vulnerabilities that containers bring to your applications and how to address them to keep attackers at bay.

Read More
Quick Guide to the OWASP OSS Risk Top 10 - nvd backlog triggers public response from cybersec leaders

NVD’s Backlog Triggers Public Response from Cybersec Leaders

The National Vulnerability Database's backlog triggers a public response from cybersecurity leaders. Concerns raised, open letter to Congress

Read More
Quick Guide to the OWASP OSS Risk Top 10 - owasp top 10 llm application vulnerabilities

OWASP Top 10 for LLM Applications: A Quick Guide

Discover the OWASP Top 10 for LLM Applications in this comprehensive guide. Learn about vulnerabilities, & prevention techniques.

Read More
Quick Guide to the OWASP OSS Risk Top 10 - hugging face blog

What You Need to Know About Hugging Face

Stay informed about the risks and challenges of AI models with Hugging Face. Learn how to identify and secure AI-generated code.

Read More
Quick Guide to the OWASP OSS Risk Top 10 - shrinking security debt with dependency management white paper

Critical Backdoor Found in XZ Utils (CVE-2024-3094) Enables SSH Compromise 1

Discover how CVE-2024-3094 affects XZ Utils and enables SSH compromise. Get insights on detection, mitigation, and system security.

Read More
Quick Guide to the OWASP OSS Risk Top 10 - learning from history gender bias in ai

Learning From History: AI Gender Bias

Learn about AI gender bias in large language models, how historical data impacts AI, & implications for women in health & car safety fields.

Read More
Quick Guide to the OWASP OSS Risk Top 10 - Container Security post

Container Security: Creating an Effective Security Program with Reachability Analysis

Learn how to create an effective container security program with reachability analysis to protect your applications from vulnerabilities.

Read More
Quick Guide to the OWASP OSS Risk Top 10 - container blog

Mend.io Launches Mend Container

Mend.io launches Mend Container to address security in cloud-native development, offering reachability analysis and secrets detection.

Read More
Quick Guide to the OWASP OSS Risk Top 10 - broken nvd

Breaking: What is Going on with the NVD? Does it Affect Me?

Learn about the current issues with the National Vulnerability Database, how it affects vulnerability reporting, and how Mend SCA can help.

Read More
Quick Guide to the OWASP OSS Risk Top 10 - what is the difference between an sca scan and a container scan

What is the difference between an SCA scan and a container scan?

Learn about the difference between SCA scans and container scans, why scanning containers for vulnerabilities is important.

Read More
Quick Guide to the OWASP OSS Risk Top 10 - how is a container scan done

How is a Container Scan Done?

Learn the importance of scanning container images for vulnerabilities to keep your containerized environments safe.

Read More
Quick Guide to the OWASP OSS Risk Top 10 - secrets management vs secrets detection what you need to know

Secrets Management vs Secrets Detection: Here’s What You Need to Know

Learn about the importance of secrets management vs secrets detection in application security. Protect your sensitive data.

Read More
Quick Guide to the OWASP OSS Risk Top 10 - cvss4 is here how to make the most of it

CVSS 4.0 is Here: How to Make the Most of It

Learn about the latest version of CVSS 4.0. Understand the new metrics and how to use them in your org's vulnerability remediation strategy.

Read More
Quick Guide to the OWASP OSS Risk Top 10 - how to get the most out of sast blog post

Quality vs. Quantity: How to Get the Most Out of SAST

Learn how to make the most out of Static Application Security Testing (SAST) without overwhelming developers.

Read More