logo

The state of AppSec: Are we getting ahead of attackers — or falling behind?

ID: cd5b5f8d-b37d-5c60-b36d-543b096c5e08

STIX ID: report--cd5b5f8d-b37d-5c60-b36d-543b096c5e08

Feed Name: ReversingLabs Blog

Date Published: 2024-05-28

Date Updated: 2026-04-29

Author: [email protected] (John P. Mello Jr.)

...
...

Industry experts reflect on the state of AppSec, noting progress in adopting safer languages (Rust, Go), improved container security practices, and broader 'shift-left' supply chain controls (e.g., signed commits, dependency scanning), while emphasizing persistent challenges such as legacy C/C++ codebases, tooling fragmentation, transitive dependency risk, and implementation gaps. They advocate investing in people, avoiding developer blame, pursuing transparency over liability, and modernizing tooling and budgets to meet the scale and complexity of software supply chain threats.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.