Taylor Armerding·Jan 14, 2025Get to know the BSIMM — a crowd-sourced guidebook for your journey to better software securityIf you want to build better, more secure software, and you should, BSIMM is the report you should read and the club you should join.
Taylor Armerding·Jan 7, 2025Cybersecurity experts join the 2025 guessing gameA range of cybersecurity experts weigh in on what is the best and worst we can expect in the coming year.
Taylor Armerding·Dec 16, 2024Control systems exposure puts critical infrastructure at riskIndustrial control systems run most of the nation’s critical infrastructure. Too many of them are vulnerable to hackers.
Taylor Armerding·Dec 9, 2024Both good and bad guys showing that LLMs aren’t ready for prime timeLarge language models—the brains behind artificial intelligence—keep getting better, but still need lots of improvement,
Taylor Armerding·Dec 2, 2024These software packages contain “presents” you don’t want to openMalicious hackers, instead of waiting for software developers to make mistakes, are trying to trick them into downloading mistakes.
Taylor Armerding·Nov 25, 2024Are there too many “top software vulnerabilities” lists? Or are they the wrong lists?Are there too many lists of top software vulnerabilities? Maybe. Or maybe the lists should be about how to build more secure code.
Taylor Armerding·Nov 12, 2024Report: Building trust into software takes a team of testsA new report documents the benefits of multiple software security testing tools
Taylor Armerding·Nov 4, 2024Will AI be good for democracy? That depends on the humans in chargeArtificial intelligence is invading every element of our lives, including our system of government. That will likely be both good and bad.
Taylor Armerding·Oct 28, 2024Zero-day software defects are leading to many very bad daysZero-day software vulnerabilities are among the most dangerous, because there is no patch for them. And they are increasing.
Taylor Armerding·Oct 21, 2024Researcher finds government cybersecurity is still porousDespite catastrophic breaches of government, cybersecurity hasn’t improved as much as it could, or should