Home / Companies / Snyk / Blog / January 2020

January 2020 Summaries

7 posts from Snyk

Filter
Month: Year:
Post Summaries Back to Blog
Snyk has closed $150 million in funding to accelerate its vision of bringing a new approach to application security, enabling businesses to continuously build security into their application development process and culture. A recent study with Puppet found that 37% of companies are still not implementing security testing in Continuous Integration (CI). The company's founder and president, Guy Podjarny, believes that scaling security needs to happen through DevSecOps and dev-first security. Snyk has also released new features, including improved Linux vulnerability severity definitions and a new CLI tool feature that allows users to scan their entire directory and test all manifest files. Additionally, the company is partnering with various organizations for events such as conferences and meetups, where its team will be present to discuss security topics and showcase its products.
Jan 31, 2020 455 words in the original blog post.
There is a significant tension between security teams, operations or IT, and core R&D engineering within organizations when traditional security activities are siloed. However, integrating security practices throughout the Software Development Life Cycle (SDLC) can elevate the overall confidence level of security practices for the entire organization. Threat modeling, which connects business stakeholders and focuses on answering fundamental questions, creates a collaborative environment and open discussion between Dev, Sec, and Ops parties. Despite being at the highest level of security integration, 29% of organizations still experience friction when collaborating between security teams and delivery teams. However, this is less common than among medium-level security integration organizations. Organizations with strong security integration can prioritize security issues over feature delivery and address them faster, viewing security as a shared responsibility across the organization.
Jan 28, 2020 635 words in the original blog post.
While DevOps adoption is increasing, there are still significant challenges in implementing effective DevSecOps practices. The study highlights that 79% of respondents use security code reviews despite employing automated security tooling, indicating a need for better integration and feedback loops for developers. Additionally, many teams struggle to test for known vulnerabilities in their open source dependencies and container images, highlighting the importance of leveraging security tooling like Snyk Container to mitigate this gap. The study also reveals that 86% of security and tech roles agree that security is a shared responsibility, suggesting that all parties involved in a DevSecOps environment should be accountable for infrastructure security. Furthermore, the results show that friction between teams with high security integration orgs can occur when collaborating, emphasizing the need for effective communication and collaboration to achieve successful DevSecOps adoption.
Jan 28, 2020 653 words in the original blog post.
The article highlights the challenges organizations face in delivering software quickly while ensuring security. 48% of respondents see security as a major constraint on software delivery speed, indicating that traditional security practices often take place late in the SDLC and can hinder fast development iterations. The study emphasizes the importance of DevSecOps, which requires automation and empowerment of developers to address security concerns proactively. Integrated tooling is key to aligning with the agility demanded in a DevOps world, enabling engineers to assess and prioritize risk, and shortening the time window of exposed vulnerabilities. 79% of organizations are midway in their DevOps journey, facing challenges such as scaling tooling and culture to effectively meet the promises of DevOps. The article concludes that security is a shared responsibility and that developers should own security, but often lack the necessary skills and tools to do so effectively.
Jan 28, 2020 975 words in the original blog post.
Snyk has closed $150 million in funding to accelerate its developer-first security approach, partnering with top investors like Stripes and Coatue to expand product innovation, EMEA and APJ markets, and support the DevSecOps community. The company aims to bring a new approach to application security by enabling businesses to continuously build security into their development process and culture. With this investment, Snyk will focus on offering a developer-first approach to security that supports shared ownership between security, ops, and development teams, prioritizing the developer experience and business efficiency. The funding milestone marks an exciting step in Snyk's journey to support modern application security teams as they adjust their approach to cybersecurity.
Jan 21, 2020 405 words in the original blog post.
The npm package manager client is vulnerable to a security vulnerability that allows arbitrary file overwrites, which can be exploited by malicious actors to overwrite files in the user's filesystem or project directory. This vulnerability affects packages installed globally and transitive dependencies, and can lead to inject malware, alter lockfiles, or poison the filesystem. The vulnerability is severe because it can occur even when using the `ignore-scripts` flag, and has triggered Node.js security releases. Users are advised to upgrade to fixed versions of npm, yarn, and pnpm, and practice secure developer practices to mitigate this risk.
Jan 07, 2020 1,366 words in the original blog post.
Navigating your own career growth in a hyper-growth startup is chaotic yet rich with opportunity. The rapid pace of change can create ambiguity and uncertainty, but also opens up numerous opportunities for employees. To position themselves for accelerated career growth, individuals must be proactive and take ownership of their development. This involves scheduling regular check-ins with their manager, seeking to understand what "good" looks like in terms of success and goals, recognizing that career growth comes in different shapes and sizes, raising their hand for projects even if they may not be the most appealing ones, and laying the groundwork to tilt the odds in their favor through a combination of their own performance, network, and luck. By taking these steps, individuals can navigate the complex landscape of hyper-growth startups and increase their chances of career advancement.
Jan 07, 2020 849 words in the original blog post.