February 2026 delivered two milestones that signal a real shift in application security: Anthropic shipped Claude Code Security after finding 500+ zero-day vulnerabilities in production open-source …
READ MORE Read More »
Most companies misunderstand penetration testing types. Learn the real difference between black box, white box, and grey box pentests—it’s about knowledge, not access.
READ MORE Read More »
Complete guide to API security testing and appsec testing in 2026. Learn REST/GraphQL testing, OWASP Top 10, tools, and when to get professional help.
READ MORE Read More »
The OWASP Top 10 2025 brings significant changes to web application security priorities. Two new categories, major ranking shifts, and 589 CWEs analysed—here’s what security teams need to know.
READ MORE Read More »
MITRE’s CVE contract expired on April 16, putting global vulnerability tracking at risk. Learn what’s happening and how the security community is responding.
READ MORE Read More »
Some software vulnerabilities are unforgivable—easy to find, easy to fix, and never should’ve existed. Here’s how to spot and prevent them.
READ MORE Read More »
Assess and improve your software security maturity with SAMMY. Free OWASP SAMM implementation tool for DevSecOps teams. Start your assessment now.
READ MORE Read More »
Software supply chain security is in the news again, along with the Trojan Source attack on modern software compilers. Why is it so important?
READ MORE Read More »
BSG has conducted an application pentest for the Ukrainian Bone Marrow Donors Registry. Why it matters and how it relates to you?
READ MORE Read More »
Where in the software product lifecycle does security come into play? What are best practices and common pitfalls? In this post, read about that and more.
READ MORE Read More »