Application security posture management company Apiiro today has released two open-source tools to help organizations defend against malicious code in their applications. The action comes on the heels of Apiiro’s security research that shows thousands of malicious code instances in repositories and packages. According to the company, its focus in the research was deep code analysis and analyzing malicious samples for patterns to find ways to defend against malicious code. “Malicious code is one of the most accessible and easy-to-execute attack vectors,” the company wrote in a blog about the research. “The security of dependency managers and source code hosting platforms is still evolving, with large gaps in areas like human-to-digital identity verification, source and release validation, and more. Major security gaps also exist in build systems, artifact managers, and pipeline tools.” Malicious code is introduced via anti-patterns, the research found, and obfuscated code is a key a...
This website is about programming knowledge. You can call this blog best programming master.