InfoQ Homepage Security Content on InfoQ
-
Are We Ready for the Next Cyber Security Crisis Like Log4shell?
Soroosh Khodami shares a "horror story" on supply chain attacks. He explains how one Maven or npm command can gift hackers a reverse shell and shares critical strategies like SBOMs to defend teams.
-
Security and Architecture: to Betray One is to Destroy Both
Shana Dacres-Lawrence discusses the "betrayals" between security and architecture. She explains how delivery pressure and assumed trust lead to failures and shares five strategies for a lasting union.
-
Panel: Security against Modern Threats
The panelists discuss the challenges in securing the software supply chain against modern threats.
-
Busting AI Myths and Embracing Realities in Privacy & Security
Katharine Jarmul keynotes on common myths around privacy and security in AI and explores what the realities are, covering design patterns that help build more secure, more private AI systems.
-
Platforms for Secure API Connectivity with Architecture as Code
Jim Gough explains how "Architecture as Code" and the CALM model bridge the gap between developers and infrastructure, sharing patterns to automate security reviews and accelerate API deployment.
-
Securing AI Assistants: Strategies and Practices for Protecting Data
Andra Lezza reviews the OWASP Top 10 for LLMs and contrasts security controls for independent vs. integrated copilot architectures.
-
Trust No One: Securing the Modern Software Supply Chain with Zero Trust
Emma Yuan Fang discusses how to apply Zero Trust principles to secure the software supply chain and CI/CD pipeline, detailing mitigation for major attacks like SolarWinds and dependency confusion.
-
The Way We Manage Compliance is Wrong… and is Changing! Bringing DevOps Principles to Controls and Audit
Ian Miell shares the open-source Continuous Compliance Framework, discussing how to revolutionize audits. He explains shifting from periodic checks to continuous monitoring with DevOps and OSCAL.
-
Secure by Design: Building Security into Engineering Workflows and Teams
Stefania Chaplin discusses how to build security into engineering workflows and teams. She shares how to achieve a security-first culture by focusing on people, processes, and technology.
-
Designing for Defense: Architecting APIs with Zero Trust Principles
Renato Losio and security experts discuss designing for defense and architecting APIs with Zero Trust principles, covering challenges, common vulnerabilities, and practical advice for developers.
-
One Network: Cloud-Agnostic Service and Policy-Oriented Network Architecture
Anna Berenberg reveals Google's shift to One Network, streamlining diverse infrastructures to enhance developer velocity and policy management.
-
Security or Convenience - Why Not Both?
Dorota Parad discusses the BLISS framework for security, showing senior developers and leaders how to enhance security while boosting engineering productivity and minimizing operational friction.