Latest news

Fuzz-o-Matic provides users actual, repeatable test cases for software bugs that cause product crashes and security breaches. Codenomicon's security testing platform finds previously-unknown vulnerabilities before hackers do, without false positives or false alarms.
For users who already tested software with Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), vulnerability scanning, or hybrid analysis, Fuzz-o-Matic is the next progression in testing to find the bugs the other testing solutions missed. For users who have not tested software at all yet, but the user's code is executable, Fuzz-o-Matic provides users longer lead-times to remedy bugs before software release.
According to Ira Winkler, security expert and Codenomicon's Chief Security Strategist, "It is irresponsible to seriously consider investing in or acquiring a software product without testing for software reliability and security. While people think of software fuzzing as a security measure, fuzzing is really testing for all types of software bugs, of which security vulnerabilities are just one type of bug."
Fuzzing is perhaps the most effective measure of identifying any software reliability issues. To that end, investors and M&A professionals need to ensure they use a reliable fuzzing tool that is proven, robust and versatile. Only a testing-as-a-service platform with this level of support can produce repeatable and robust results that can produce a reasonable level of diligence, beyond the straight financials," he added.
Fuzz-o-Matic is a convenient and cost-effective approach to application fuzzing for those who do not have in-house security testers or have a limited budget for penetration testing. Application fuzzing uses unexpected inputs to stress-test software far beyond normal operating conditions.
Most software testing simulates normal operating conditions to determine if software does what it is designed to do. Black-hat hackers use application fuzzing to find exploitable security bugs in unused or rarely-used software functionality.
Microsoft Software Development Lifecycle (SDLC), Cisco SDLC, and Building Security in Maturity Model (BSIMM) recognize the key role of fuzzing in the creation of secure and rugged software. Fuzz-o-Matic uses a range of fuzzers to provide the most comprehensive cloud-based stress-testing and vulnerability detection platform on the Market today.


Spotlight

Review: Logging and Log Management
Posted on 22 May 2013. | Every security practitioner should be aware of the overwhelming advantages of logging and perusing logs for discovering system intrusions. But logging and log management comes with its own set of difficulties.

Experts highlight top data breach vulnerabilities
Posted on 22 May 2013. | Hidden vulnerabilities lie in everyday activities that can expose personal information and lead to data breach, including buying gas with a credit card or wearing a pacemaker.

A closer look at Mega cloud storage
Posted on 21 May 2013. | Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.

Cyber espionage campaign uses professionally-made malware
Posted on 20 May 2013. | A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.




