Latest news
It helps teams ease compliance to internal security policies, allowing for the creation and customization of security best practices and standards - and it reduces overall application risk.

TeamMentor v3.2 is also a Visual Studio 2010 plugin that integrates static analysis results with TeamMentor’s prescriptive security guidance – providing comprehensive remediation capabilities for Security and Development teams looking to expand the value and impact of static analysis solutions and fix code vulnerabilities, based on specific coding problems and patterns to permanently eliminate those problems in your code moving forward.
The tool also features content updates including new mobile application security libraries for both iOS and Android – the first comprehensive guidance set for implementing application security controls for both platforms.
In addition to the newly added CWE/SANS Top 25 most common code vulnerabilities, TeamMentor now features added functionality so that teams can hyper-link filtered results to quickly send and consume the guidance content.
“For organizations using static analysis tools, the results can often be overwhelming in terms of prioritization and remediation,” said Wendy Nather, Research Director, 451 Group. “As Security and Development teams progress in collaborating to ensure that software is delivered securely, they’ve needed a just-in-time 'pull' model, where people can look up the information they need right when they need it. In turn it becomes more effective to run results against prescriptive guidance in a central location so you can start to reduce software vulnerabilities.”
“We are excited to deliver the latest build of TeamMentor because it satisfies the vision we have of enabling organizations to leverage existing tools to solve the persistent problem of fixing vulnerabilities as opposed to just knowing they exist,” said Jason Taylor, Chief Technology Officer, Security Innovation. “Now, developers can stay within their environment while scanning software code and remediate what they find in one step. TeamMentor offers a comprehensive solution that helps build security into software without inhibiting revenue-generating projects.”
TeamMentor’s out-of-the-box guidance assets are experience-based, leveraging the company’s decade of security analysis and research. The content is developed by Security Innovation’s foremost security experts and is peer-reviewed. Updates are delivered quarterly so development and security teams have the most recent and relevant information on known and new software vulnerabilities.


Spotlight

The security of WordPress plugins
Posted on 18 June 2013. | Checkmarx’s research lab identified that more than 20% of the 50 most popular WordPress plugins are vulnerable to common Web attacks, such as SQL Injection.

Information security executives need to be strategic thinkers
Posted on 17 June 2013. | George Baker, the Director of Information Security at Exostar, talks about the challenges in working in a dynamic threat landscape, offers tips for aspiring infosec leaders, and more.

Large orgs in denial about own security breaches?
Posted on 14 June 2013. | Over two thirds (66%) of large organizations said they either had not experienced a security incident in the last 12-18 months or were unsure if they had.

Vulnerability scanning with PureCloud
Posted on 12 June 2013. | nCircle PureCloud is a cloud-based network security scanning product built upon the companies' vulnerability and risk management system IP360.

Reactions from the security community to the NSA spying scandal
Posted on 11 June 2013. | Read on for comments on this scandal that Help Net Security received from a variety of security professionals and analysts.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.







