1. https://appdevelopermagazine.com/devops
  2. https://appdevelopermagazine.com/devsecops-will-go-mainstream-this-year/
1/26/2021 11:21:28 AM
DevSecOps will go mainstream this year
Predictions 2021,DevSecOps,Shadow Code
/DevSecOps-goes-mainstream-App-Developer-Magazine_c55y8daa.jpg
App Developer Magazine

DevOps

DevSecOps will go mainstream this year


Tuesday, January 26, 2021

Richard Harris Richard Harris

Ido Safruti, CTO and co-founder of app security leader PerimeterX predicts that DevSecOps will go mainstream this year and there will be an increase in shadow code, typosquatting, and other malicious attacks.

Cybercriminals love Shadow Code exploits because hacking a commonly used library or service can place the malicious code on hundreds or thousands of websites. For example, the widely used jQuery JavaScript library has been breached multiple times, leading to digital skimming attacks broadly across the e-commerce sector. Adding jQuery to an application without appropriate security review to ascertain whether there was an outstanding vulnerability on that version of the library is a classic Shadow Code failing. Typosquatting is another favorite broad use case where hackers create malicious third-party scripts with names very similar to legitimate services for payments or chatbots, to name two examples, to trick developers into adding this code, or to reduce suspicion when this code sends stolen data to these domains. The malicious scripts then execute hard-to-detect skimming attacks against application users, often evading detection for months.

The definition of DevSecOps

Acourding do SumoLogic, DevSecOps is the philosophy of integrating security practices within the DevOps process. DevSecOps involves creating a ‘Security as Code’ culture with ongoing, flexible collaboration between release engineers and security teams. The DevSecOps movement, like DevOps itself, is focused on creating new solutions for complex software development processes within an agile framework.

DevSecOps is a natural and necessary response to the bottleneck effect of older security models on the modern continuous delivery pipeline. The goal is to bridge traditional gaps between IT and security while ensuring fast, safe delivery of code. Silo thinking is replaced by increased communication and shared responsibility of security tasks during all phases of the delivery process.

DevSecOps will go mainstream this year

With a growing percentage of code running on client-side applications coming from third-party JavaScript libraries or services, we see an increase in “Shadow Code.” When looking at front end JavaScript code, Shadow Code is code that is introduced into an application without a formal approval process or security validation. Shadow Code often takes the form of third-party vendors or open-source libraries delivering specific functionalities into an application. Shadow Code can also include first-party code introduced by a rogue or compromised developer, or unauthorized code injected into the application through a vulnerability or security breach. Because it was not appropriately reviewed or might have been compromised or modified since code review (which is commonly the case with 3rd party vendors), Shadow Code may harbor malicious client-side code that alters application behavior to illegally gather and exfiltrate PII from websites. The malicious code may escape further scrutiny since it executes on the client-side.

Who is Ido Safruti

Ido Safruti, CTO and co-founder of app security leader PerimeterX. Ido co-founded PerimeterX and as CTO is responsible for stewarding the company’s technology vision and leading the R&D team. Before PerimeterX, he was Senior Director of Product Management at Akamai focused on web performance and scalability. Ido joined Akamai through the acquisition of Cotendo, where he was VP for product strategy. Prior to Cotendo, he headed a cybersecurity branch of the Israeli intelligence services. He holds a master’s degree in computer science from Tel Aviv University and a degree in physics and mathematics from the Hebrew University.

DevSecOps will go mainstream this year







Subscribe to App Developer Magazine

Become a subscriber of App Developer Magazine for just $5.99 a month and take advantage of all these perks.

MEMBERS GET ACCESS TO

  • - Exclusive content from leaders in the industry
  • - Q&A articles from industry leaders
  • - Tips and tricks from the most successful developers weekly
  • - Monthly issues, including all 90+ back-issues since 2012
  • - Event discounts and early-bird signups
  • - Gain insight from top achievers in the app store
  • - Learn what tools to use, what SDK's to use, and more

    Subscribe here



Stay Updated

Sign up for our newsletter for the headlines delivered to you

SuccessFull SignUp

Featured Stories


FTC AI accuracy policy puts chatbot trust under review
FTC AI accuracy policy puts chatbot trust under review Tuesday, July 21, 2026




Human-Made Video Ads Outperform AI-Generated Creativity
Human-Made Video Ads Outperform AI-Generated Creativity Monday, July 20, 2026


SpaceX accelerates AI push with new hires
SpaceX accelerates AI push with new hires Monday, July 20, 2026


NearLens: Smart Glasses Privacy Taken Seriously
NearLens: Smart Glasses Privacy Taken Seriously Wednesday, July 15, 2026


Agentic Commerce Grows Cequence Unveils AI-Era Bot Defense
Agentic Commerce Grows Cequence Unveils AI-Era Bot Defense Wednesday, July 15, 2026


Nearly all developers use AI but few secure the code it generates
Nearly all developers use AI but few secure the code it generates Monday, July 13, 2026


Enviromates new browser launches
Enviromates new browser launches Monday, July 6, 2026


AI Executive Order aims to balance security and innovation
AI Executive Order aims to balance security and innovation Monday, June 29, 2026


Top manufacturing trends for 2026
Top manufacturing trends for 2026 Tuesday, June 23, 2026


API scoring tool shows if your API is ready for AI
API scoring tool shows if your API is ready for AI Monday, June 22, 2026


Get More App News