1. https://appdevelopermagazine.com/devops
  2. https://appdevelopermagazine.com/devsecops-will-go-mainstream-this-year/
1/26/2021 11:21:28 AM
DevSecOps will go mainstream this year
Predictions 2021,DevSecOps,Shadow Code
/DevSecOps-goes-mainstream-App-Developer-Magazine_c55y8daa.jpg
App Developer Magazine
DevSecOps will go mainstream this year

DevOps

DevSecOps will go mainstream this year


Tuesday, January 26, 2021

Richard Harris Richard Harris

Ido Safruti, CTO and co-founder of app security leader PerimeterX predicts that DevSecOps will go mainstream this year and there will be an increase in shadow code, typosquatting, and other malicious attacks.

Cybercriminals love Shadow Code exploits because hacking a commonly used library or service can place the malicious code on hundreds or thousands of websites. For example, the widely used jQuery JavaScript library has been breached multiple times, leading to digital skimming attacks broadly across the e-commerce sector. Adding jQuery to an application without appropriate security review to ascertain whether there was an outstanding vulnerability on that version of the library is a classic Shadow Code failing. Typosquatting is another favorite broad use case where hackers create malicious third-party scripts with names very similar to legitimate services for payments or chatbots, to name two examples, to trick developers into adding this code, or to reduce suspicion when this code sends stolen data to these domains. The malicious scripts then execute hard-to-detect skimming attacks against application users, often evading detection for months.

The definition of DevSecOps

Acourding do SumoLogic, DevSecOps is the philosophy of integrating security practices within the DevOps process. DevSecOps involves creating a ‘Security as Code’ culture with ongoing, flexible collaboration between release engineers and security teams. The DevSecOps movement, like DevOps itself, is focused on creating new solutions for complex software development processes within an agile framework.

DevSecOps is a natural and necessary response to the bottleneck effect of older security models on the modern continuous delivery pipeline. The goal is to bridge traditional gaps between IT and security while ensuring fast, safe delivery of code. Silo thinking is replaced by increased communication and shared responsibility of security tasks during all phases of the delivery process.

DevSecOps will go mainstream this year

With a growing percentage of code running on client-side applications coming from third-party JavaScript libraries or services, we see an increase in “Shadow Code.” When looking at front end JavaScript code, Shadow Code is code that is introduced into an application without a formal approval process or security validation. Shadow Code often takes the form of third-party vendors or open-source libraries delivering specific functionalities into an application. Shadow Code can also include first-party code introduced by a rogue or compromised developer, or unauthorized code injected into the application through a vulnerability or security breach. Because it was not appropriately reviewed or might have been compromised or modified since code review (which is commonly the case with 3rd party vendors), Shadow Code may harbor malicious client-side code that alters application behavior to illegally gather and exfiltrate PII from websites. The malicious code may escape further scrutiny since it executes on the client-side.

Who is Ido Safruti

Ido Safruti, CTO and co-founder of app security leader PerimeterX. Ido co-founded PerimeterX and as CTO is responsible for stewarding the company’s technology vision and leading the R&D team. Before PerimeterX, he was Senior Director of Product Management at Akamai focused on web performance and scalability. Ido joined Akamai through the acquisition of Cotendo, where he was VP for product strategy. Prior to Cotendo, he headed a cybersecurity branch of the Israeli intelligence services. He holds a master’s degree in computer science from Tel Aviv University and a degree in physics and mathematics from the Hebrew University.






Subscribe to App Developer Magazine

Become a subscriber of App Developer Magazine for just $5.99 a month and take advantage of all these perks.

MEMBERS GET ACCESS TO

  • - Exclusive content from leaders in the industry
  • - Q&A articles from industry leaders
  • - Tips and tricks from the most successful developers weekly
  • - Monthly issues, including all 90+ back-issues since 2012
  • - Event discounts and early-bird signups
  • - Gain insight from top achievers in the app store
  • - Learn what tools to use, what SDK's to use, and more

    Subscribe here



Featured Stories


Spotify and UMG strike landmark AI music licensing deal
Spotify and UMG strike landmark AI music licensing deal Thursday, May 28, 2026




Anthropic investigation opened after Mythos accessed by Discord group
Anthropic investigation opened after Mythos accessed by Discord group Wednesday, May 27, 2026


AI layoffS: What is really behind it all
AI layoffS: What is really behind it all Tuesday, May 26, 2026


The identity system is failing under AI
The identity system is failing under AI Monday, May 25, 2026


The Real World Launches Expert-Verified AI Certification Framework
The Real World Launches Expert-Verified AI Certification Framework Friday, May 22, 2026


Multiple language options when developing apps with Evoke
Multiple language options when developing apps with Evoke Thursday, May 21, 2026


When Social Listening Becomes Social Surveillance
When Social Listening Becomes Social Surveillance Wednesday, May 20, 2026


Medical debt relief custom-built platform moopFi launches
Medical debt relief custom-built platform moopFi launches Tuesday, May 19, 2026


Quant Pros Say AI Is Widening the Skills Gap
Quant Pros Say AI Is Widening the Skills Gap Monday, May 18, 2026


Tether QVAC SDK Powers AI Across Devices and Platforms
Tether QVAC SDK Powers AI Across Devices and Platforms Wednesday, April 22, 2026


Stay Updated

Sign up for our newsletter for the headlines delivered to you

SuccessFull SignUp

Get More App News



/sites/themes/prod/assets/js/less.js"> ' ' %>