ProfitQuotes.com
symbol lookup  commodity list
Bookmark This Page
Friday's ETF with Unusual Volume: RSPU

Fri, 03 May 16:24:07 GMT
S&P 500 Analyst Moves: CTRA

Fri, 03 May 16:12:25 GMT
Portfolio Channel
Free Energy Dividend Stock Report
Free Dividend Report - Top Ranked Stocks
Free Dividend Paying Gold/Metals Stocks Report
Get a quote box (like the one below) for your site!
ProfitQuotes.com Commodities Quotes
commodity quotes list
energy quotes  gold quotes
uranium stocks  
solar power stocks

wind power stocks

Industry focus:

advertising stocks,
space stocks,
aerospace stock,
aerospace sector,
list of aerospace companies,
largest chemical companies,
chemical stock,
chemical news,
best agriculture stocks,
ag stocks,
chinese agriculture stocks,
top agriculture companies,
agriculture stocks,
agricultural stocks,
agricultural stock,
stocks agriculture,
agriculture markets,
agriculture index,
agriculture industries,
agricultural investment,
agriculture investment,
agricultural industry,
farm stock,
airline stock symbols,
airline stock prices,
airline stock,
airlines stock,
clothing stock,
fashion stocks,
publicly traded fashion companies,
clothing company stocks,
apparel stock,
apparel companies,
application software stocks,
asset management stocks,
auto stocks,
auto industry stocks,
chinese auto stocks,
auto stock prices,
automotive stock,
auto parts stocks,
community bank stocks,
regional bank stocks,
canadian bank stocks,
banking stock,
national bank stocks,
commercial bank stock,
banks stock,
bank stock quote,
bank stocks,
banking industry,
alcohol stocks,
beverage stock,
global wine stocks,
wine stocks,
liquor stock,
biotech stocks list,
biotechnology investing,
public biotech companies,
top biotech stocks,
nanotechnology stock,
largest biotech companies,
biotechnology stock,
biotech investing,
investing in biotech,
best biotech companies,
bio stocks,
biotech sector,
biotechnology investment,
biopharma companies,
new biotech companies,
biotech investment,
biotechnology industries,
nanotech stocks,
biotech stocks,
biotechnology articles,
biotechnology news,
business stocks,
service stocks,
chemical companies,
chemical industries,
chemical industry,
chemical company,
chemicals company,
cigarette stock,
cigarette company stocks,
cigarette stock symbols,
tobacco company stocks,
tobacco stock,
cigar stocks,
communications stocks,
communication stock,
computer peripherals companies,
computer peripherals,
computers stocks,
computer stock,
computer web,
internet stocks,
construction stocks,
machinery stocks,
builders stocks,
building stocks,
consumer goods stocks,
consumer services stocks,
consumer services companies,
lending stocks,
mortgage banking,
lending companies,
mortgage bankers,
loan services,
mortgage services,
mortgage bank,
loan bank,
defense stocks,
defensive stock,
department store stocks,
diagnostic company,
diagnostic companies,
pharmaceuticals stocks,
drug stocks,
drug company stocks,
pharma stock,
education stocks,
college stock,
electric utility stocks,
electric company stocks,
electric utilities stocks,
utility stocks,
utilities stocks,
power equipment companies,
electrical supply companies,
electronic stocks,
entertainment stock,
movie stocks,
movies companies,
movie company,
cefs,
open ended and closed ended mutual funds,
closed ended investment,
closed ended fund,
bonds fund,
closed end,
food stock,
game stock,
gambling stocks,
casino stocks,
gaming stocks list,
gaming stocks,
gas utility companies,
gas company stocks,
construction industries,
builders contractors,
construction services,
construction industry,
grocery store stocks,
supermarket stock,
drug store stocks,
home stocks,
furniture stock,
home improvement stocks,
medical company stocks,
top medical stocks,
medical stock,
hospital stock,
medical supply stocks,
medical technology stocks,
medical device stocks,
medical equipment stocks,
copper mining,
palladium mining stocks,
mining metals,
mining,
mining news,
gold exploration,
mining share price,
lithium mines,
mining industries,
international mining companies,
mining information,
molybdenum mining companies,
nickel mining companies,
metals and mining stocks,
gold and silver mining stocks,
copper mining companies,
rare earth mining companies,
rare metals stocks,
rare earth stocks,
metals stocks,
welding stock,
nonprecious metals,
non metallic mining,
office supplies companies,
office supply companies,
oil services stocks,
oil pipeline stocks,
gas pipeline stocks,
gas pipeline companies,
pipeline companies,
natural gas pipeline companies,
oil services companies,
oil field services,
oil service stocks,
natural gas pipelines,
oilfield service companies,
oil and gas pipeline companies,
oil gas pipeline,
oil exploration stocks,
oil exploration sector,
oil exploration companies,
oil drilling stocks,
oil drilling companies,
oil production companies,
china oil companies,
brazil oil companies,
china oil stocks,
brazil oil stocks,
oil companies,
oil stocks,
oil drilling,
oil exploration,
offshore oil drilling companies,
list of oil drilling companies,
oil and gas exploration,
oil and gas drilling,
oil and gas stocks,
oil and gas drilling companies,
oil refining companies,
oil marketing companies,
oil refining stocks,
oil refining sector,
oil refinery companies,
oil refinery stocks,
major oil companies,
oil sector,
oil refinery,
oil refinery company,
oil company,
oil marketing company,
oil refining company,
oil refining industry,
major oil companies list,
oil and gas companies,
crude oil stocks,
packaging companies,
container companies,
packaging stocks,
packaging sector,
container sector,
pulp stocks,
paper stocks,
timber stocks,
pulp companies,
paper companies,
timber companies,
timber trusts,
cardboard companies,
paper sector,
timber sector,
paper companies list,
silver mining companies,
gold mining companies,
gold mining sector,
precious metal stocks,
mining companies,
exploration sector,
mining sector,
exploration stocks,
mining stocks,
silver stocks,
gold stocks,
gold mining stocks,
silver mining stocks,
silver mining company,
canadian mining companies,
gold mining,
gold mining company,
mining company,
list of mining companies,
gold stocks list,
largest gold mining companies,
silver mining,
printing companies,
printing stocks,
printing sector,
newspaper stocks,
newspaper sector,
newspaper companies,
publishing stocks,
publishing sector,
publishing companies,
digital media companies,
digital media stocks,
digital media sector,
book publishing companies,
digital media company,
publishing company,
railroad stocks,
railroad sector,
railroad companies,
railroad company,
railroad investment,
major railroad companies,
real estate companies,
real estate stock,
real estate public companies,
real estate investing,
real estate investments,
real estate sector,
commercial real estate investing,
real estate investment firms,
real estate investing guide,
REITs,
real estate investment trust,
REIT sector,
REIT stocks,
REITs sector,
REITs stock,
public REITs,
real estate investment trusts,
real estate investment trust companies,
real estate investment trusts REITs,
real estate investment companies,
real estate investment company,
real estate investment trust REIT,
rubber stocks,
plastic stocks,
rubber companies,
plastic companies,
rubber sector,
plastic sector,
plastic manufacturing companies,
rubber company,
plastic company,
semiconductor stocks,
semiconductor investments,
semi stocks,
semiconductor companies,
semiconductor sector,
shipping stocks,
dry bulk stocks,
container stocks,
dry bulk shipping,
dry bulk shipping companies,
tanker stocks,
shipping companies,
shipping sector,
specialty retail,
retail stocks,
retail investing,
retail store stocks,
consumer stocks,
consumer investment,
retail companies,
retail sector,
sports stocks,
sports investing,
sporting goods stocks,
sports investments,
sporting goods companies,
sporting goods sector,
stock message boards,
television stocks,
television investment,
radio stocks,
radio invest,
media stocks,
media invest,
media investment,
media investing,
television companies,
television sector,
radio sector,
radio companies,
media companies,
media sector,
textile stocks,
apparel stocks,
textile investment,
textile companies,
textile sector,
apparel sector,
freight investment,
transportation investment,
truck investment ,
freight stocks,
transportation stocks,
trucking stocks,
trucking companies,
trucking sector,
waste management stocks,
waste stocks,
recycling stocks,
waste investment,
waste companies,
waste sector,
water stocks,
water utilities,
water investing,
water investment,
water companies,
water sector

Home Oil & Gas Electricity Metals Treasuries Stocks My Portfolios Forex
News - Full Story
 Related Quotes
 Jfrog LTD. - Ordinary Shares  40.38   0.66  1.66%
 Enter Symbols: 

JFrog Software Supply Chain Report Shows Most Critical Vulnerabilities Scores Are Misleading


74% with High or Critical CVSS scores weren't applicable in most common cases, but 60% of security and development teams still spend a quarter of their time remediating vulnerabilities

SUNNYVALE, Calif. & PARIS, Mar. 19 /BusinessWire/ -- (KubeCon + CloudNativeCon Europe) - JFrog Ltd. ("JFrog") (NASDAQ:FROG), the Liquid Software company and creators of the JFrog Software Supply Chain Platform, today released the findings of its annual Software Supply Chain State of the Union report 2024, which identifies emerging development trends, risks and best practices for securing enterprise software supply chains.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20240319775900/en/

JFrog Software Supply Chain State of the Union Report 2024 (Graphic: JFrog)

JFrog Software Supply Chain State of the Union Report 2024 (Graphic: JFrog)

"DevSecOps teams worldwide are navigating a volatile field of software security, where innovation frequently meets demand in an age of rapid AI adoption," said Yoav Landman, CTO and Co-Founder, JFrog. "Our data provides security and development organizations with a comprehensive snapshot of the rapidly evolving software ecosystem, including notable CVE scoring errors, perspectives on the security implications of using GenAI to code, the most risky packages to allow your organization to use for development, and more, so they can make more informed decisions."

Key Findings

JFrog's Software Supply Chain State of the Union report combines JFrog Artifactory developer usage data amongst 7K+ organizations, original CVE analysis by the JFrog Security Research team, and commissioned third-party survey data of 1,200 technology professionals worldwide to provide context into the broad, rapidly evolving software supply chain landscape. Key findings include:

  • Not all CVEs are what they seem - Traditional CVSS ratings look purely at the severity of the exploit as opposed to the likelihood it will be exploited, which requires context to make an effective assessment. The JFrog Security Research team downgraded the severity of 85% of Critical CVEs and 73% of High CVEs on average after analyzing 212 different high-profile CVEs discovered in 2023. Additionally, JFrog found that 74% of the reported common CVEs with High and Critical CVSS scores on the top 100 Docker Hub community images weren't exploitable.
  • Denial of Service (DoS) attacks reign - Of the 212 high-profile CVEs analyzed by the JFrog Security Research team, 44% of them held the potential for a DoS attack vs. 17% with the potential to perform Remote Code Execution (RCE). This is good news for security organizations in the sense that RCE has a far more detrimental impact vs. DoS attacks due to their ability to offer full access to backend systems.
  • Security taking a toll on productivity - Forty percent of survey respondents said it typically takes a week or longer to get approval to use a new package/library, extending time to market for new apps and software updates. Additionally, approximately 25% of security teams' time is spent remediating vulnerabilities, even when those vulnerabilities may be overrated or even non-exploitable given their current context.
  • Applying security checks is inconsistent across the software development lifecycle (SLDC) - The industry seems to be split pretty evenly down the middle when it comes to deciding where to apply application security testing across the software development lifecycle, underscoring the importance of shifting left and right simultaneously. Forty-two percent of developers claim it's best to perform security scans during code writing while 41% say it's best to perform scans on new software packages before bringing them into your organization from an Open-Source Software (OSS) repository.
  • Security tool sprawl continues - Nearly half of IT professionals (47%) say they use between four and nine application security solutions. However, a third of survey respondents and security professionals (33%) say they're using 10 or more application security solutions. This supports a market-wide trend of needing security tooling consolidation with a movement away from point solutions.
  • Disproportionate use of AI/ML tools for security - While 90% of survey respondents indicate their organization currently uses AI/ML-powered tools in some capacity to assist in security scanning and remediation efforts, only one in three professionals (32%) claim their organization uses AI/ML-powered tools to write code, indicating the majority are still wary of the potential vulnerabilities GenAI-developed code can introduce to enterprise software.

"Vulnerabilities are growing in number year over year, but that does not necessarily mean they are growing in severity. It's clear that IT teams are willing to invest in new tools to bolster their security, but knowing where to put those tools, use their team's time, and streamline processes is critical to keeping their SDLC secure," said Shachar Menashe, Sr. Director, JFrog Security Research. "We designed this report to go beyond trend analysis, providing both counsel and clarity on the technology business leaders use to make decisions, whether it's on AI navigation, malicious code, or security solutions."

For deeper insights from the JFrog Software Supply Chain State of the Union 2024 download the full report. You can also register to join JFrog security and developer experts on Wednesday, April 17, 2024 at 10:00 a.m. PT for a webinar, "Safeguarding Software Supply Chains in 2024: A Deep Dive into the State of the Union Report," detailing the challenges and complexities of managing and securing the software supply chain.

Like this Story? Share this: @JFrog shares research findings in their annual Software Supply Chain State of the Union 2024 report. Discover the emerging #DevSecOps trends, risks & best practices to securing enterprise #SoftwareSupplyChain. Learn more: https://jfrog.co/3TzsVNg #SoftwareSupplyChain #DevOps #DevSecOps #cybersecurity #containers #CVE

About JFrog

JFrog Ltd. (NASDAQ: FROG) is on a mission to create a world of software delivered without friction from developer to device. Driven by a "Liquid Software" vision, the JFrog Software Supply Chain Platform is a single system of record that powers organizations to build, manage, and distribute software quickly and securely, ensuring it is available, traceable, and tamper-proof. The integrated security features also help identify, protect, and remediate against threats and vulnerabilities. JFrog's hybrid, universal, multi-cloud platform is available as both self-hosted and SaaS services across major cloud service providers. Millions of users and 7K+ customers worldwide, including a majority of the Fortune 100, depend on JFrog solutions to securely embrace digital transformation. Once you leap forward, you won't go back! Learn more at jfrog.com and follow us on Twitter: @jfrog.

Cautionary Note About Forward-Looking Statements

This press release contains "forward-looking" statements, as that term is defined under the U.S. federal securities laws, including but not limited to statements regarding the JFrog Software Supply Chain Report.

These forward-looking statements are based on our current assumptions, expectations and beliefs and are subject to substantial risks, uncertainties, assumptions and changes in circumstances that may cause JFrog's actual results, performance or achievements to differ materially from those expressed or implied in any forward-looking statement. There are a significant number of factors that could cause actual results, performance or achievements, to differ materially from statements made in this press release, including but not limited to risks detailed in our filings with the Securities and Exchange Commission, including in our annual report on Form 10-K for the year ended December 31, 2023, our quarterly reports on Form 10-Q, and other filings and reports that we may file from time to time with the Securities and Exchange Commission. Forward-looking statements represent our beliefs and assumptions only as of the date of this press release. We disclaim any obligation to update forward-looking statements.

<  back


TickerTech.com Private-label branded pages powered by TickerTech.com. Copyright © 2024 Ticker Technologies, All Rights Reserved. Quote data is at least 20 minutes delayed. NYMEX/COMEX data is at least 30 minutes delayed. Please read other important disclaimer information.
"No profit grows where is no pleasure ta'en: In brief, sir, study what you most affect." - William Shakespeare
Google
 

© Ticker Technologies, all rights reserved. Profitquotes.com is wholly owned by Ticker Technologies and serves to demonstrate the company's products to prospective clients. All quotes are in US Eastern Time (EST) and delayed at least 15 minutes. NYMEX/COMEX data delayed at least 30 minutes. Data is presented for informational purposes only and not intended for investment purposes. Nothing on this site should be considered advice, opinions, recommendations, or endorsements from ProfitQuotes.com or TTI Group. Full Disclaimer.