Home > Fortify

Fortify

2215 Bridgepointe Pkwy
Suite 400
San Mateo
CA 94404
USA
[t] 001 650 358 5600
[f] 001 650 358 4600

 

Secure Code Development Necessity for Smartphone Apps

Warning from Fortify focuses on the proliferation of smartphone applications and the need for secure code development practices to be applied to them to prevent serious data security vulnerabilities from arising

12 March 2010

 

Hybrid 2.0 Provides Security Analysis on Web Applications

Fortify has been through a joint development activity with HP resulting in hybrid security analysis technology for web applications

24 February 2010

 

Industrial Consortium Calls for Secure Software Development Practices

Fortify is backing calls from the SANS Institute and Mitre Group for software developers to implement code development measures which are more secure thereby driving more responsibility for secure code to the suppliers

18 February 2010

 

Code audits required to close out GPS MiFi weakness

Internet revelations of GPS wireless positions indicate a flaw in code that has been exploited and needs avoiding with more careful code auditing, according to Fortify

25 January 2010

 

Risk of malicious modification on e-reader type devices

Fortify Software is warning of the potential risks from application specific devices where software and operating system modifications are relatively easy leading to vulnerabilities

06 January 2010

 

Code testing advice for users of open source code

With the major release of open source cloud computing security applications from Sun Microsystems, Fortify is warning users of any open source code to do extensive code testing to uncover vulnerabilities before use

24 December 2009

 

Electronic parking payment system protected by Fortify

Fortify assists parking provider Parkeon with securing their electronic payment systems against vulnerabilities and ensuring compliance with payment card standards

11 December 2009

 

Vulnerability assessment and remediation available on demand

Fortify on Demand is a software-as-a-service security product offering application testing, vulnerability assessment and remediation

10 December 2009

 

Windows 7 registration crack comes as no surprise to Fortify

The product activation system of Microsoft’s Windows 7 OS has been cracked, a problem which Fortify says is no surprise due to the complexity of code auditing operating system software

18 November 2009

 

Windows 7 vulnerabilities highlight need for code auditing

Fortify is unsurprised by recent report that Windows 7 is highly vulnerable to viruses and is an example of a clear code auditing regime for software developers

06 November 2009

 

Four popular myths about cyber security

Richard Kirk of Fortify Software dispels four of the key myths that surround corporate data security

27 October 2009

 

WiFi Direct Standard contains security flaw

Fortify is calling for changes to the proposed new standard concerning WD-enabled WiFi Devices to prevent a potentially serious vulnerability

21 October 2009

 

Fortify prepares parking company for PCI compliance

Parkeon has chosen Fortify to examine the security of its IT systems to enable it to gain compliance with Payment Card Industry regulations next month

25 September 2009

 

Porosity of RBS Worldpay site down to poor code auditing

Hacker’s revelation that RBS Worldpay web portals are open to vulnerabilities doesn’t surprise Fortify who recommend code auditing as a preventive measure

16 September 2009

 

Code auditing can help prevent PBX phreaking

The recent high profile hack of a toll-free PBX in North Carolina illustrates the need for code auditing to close system back doors

03 September 2009

 

Code auditing could have avoided hotel booking losses

Poor application code testing on web application causes online booking losses at Intercontinental hotels according to Fortify

19 August 2009

 

Cross site scripting flaws continue to hit businesses

Hackers identify XSS flaw on Ministry of Defence site, highlighting continued vulnerabilities due to cross site scripting

14 August 2009

 

Chrome OS can’t promise a virus free environment

Fortify points out the flaw in the argument of Google’s Engineering Director since application vulnerabilities mean OS improvements alone can’t eradicate viruses

24 July 2009

 

Security as a service boosts Fortify’s quarterly results

Fortify Software registers a record quarter for earnings with existing enterprise vulnerability management products enhanced by new SaaS offering

23 July 2009

 

Fortify believes mobiles will grow as a Trojan target

As processing capabilities of SmartPhones increases, so does their viability as a target for malware writers with Fortify predicting more serious problems to come

22 July 2009

 

Parcel Force web site errors avoidable with code testing

In-house developed code on web-sites tend to be more vulnerable to attack which could have been the case with Parcelforce according to Fortify

23 June 2009

 

HP collaboration on software security testing

Fortify has entered a joint program with HP on business risk reduction through application lifecycle security

16 June 2009

 

ATM code sniffing results from poor security audits

Fortify reports that extensive code auditing could have prevented the recent spate of data-sniffing that has taken place in Eastern Europe for extracting cardholder data

09 June 2009

 

Survey demonstrates degree of hacker vulnerability

Nearly three quarters of IT professionals believe their companies are still vulnerable to hacker intrusions

05 June 2009

 

Security patch service withdrawal warning for Office 2000 users

Microsoft will be withdrawing it’s security patch support of the popular Office 2000 product from mid July this year

02 June 2009

 

Code audit advice for new XP-based software

New applications to run under Windows XP will require stringent code auditing as Microsoft reduces support levels for the most popular version of its operating system

25 May 2009

 

Poor software development results in credit card breach

Fortify comments on the possible causes for Atlanta data breach where customer was able to view on-line credit card statements of 120 users

18 May 2009

 

Ironic hack comes as no surprise

Fortify comments on the recent “ironic” hack of movie licensing site with link to illegal file sharing site

11 May 2009

 

Hacked facebook page a warning to users of Web 2.0

High profile Facebook hack serves as a reminder of the need for code auditing to prevent user content from being manipulated

27 April 2009

 

Twitter attacks avoidable with code audits

With improved code auditing and security processing during software development, applications such as those found on Twitter would be less vulnerable according to Fortify

15 April 2009

 

Security levels inconsistent with e-mail SaaS predictions

Gartner forecast for levels of e-mail software as a service models not consistent with the security protection levels available according to Fortify

09 April 2009

 

Hosted Vendor Security Management from Fortify

Fortify releases enhancements to Fortify 360 as well as branching into the hosted security services market with Vendor Security Management

06 April 2009

 

Code auditing essential for utilities protection

Analysis and audit of custom code an essential element of protecting utility networks from being hacked according to Fortify

31 March 2009

 

New Fortify report offers a guide to cryptographic algorithms

A new report from Fortify's Security Research Group provides a guide to cryptographic algorithms - detailing which ones to use, which ones not to use and when it is appropriate to use them.

19 March 2009

 

Security software benchmarking model

Cigital and Fortify join forces to develop enterprise software security benchmarking program

10 March 2009

 

Card fraud set to increase in 2009

Fortify is predicting a 33% increase in payment fraud crime during 2009 with as many as 1 in 3 people likely to be affected

26 February 2009

 

Security testing recognition for Fortify

Gartner recognises Fortify Software in the area of Static Application Security Testing

13 February 2009

 

Open source danger for government applications

Public sector organisations need to think carefully about the security implications before opting for open source solutions according to Fortify

06 February 2009

 

Google outage a lesson in the human factor

Mistakes made by IT security personnel or those with modify access to databases can cause chaos as proven by the recent 55 minute outage at Google

04 February 2009

 

Heartland heist could have been rogue software

Fortify speculates on the cause of the data breach of the Heartland Payment System and looks at how it could have been caused by a rogue employee or by a direct external attack on the system

23 January 2009

 

Strong growth for Fortify despite economic crisis

Final quarter bookings increase 80% over previous year due to increased diligence in IT security regardless of crisis conditions

22 January 2009

 

Increasing trend towards middle-Eastern web threats

Hackers from the middle East are increasing their activities in the wake of the crisis existing between Israel and Palestine

07 January 2009

 

Pirate copies of Windows 7 contain security flaws

Fortify issues warnings against downloading Windows 7 pirate copies after discovering poor build level and significant security flaws

05 January 2009

 

Hack vulnerability of IP based PBX systems

Recent US hack on PBX results in $52000 phone bill presenting a timely reminder for protection of vulnerable systems

24 December 2008

 

VoIP vulnerabilities explained by Fortify

Fortify attempts to raise corporate awareness of the vulnerability of voice-over-IP based private branch exchanges to attacks by hackers

10 December 2008

 

Bloor recognition for Fortify Software

Application security leadership recognition for Fortify software received in Bloor Research market update report

03 December 2008

 

Getting the IT security message through to the board

Fortify Software’s European Director, Richard Kirk explains the art of providing management justifications for changes that may need to be made to keep ahead of the game.

12 November 2008

 

Joint centre established for software assurance

Fortify and Wipro join forces to establish centre for assuring software security throughout the world

28 October 2008

 

Protection through Business Software Assurance

Rob Rachwald of Fortify Software examines the extent of corporate software crime and methods of bolstering protection against it

27 October 2008

 

Report on US voting systems

Fortify assists voters in choosing the most reliable and secure voting methods in report on voting in the American Presidential elections

16 October 2008

 

Microsoft’s secure computing initiative begins to pay off

Advances in development of secure software in Microsoft team results in a fall from the top of IBM’s reported security incident chart for the world’s largest software vendor

29 September 2008

 

Dynamic analysis better for staying ahead of hackers

Whilst welcoming IBM into the market of static analysis, Fortify believes that the most comprehensive protection comes from a more dynamic approach

26 September 2008

 

Clickjacking flaw discussion moratorium

Crackers’ discussion of Adobe Clickjacking problem suspended in effort to enable time for vendor response

24 September 2008

 

Fortify 360 secure code development software available free to universities

University students and researchers to benefit from freely available software from Fortify for building secure code

16 September 2008

 

Hacker interest in virtual environments leads to high patch activity

Large number of VMWare patches released this week an indication of the increased level of interest shown in virtual environments by the hacker community

08 September 2008

 

Application security testing drives strong annual growth

Double the orders for 2007 drive outstanding growth for Fortify, consolidating its position in the market of Business Assurance software

04 August 2008

 

Fortify 360 now identifies vulnerabilities in SOA frameworks

Protection extended for Fortify 360 customers as vulnerabilities in web services and SOA configurations are now revealed by the software

29 July 2008

 

ActiveX vulnerability illustrates difficulty in fixing flaws

Continual discovery and rectification of flaws in applications illustrates the need for pro-active protection against IT threats

11 July 2008

 

SQL injection warning for MS ASP users

Active Server Page users are being warned by Fortify of vulnerability which can result in SQL injection attacks

07 July 2008

 

Fortify 360 users gain PCI compliance assistance

Vulnerabilities for Payment Card Industry compliance identified by Fortify 360 enabling problem remediation for users

25 June 2008

 

Complex software trends create increased vulnerability

Report on the complexity of enterprise software reveals an increased possibility of security flaws being present causing risk for inadequately protected businesses

24 June 2008

 

XSS flaw problem needs to be urgently addressed

Fortify is calling on the IT security industry to make a consolidated attack on cross site scripting flaws before the problem becomes unmanageable

12 June 2008

 

Fortify discovers systematic web hacking route

Systematic vulnerability in web security could affect all web authorisation security applications

09 June 2008

 

Linux security flaw verified by Fortify

Cryptographic key vulnerability in Debian and Ubuntu Linux operating systems represents serious security flaw

20 May 2008

 

SQL attacks on web applications continue to increase.

Fortify warns of the need for protection against malicious web site attacks that can compromise applications and expose sensitive data.

02 May 2008

 

Application vulnerability exposes public data.

The US State of Oklahoma has been the victim of SQL injection vulnerability allowing thousands of its resident’s data to become exposed.

18 April 2008

 

Reader recognition for software development product.

SC Magazine readers select SCA 5.0 from Fortify as the best product for developing secure code.

15 April 2008

 

Fortify warns of outsourcing dangers.

Outsourcing decisions frequently overlook the requirement to build strong security into application code according to survey by Fortify.

08 April 2008

 

Software weakness could have been behind Hannaford data loss.

Server code vulnerability likely to have allowed unauthorised access to card-holder data in US supermarket breach according to Fortify.

02 April 2008

 

Buffer overflows are predicted to hit PBXs.

Fortify Software, the application vulnerability specialist, says that companies may soon find their PBX computerised telephone switchboards being hit by a new wave of security flaws.

20 March 2008

 

Increase in buffer overflow attacks on social networking sites.

Freely available hacking software leads to series of hack attacks on social networking sites causing problems across the whole of the web community.

29 February 2008

 

E-banking remains safe despite more sophisticated ID theft techniques.

Fortify Software continues to believe in the safety of internet banking provided that sufficient security software is installed and kept up to date.

29 February 2008

 

Hacking for profit represents the changing trend of cyber criminals.

Richard Kirk of Fortify Software gives an overview of cyber crime and how the obsolete image of hackers must be replaced by serious criminals who need to be fought using the latest security tools.

21 February 2008

 

Disclosure war between Mozilla and Opera unhelpful to end users.

Browser vulnerability shared between Mozilla and Opera gives Mozilla the advantage as it issues a patch without disclosing the problem to Opera with enough time for them to issue a similar fix.

21 February 2008

 

Vulnerability auditing could have avoided Swedish bank crime.

Internal hacking in Swedish financial institute highlights the need for software controls to detect cases of employee based security attacks.

05 February 2008

 

Free offer to secure US e-voting systems.

Fortify is offering free copies of SCA 5.0 to secure electronic voting machines in the forthcoming US elections.

04 February 2008

 

BetFair podcast outlines their approach to web security.

European E-commerce business presents podcast on securing web applications with high transaction rates against hacking threats.

01 February 2008

 

Auto reality check compromise increases spam from major e-mail services.

E-mail service sign up technology compromise has allowed spammers to sign up for Yahoo, Google and Hotmail accounts generating a surge in spam from these domains warns Fortify.

24 January 2008

 

Fortify hosts pre-screening of cybercrime documentary.

The New Face of Cybercrime highlights the current state of criminality using computers with responses from the security industry and can be seen at previews hosted by Fortify in the UK and USA.

09 January 2008

 

Computer Associates falls victim to web site hack.

Chinese malware site picks up re-routes from Computer Associates web site causing embarrassment for the US computer giant.

08 January 2008

 

MI5 indicates cyber crime is a threat to national security.

Hackers find ways of exploiting weak software that gets around the perimeter defences supplied by most firewalls and anti-virus software.

04 December 2007

 

Fortify warns online Christmas shoppers of the eGrinch.

Increased online spending in the Christmas season provides ripe opportunities for cyber criminals and thus demanding extra caution from users.

23 November 2007

 

Fortify products for retail PCI compliance.

Retails can now address crucial payment card industry compliance issues with the use of Fortify’s SCA and Defender products.

28 June 2007

 

PCI Standard compliance requirement deadline eased.

Fortify comments on Government easing of Payment Card Industry requirements as deadline approaches.

28 June 2007

 

Fortify updates rulepack to include detection of JavaScrip Hijacking.

Rulepack now includes comprehensive protection against computer threats by counteracting the latest hacking threats.

14 May 2007

 
 

 

© 2010 ProSecurityZone.com