Connect with us

Technology

New Research From Legit Security and TechTarget’s Enterprise Strategy Group Shows Outdated Application Security Approaches Do Not Work With Modern Development Trends

Published

on

Comprehensive study shows an urgent need for organizations to adopt a modernized approach to their application security processes

BOSTON, Aug. 16, 2024 /PRNewswire/ — Legit Security, the definitive application security posture management (ASPM) leader providing end-to-end visibility and protection across the entire software factory, and TechTarget’s Enterprise Strategy Group (ESG), a leading IT analyst, research, and strategy firm, today announced the publication of Modernizing Application Security to Scale for Cloud-native Development. The report delves into the development trends driving the need to modernize application security programs and evaluates pressing challenges that application security teams encounter with their current tools. The findings underscore the urgency for organizations to modernize their application security practices so that they can support growth and mitigate risks.

“Organizations are increasingly adopting new technologies so that they can bolster their software development, and as modern development has changed, so have attacker tactics,” said Joe Nicastro, Field CTO, Legit Security. “Development teams are using cloud-native technologies to drive efficiency and optimize innovation, but this often leads to a larger attack surface due to misconfigurations, vulnerable plug-ins, and excessive permissions throughout the SDLC. In today’s environment, organizations must adopt security solutions that can protect their software factory from end-to-end while providing developers with the guardrails they need to do their best work safely.”

The report found that application teams face a number of challenges, such as keeping up with the speed and volume of releases and prioritizing remediation. These challenges highlight the importance of a modernized approach and alignment with development and DevOps teams for improved collaboration. Additionally, nearly all organizations reported difficulties in fixing vulnerabilities after applications are deployed, reinforcing the significance of incorporating security processes and tools in the build process.

The report’s key findings include:

60% of organizations use IaC to simplify infrastructure provisioning and easily deploy software applications. However, with increased IaC adoption, misconfigurations can be magnified because flaws are easily proliferated if not addressed. Of particular concern, 67% of respondents report an increase in IaC misconfigurations.45% of security teams supporting cloud-native development processes said understanding and managing risks related to usage of generative AI is their biggest challenge, followed by measuring and improving AppSec program effectiveness, and understanding developer environments and assets to effectively manage security.The majority of organizations experienced a cybersecurity event involving their cloud-native application stack in the last 12 months, with secrets stolen from a source code repository (32%) coming in as the most common incident.Only 39% of organizations report that their security teams have visibility for certain applications, reinforcing the necessity for visibility into security testing in development.

“Our research calls attention to how traditional application security teams need solutions that support modern development processes as they scale to drive productivity and business growth,” said Melinda Marks, Practice Director, Cybersecurity, Enterprise Security Group. “The research showed that in addition to securing the applications, security teams need to address security related to how developers work, including secrets, pipeline tools, containers, and source code repositories. While these elements enable developers to work quickly and collaborate, the added attack surfaces and chance for mistakes become greater as development scales. By understanding and addressing these areas, organizations can improve their security programs. This is important as we have seen all too often that just one incident can have severe ramifications on the business, including data loss, business disruption, application downtime, customer data loss, malware, and compliance fines.”

To download the report, visit http://info.legitsecurity.com/esg-modernizing-application-security-to-scale-for-cloud-native-development.

To read our latest blog and perspective on the report, visit https://www.legitsecurity.com/blog/esg-survey-report-finds-ai-secrets-and-misconfigurations-plague-appsec-teams

Methodology
TechTarget’s Enterprise Strategy Group surveyed 350 IT, cybersecurity, and application development professionals in North America (US and Canada) responsible for evaluating, purchasing, and utilizing developer-focused security products (i.e., application/code security testing tools, software composition analysis, policy-setting tools, remediation tools, etc.). 

About Legit Security
Legit is a new way to manage your application security posture for security, product, and compliance teams. With Legit, enterprises get a cleaner, easier way to manage and scale application security and address risks from code to cloud. Built for the modern SDLC, Legit tackles the most challenging problems facing security teams, including GenAI usage, proliferation of secrets, and an uncontrolled dev environment. Fast to implement and easy to use, Legit lets security teams protect their software factory from end to end, gives developers guardrails that let them do their best work safely, and delivers metrics that prove the security program’s success. This new approach means teams can control risk across the business – and prove it.

About ESG
Enterprise Strategy Group is an integrated technology analysis, research, and strategy firm providing market intelligence, actionable insight, and go-to-market content services to the global technology community. It is increasingly recognized as one of the world’s leading analyst firms in helping technology vendors make strategic decisions across their go-to-market programs through factual, peer-based research. ESG is a division of TechTarget, Inc. (Nasdaq: TTGT), the global leader in purchase intent-driven marketing and sales services focused on delivering business impact for enterprise technology companies.

Media Contact for Legit Security:
Michelle Yusupov
Hi-Touch PR
443-857-9468
yusupov@hi-touchpr.com

SOURCE Legit Security

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

The Denver Post Names Luminate Bank the #1 Large Top Workplace in Colorado for 2026

Published

on

By

MINNEAPOLIS, May 13, 2026 /PRNewswire/ — Luminate Bank® earned the #1 ranking among large companies in The Denver Post’s Colorado Top Workplaces 2026 awards. The company also received the Special Award for Appreciation, recognizing its culture of employee support and recognition. This distinction is based solely on employee feedback gathered through a third-party survey administered by employee engagement technology partner Energage LLC. The confidential survey uniquely measures the employee experience and its component themes, including that employees feel Respected & Supported, Enabled to Grow, and Empowered to Execute, to name a few.

“Being named a Top Workplace is incredibly meaningful because it comes directly from the individuals who choose to grow their careers with us and show up every day with purpose and conviction. They are the foundation of our success,” said Eric Lovins, President of Mortgage Lending at Luminate Bank. “We don’t take the responsibility of earning their trust lightly, and we remain committed to creating an environment where they can thrive, succeed, and feel proud of the work they do.”

Luminate Bank traces its roots to 1937, when it first opened as Equity Bank. In 2020, the organization was acquired and reintroduced as Luminate Bank and Luminate Home Loans, reflecting a renewed commitment to guiding customers through complex financial moments with clarity and care. In 2025, Luminate Home Loans and Luminate Bank unified under one brand, combining full-service banking with a strong mortgage platform to expand offerings and better serve customers. Today, Luminate Bank’s team of more than 700 professionals nationwide continues to focus on relationship-based banking paired with digital innovation, supporting responsible growth and long-term customer success.

“Earning a Top Workplaces award is a badge of honor for companies, especially because it comes authentically from their employees,” said Eric Rubino, Energage CEO. “That’s something to be proud of. In today’s market, leaders must ensure they’re allowing employees to have a voice and be heard. That’s paramount. Top Workplaces do this, and it pays dividends.”

About Luminate Bank® — At Luminate Bank, We Open Doors—empowering individuals and families to achieve their financial dreams through personalized service and innovative digital solutions. As a nationwide bank headquartered in Minneapolis, Minnesota, we are committed to helping our clients meet their financial goals with a blend of modern technology, traditional values, and the trusted guidance of experienced professionals. Known for our exceptional commitment to customers, we take pride in delivering a seamless, supportive experience for every step of the journey. Our dedicated mortgage division has branches and a team of loan originators across the US, making expert home financing solutions accessible to communities nationwide.

Luminate Bank is committed to safeguarding your money and accounts with FDIC insurance coverage up to applicable limits. Learn more about how we can open doors for you at www.luminate.bank, follow us on Instagram, LinkedIn, and Facebook, or call (952) 939-7200.

ABOUT ENERGAGE
Making the world a better place to work together.™
Energage is a purpose-driven company that helps organizations turn employee feedback into useful business intelligence and credible employer recognition through Top Workplaces. Built on 20 years of culture research and the results from 30 million employees surveyed across more than 80,000 organizations, Energage delivers the most accurate competitive benchmark available. With access to a unique combination of patented analytic tools and expert guidance, Energage customers lead the competition with an engaged workforce and an opportunity to gain recognition for their people-first approach to culture. For more information or to nominate your organization, visit energage.com or topworkplaces.com.

Media Contact
Debbie Schwake, CMO
debbie.schwake@luminate.bank
952-698-3300

View original content to download multimedia:https://www.prnewswire.com/news-releases/the-denver-post-names-luminate-bank-the-1-large-top-workplace-in-colorado-for-2026-302771529.html

SOURCE Luminate Bank

Continue Reading

Technology

InfoSight Launches AI-Enabled Purple Team SOCaaS: Machine-Speed Defense, Human-Led Control

Published

on

By

Purple SOC Unifies Offensive Testing, Defensive Monitoring, and AI-Driven Detection Engineering Into a Single Human-Led Security Program

MIAMI, May 13, 2026 /PRNewswire/ — InfoSight today announced the general availability of its AI-Enabled Purple Team Security Operations Center as a Service (SOCaaS)—a managed security solution that combines AI-driven attack path intelligence with human-led security governance. The service redefines how organizations detect, validate, and respond to modern cyber threats by unifying offensive adversary emulation and defensive monitoring into a single, continuously operating program.

AI-Enabled Purple SOC: Offensive Testing, Defensive Monitoring & Detection Engineering in One Human-Led Security Program

Modern enterprises face a growing mismatch between attacker speed and defender capability. AI-driven attack tools now operate at scale—testing controls, chaining vulnerabilities, and adapting faster than traditional SOC workflows can respond. Meanwhile, many Security Operations Centers (SOC) remain constrained by human-speed processes, where alert queues backlog, tickets accumulate, and threats progress before action is taken.

The challenge is no longer visibility—it is speed, correlation, and execution.

InfoSight’s Purple Team SOCaaS addresses this gap by delivering continuous threat exposure management across the full attack lifecycle. Rather than reacting to alerts alone, the AI-enabled experts continuously hunt for Advanced Persistent Threats (APT) and indicators of compromise (IOC)while decoding real-time threat signals to anticipate adversary behavior before incidents occur.

Core Capabilities

AI-driven attack path correlation across identity, cloud, and critical systemsAdversary emulation aligned to real-world MITRE ATT&CK techniques TTPsReal-time validation of SIEM, XDR, and EDR detections and response workflowsDynamic feedback loops that continuously update rules, telemetry, and playbooksHuman-led oversight for threat modeling, risk acceptance, and executive reporting

By fusing traditionally siloed red team and blue team functions with AI enablement, Purple SOCaaS creates a continuously learning security program. When detection gaps are identified, rules, telemetry configurations, and response playbooks are refined continuously instead of waiting for scheduled review cycles.

When analysts engage, alerts are already enriched, correlated, and prioritized. Evidence is pre-assembled across identity, endpoint, network, and cloud telemetry, allowing security teams to shift focus from manual triage to higher-value decisions such as determining scope, assessing control weaknesses, and directing response actions.

Purple SOCaaS delivers measurable business outcomes, including:

Reduced Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR)Expanded detection coverage across high-risk attack vectorsReduced blast radius through continuous control validationStrengthened identity and privileged access controls based on proven adversary pathwaysBoard-level reporting tied to quantified exposure reduction over time

InfoSight’s Purple SOCaaS is delivered through a structured 30–60-day onboarding and launch program, followed by continuous validation cycles.

“Bad actors can operate at machine speed on a scale like never before, so organizations no longer have the luxury of reactive 8-5 security operations. Adversaries operate continuously, so defenses must too. Purple SOCaaS allows security teams to go on the offense and anticipate threats bases upon intent signals to stay ahead of modern threats. Attacks are running at machine speed so modern SOC operations must match the new pace. — Tom Garcia, President & CEO, InfoSight

InfoSight’s AI-Enabled Purple Team SOCaaS is available immediately for enterprise and mid-market organizations. Organizations can request an executive overview or technical brief by contacting InfoSight directly.

About InfoSight

InfoSight, Inc. is a cybersecurity services firm helping organizations reduce cyber risk across healthcare, financial services, manufacturing, energy, and government sectors. Founded in 1998, InfoSight delivers advanced security operations, risk management, and compliance solutions that help organizations strengthen defenses, reduce exposure, and protect critical systems and digital assets.

Media Contact:
Yendi Valdes
Marketing Director, InfoSight
Yendi.Valdes@infosightinc.com 
1-305-828-1003

View original content to download multimedia:https://www.prnewswire.com/news-releases/infosight-launches-ai-enabled-purple-team-socaas-machine-speed-defense-human-led-control-302771525.html

SOURCE InfoSight, Inc.

Continue Reading

Technology

Tuya Inc. to Hold Annual General Meeting on June 18, 2026

Published

on

By

SANTA CLARA, Calif., May 13, 2026 /PRNewswire/ — Tuya Inc. (“Tuya” or the “Company”) (NYSE: TUYA; HKEX: 2391), a global leading AI cloud platform service provider, today announced that it will hold an annual general meeting of the Company’s shareholders (the “AGM”) at 2:00 p.m. (Hong Kong time) on Thursday, June 18, 2026 at Huace Center, Building A, 3/F VVIP room, Xihu District, Hangzhou City, Zhejiang Province, 310012, China, for the purposes of considering and, if thought fit, passing each of the Proposed Resolutions as defined and set forth in the notice of the AGM (the “AGM Notice”). The AGM Notice and the form of proxy for the AGM are available on the Company’s website at ir.tuya.com. The board of directors of the Company fully supports the Proposed Resolutions and recommends that shareholders and holders of American depositary shares (“ADSs”) vote in favor of the Proposed Resolutions.

Holders of record of the Company’s ordinary shares as of the close of business on May 22, 2026 (Hong Kong time) are entitled to receive notice of, and to attend and vote at, the AGM or any adjournment or postponement thereof. Holders of record of ADSs as of the close of business on May 22, 2026 (New York time) who wish to exercise their voting rights for the ADSs underlying Class A ordinary shares must give voting instructions directly to The Bank of New York Mellon, the depositary of the ADSs, if ADSs are held directly by holders on the books and records of The Bank of New York Mellon or indirectly through a bank, brokerage or other securities intermediary if the ADSs are held by any of them on behalf of holders.

The Company has filed its annual report on Form 20-F, including its audited financial statements, for the fiscal year ended December 31, 2025, with the U.S. Securities and Exchange Commission (the “SEC”). The Company’s annual report on Form 20-F can be accessed on the Company’s website at ir.tuya.com and on the SEC’s website at http://www.sec.gov.

About Tuya Inc.

Tuya Inc. (NYSE: TUYA; HKEX: 2391) is a global leading AI cloud platform service provider with a mission to build an AI developer ecosystem and enable everything to be smart. Tuya has pioneered a purpose-built AI cloud platform with cloud and generative AI capabilities that delivers a full suite of offerings, including Platform-as-a-Service, or PaaS, AI application & others and Smart home & robot products for developers of smart device, commercial applications, and industries. Through its AI developer platform, Tuya has activated a vibrant global developer community of brands, OEMs, AI agents, system integrators and independent software vendors to collectively strive for smart solutions ecosystem embodying the principles of green and low-carbon, security, high efficiency, agility, and openness.

Investor Relations Contact

Tuya Inc.
Investor Relations
Email: ir@tuya.com

HL Strategy
Haiyan LI-LABBE
Email: hl@hl-strategy.com

Piacente Financial Communications
China Tel: +86-10-6508-0677
U.S. Tel: +1-212-481-2050
Email: tuya@thepiacentegroup.com

View original content:https://www.prnewswire.com/news-releases/tuya-inc-to-hold-annual-general-meeting-on-june-18-2026-302771184.html

SOURCE Tuya Inc.

Continue Reading

Trending