Explore Resources on Application and Cloud Security

Discover the latest events, conferences, research from the Phoenix team on application and cloud security.
Download all the whitepaeprs data sheet and conference material.
Time to build better Application Security and Cloud Security programmes.

White Papers

SLA are dead long live SLA – Data driven approach on Vulnerabilities

Vulnerability Management at scale & the power of context based prioritiz…

Application & Cloud security program

Content Risk and prioritization.
Do’s and don’ts

Data Sheet and Reference materials




Getting started video tour

From our Blog

Explore ASPM’s role in modern application security, offering a panoramic view that extends beyond code vulnerabilities. This guide demystifies concepts like traceability, reachability analysis, and asset lineage, pivotal for securing digital assets. Learn how ASPM empowers organizations with actionable insights for precise vulnerability management. #Cybersecurity #ASPM #ApplicationSecurity
Francesco Cipollone
Explore the transformative role of ASPM in cybersecurity. Uncover how Application Security Posture Management aligns business and security objectives for effective vulnerability management and risk reduction. Discover Phoenix Security’s innovative approach to tackling the staggering challenge of CVEs with a strategic focus on prioritization. #ASPM #Cybersecurity #VulnerabilityManagement
Francesco Cipollone
Explore the critical insights into the latest container security vulnerabilities named leaky vessels, including CVE-2024-21626, CVE-2024-23651, CVE-2024-23653, and CVE-2024-23652, BuildKit flaws, with our comprehensive guide on mitigation strategies, best practices for application security, and tips for robust vulnerability management in Docker and Kubernetes environments. Stay ahead in securing your container deployments against potential threats with ASPM help
Francesco Cipollone
The Cloud Security and AppSec teams at Phoenix Security are pleased to bring you another set of new Phoenix Security features and improvements for vulnerability management across application and cloud security engines. This release builds on top of previous releases with key additions and progress across multiple areas of the platform. Application Security Posture Management – Teams Dashboard – Filter Assets and Vulnerabilities by Team – Link Teams to Components and Services – Triage Findings by Deployment Environment – Improved Threat Intelligence with Ransomware Alerts Asset and Vulnerability Management – New “Delta” Import Strategy – Auto-populate “location” for CSV Imports – Easy Triage of Duplicate Findings – Improved Tagging Capabilities – Set Criticality for Components and Services – Manual Closing of Vulnerabilities Integrations – Support for Custom Fields in ADO Tickets – Improved Asset Aggregation for Qualys Infra – Expanded Phoenix REST API Other Improvements – Remember User Choices – Additional Filtering in the Navigation Graph – Table Column Resizing – Improve the Risk Breakdown column – Remove Limits for Multi-selection in Lists
Alfonso Eusebio
Discover the critical cybersecurity trends and vulnerability management insights from our latest analysis of CWE categories in 2022 and 2023. Understand how software and data integrity failures, memory buffer errors, and injection vulnerabilities are shaping the cybersecurity landscape. Learn about the persistent challenges in resource management, pathname traversal, and access controls, and see where improvements are being made. Dive into the data to bolster your application security and protect against emerging threats.
Francesco Cipollone
CVE-2023-50164 Now exploited! CVE-2023-50164 in Apache Struts 2. Explore our comprehensive guide on Apache Struts, a crucial tool in application security. Learn about its impact, widespread usage, and effective strategies for preventing remote code execution vulnerabilities. Discover how ASPM enhances cybersecurity by tracing and securing Struts deployments in your organization.
Francesco Cipollone
Fixing CVE-2023-50164 in Apache Struts2. Explore our comprehensive guide on Apache Struts, a crucial tool in application security. Learn about its impact, widespread usage, and effective strategies for preventing remote code execution vulnerabilities. Discover how ASPM enhances cybersecurity by tracing and securing Struts deployments in your organization.
Francesco Cipollone

Community Podcast on Application Security & Cloud Security

Discover innovative strategies to overcome the cybersecurity talent shortage in this insightful episode with Jitendra Arora, CISO at Deloitte. Dive deep into discussions on talent sourcing, nurturing diverse skills, fostering positive work culture, and self-care in the high-stress field of cybersecurity. Featuring expert insights and practical advice, this episode is a must-watch for cybersecurity professionals and enthusiasts. #CybersecurityInsights

Quick Start

Start doing what matters today

Listen to the latest Phoenix Security podcast

Get Started with Phoenix Security

Read the latest Phoenix Security news

Read the latest Blogs

Discover our events

Explore the talks

Discover Whitepapers

Read the latest News

Discover video resources

Get in control

More than 1000 Users and 350 Organizations trust us

Jeevan Singh

Founder of Manicode Security

Jeevan Singh is the Director of Security Engineering at Rippling, with a background spanning various Engineering and Security leadership roles over the course of his career. He’s dedicated to the integration of security practices into software development, working to create a security-aware culture within organizations and imparting security best practices to the team.
In his role, Jeevan handles a range of tasks, from architecting security solutions to collaborating with Engineering Leadership to address security vulnerabilities at scale and embed security into the fabric of the organization.

James Berthoty

Founder of Latio Tech

James Berthoty has over ten years of experience across product and security domains. He founded Latio Tech to help companies find the right security tools for their needs without vendor bias.

Christophe Parisel

Senior Cloud Security Architect

Senior Cloud Security Architect

Chris Romeo

Security Journey

Chris Romeo is a leading voice and thinker in application security, threat modeling, and security champions and the CEO of Devici and General Partner at Kerr Ventures. Chris hosts the award-winning “Application Security Podcast,” “The Security Table,” and “The Threat Modeling Podcast” and is a highly rated industry speaker and trainer, featured at the RSA Conference, the AppSec Village @ DefCon, OWASP Global AppSec, ISC2 Security Congress, InfoSec World and All Day DevOps. Chris founded Security Journey, a security education company, leading to an exit in 2022. Chris was the Chief Security Advocate at Cisco, spreading security knowledge through education and champion programs. Chris has twenty-six years of security experience, holding positions across the gamut, including application security, security engineering, incident response, and various Executive roles. Chris holds the CISSP and CSSLP certifications.

Jim Manico

Founder of Manicode Security

Jim Manico is the founder of Manicode Security, where he trains software developers on secure coding and security engineering. Jim is also the founder of Brakeman Security, Inc. and an investor/advisor for Signal Sciences. He is the author of Iron-Clad Java: Building Secure Web Applications (McGraw-Hill), a frequent speaker on secure software practices, and a member of the JavaOne Rockstar speaker community. Jim is also a volunteer for and former board member of the OWASP foundation.

Join our Mailing list!

Get all the latest news, exclusive deals, and feature updates.