Mayhem Blog

Expert insights and tips on application security, API security, and other DevSecOps topics.

View All
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Why Non-Functional Testing is Equally Important to Functional Testing

Why Non-Functional Testing is Equally Important to Functional Testing

With functional testing, there’s a finite number of ways that a feature can be used. With non-functional testing there’s an infinite number of possibilities. Fuzz testing is an effective solution for addressing those non-functional testing challenges.
The Hacker Mind Podcast: Hunting The Next Heartbleed

The Hacker Mind Podcast: Hunting The Next Heartbleed

For two years Heartbleed was a zero-day in OpenSSL until fuzz testing exposed it. How many others are in the wild now? And how will we find the next one? In this episode I talk about how Heartbleed (CVE 2014-0160) was found and also interview Rauli Kaksonen.
Why Fuzzing Works

Why Fuzzing Works

Find out the fundamental reasons why fuzzing is so effective, and why it remains a useful part of a secure software development lifecycle.
The Hacker Mind Podcast: Bug Bounty Hunters

The Hacker Mind Podcast: Bug Bounty Hunters

You’ve probably heard of bug bounties. But did you know there’s an elite group of bug bounty hunters that travel the world? Meet Stok; he’s one of them. In this episode, Stok talks about his beginnings in enterprise security and his transition into the top tier of bug bounty hunters.
New Reporting Dashboard in Mayhem

New Reporting Dashboard in Mayhem

ForAllSecure, a pioneer in automated application security, announced today the continued innovation behind their flagship product Mayhem with the release of new reporting dashboards.
Your AST Guide for the Disenchanted: Part 6

Your AST Guide for the Disenchanted: Part 6

Learn why SCA and AFT are two ideal solutions for transforming your DevOps workflow to a DevSecOp workflow.
The Hacker Mind Podcast: Hacking Voting Systems

The Hacker Mind Podcast: Hacking Voting Systems

While digital voting systems today are more secure today, what about the larger ecosystem, starting from the moment you register until your vote is counted? Who’s keeping those systems secure? In this episode of The Hacker Mind, Dr. Jared DeMott of VDA Labs talks about his work securing voter registration.
Your AST Guide for the Disenchanted: Part 5

Your AST Guide for the Disenchanted: Part 5

In today’s post, we’ll focus on how fuzz testing can help you address those unknown vulnerabilities.
The Hacker Mind Podcast: Hacking the Chrome Sandbox

The Hacker Mind Podcast: Hacking the Chrome Sandbox

No matter how strong we build our browsers that does not prevent hackers from trying to break new things. In this episode, a security researcher explains how he successfully escaped the Chrome sandbox, and how bug bounties are perhaps a good thing resulting in better security for us all.

Fancy some inbox Mayhem?

Subscribe to our monthly newsletter for expert insights and news on DevSecOps topics, plus Mayhem tips and tutorials.

By subscribing, you're agreeing to our website terms and privacy policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.