DZone
Thanks for visiting DZone today,
Edit Profile
  • Manage Email Subscriptions
  • How to Post to DZone
  • Article Submission Guidelines
Sign Out View Profile
  • Post an Article
  • Manage My Drafts
Over 2 million developers have joined DZone.
Log In / Join
Refcards Trend Reports
Events Video Library
Refcards
Trend Reports

Events

View Events Video Library
Core Badge
Avatar

Apostolos Giannakidis

DZone Core CORE

Product Security at Microsoft

Dublin, IE

Joined Dec 2016

Stats

Reputation: 2623
Pageviews: 145.8K
Articles: 9
Comments: 1

Expertise

Security Expertise Icon

Security

  • Articles
  • Refcards
  • Trend Reports
  • Comments

Articles

article thumbnail
Why AI Forces a Rethink of Everything We Know About Software Security
AI-driven development expands attack surfaces; this article shows how continuous security, zero trust, and runtime enforcement scale DevSecOps in AI pipelines.
May 7, 2026
· 2,720 Views · 1 Like
article thumbnail
How AI Is Rewriting the Rules of Software Security: Machine-Speed Delivery, Shifting Risk, and New Control Points
AI-driven development expands attack surfaces; this article shows how continuous security, zero trust, and runtime enforcement scale DevSecOps in AI pipelines
April 27, 2026
· 2,331 Views · 1 Like
article thumbnail
Software Supply Chain Security Regulations From a DevSecOps Perspective
This article examines how new regulations demand automated SBOMs and DevSecOps automation to secure software supply chains and ensure compliance.
July 21, 2025
· 2,953 Views · 1 Like
article thumbnail
Demystifying SAST, DAST, IAST, and RASP: A Comparative Guide
In this comparative guide, explore the inner workings of the essential security testing tools driving the shift-left security movement.
December 15, 2023
· 8,405 Views · 4 Likes
article thumbnail
Improve Microservices Security by Applying Zero-Trust Principles
Discover how the zero-trust principles can be applied in a microservices environment and what security controls should be implemented on the back end.
December 18, 2022
· 10,793 Views · 8 Likes
article thumbnail
Guidance on Oracle July 2018 Critical Patch Update
100 percent of the Java SE flaws in the Oracle July 2018 Critical Patch Update (CPU) can be exploited remotely. Learn more below.
July 20, 2018
· 6,787 Views · 2 Likes
article thumbnail
Oracle WebLogic RCE Deserialization Vulnerability (CVE-2018-2628)
Oracle recently released its critical patch update (CPU) for the quarter. Read on to get a security experts view on the vulnerabilities included.
May 3, 2018
· 13,850 Views · 2 Likes
article thumbnail
A First Look Into Java's New Serialization Filtering
Serialization Filtering is the minimum that Oracle could provide in order to stop being blamed for not doing anything about the critical Deserialization attacks. It is a first step in the right direction but it does not completely solve the problem and is not suitable for enterprise production environments.
January 20, 2017
· 14,599 Views · 4 Likes
article thumbnail
A Revolutionary Solution to Java Deserialization Attacks
This article will provide background on the deserialization vulnerability and describe the limitations of the existing mitigation techniques.
Updated January 18, 2017
· 28,746 Views · 11 Likes

Refcards

Refcard #399

Platform Engineering Essentials

Platform Engineering Essentials

Refcard #397

Secrets Management Core Practices

Secrets Management Core Practices

Refcard #341

Identity and Access Management

Identity and Access Management

Refcard #388

Threat Modeling Core Practices

Threat Modeling Core Practices

Trend Reports

Trend Report

Security by Design

Security teams are dealing with faster release cycles, increased automation across CI/CD pipelines, a widening attack surface, and new risks introduced by AI-assisted development. As organizations ship more code and rely heavily on open-source and third-party services, security can no longer live at the end of the pipeline. It must shift to a model that is enforced continuously — built into architectures, workflows, and day-to-day decisions — with controls that scale across teams and systems rather than relying on one-off reviews.This report examines how teams are responding to that shift, from AI-powered threat detection to identity-first and zero-trust models for supply chain hardening, quantum-safe encryption, and SBOM adoption and strategies. It also explores how organizations are automating governance across build and deployment systems, and what changes when AI agents begin participating directly in DevSecOps workflows. Leaders and practitioners alike will gain a grounded view of what is working today, what is emerging next, and what security-first software delivery looks like in practice in 2026.

Security by Design

Trend Report

Software Supply Chain Security

Gone are the days of fragmented security checkpoints and analyzing small pieces of the larger software security puzzle. Today, we are managing our systems for security end to end. Thanks to this shift, software teams have access to a more holistic view — a "full-picture moment" — of our entire software security environment. In the house that DevSecOps built, software supply chains are on the rise as security continues to flourish and evolve across modern software systems. Through the increase of zero-trust architecture and AI-driven threat protection strategies, our security systems are more intelligent and resilient than ever before. DZone's Software Supply Chain Security Trend Report unpacks everything within the software supply chain, every touchpoint and security decision, via its most critical parts. Topics covered include AI-powered security, maximizing ROI when it comes to securing supply chains, regulations from a DevSecOps perspective, a dive into SBOMs, and more.Now, more than ever, is the time to strengthen resilience and enhance your organization's software supply chains.

Software Supply Chain Security

Trend Report

Developer Experience

With tech stacks becoming increasingly diverse and AI and automation continuing to take over everyday tasks and manual workflows, the tech industry at large is experiencing a heightened demand to support engineering teams. As a result, the developer experience is changing faster than organizations can consciously maintain.We can no longer rely on DevOps practices or tooling alone — there is even greater power recognized in improving workflows, investing in infrastructure, and advocating for developers' needs. This nuanced approach brings developer experience to the forefront, where devs can begin to regain control over their software systems, teams, and processes.We are happy to introduce DZone's first-ever Developer Experience Trend Report, which assesses where the developer experience stands today, including team productivity, process satisfaction, infrastructure, and platform engineering. Taking all perspectives, technologies, and methodologies into account, we share our research and industry experts' perspectives on what it means to effectively advocate for developers while simultaneously balancing quality and efficiency. Come along with us as we explore this exciting chapter in developer culture.

Developer Experience

Trend Report

Enterprise Security

This year has observed a rise in the sophistication and nuance of approaches to security that far surpass the years prior, with software supply chains being at the top of that list. Each year, DZone investigates the state of application security, and our global developer community is seeing both more automation and solutions for data protection and threat detection as well as a more common security-forward mindset that seeks to understand the Why.In our 2023 Enterprise Security Trend Report, we dive deeper into the greatest advantages and threats to application security today, including the role of software supply chains, infrastructure security, threat detection, automation and AI, and DevSecOps. Featured in this report are insights from our original research and related articles written by members of the DZone Community — read on to learn more!

Enterprise Security

Trend Report

Enterprise Application Security

Data breaches, ransomware attacks, and other security vulnerabilities have become the norm in recent years. Hackers have become shrewder. And with that, development teams bear the responsibility of ensuring that all stages of the SDLC have strong security.DZone's 2022 Trend Report, Enterprise Application Security: Building Secure and Resilient Applications, focuses on key factors of security practices including supply chain security, principles of zero-trust security, how to secure mobile applications, common DevSecOps practices, and what to do after your organization experiences a security breach. Our research dives into sentiments on perceived application security risks, development techniques for securing applications, and where the role of security lies for teams within today's organizational structures. The goal of this Trend Report is to equip developers with the tools, best practices, and advice they need to help implement security at every stage of the SDLC.

Enterprise Application Security

Comments

Solution vs Software Architecture

Aug 09, 2017 · David Shilman

Very good points! I completely agree.

User has been successfully modified

Failed to modify user

  • RSS
  • X
  • Facebook

ABOUT US

  • About DZone
  • Support and feedback
  • Community research

ADVERTISE

  • Advertise with DZone

CONTRIBUTE ON DZONE

  • Article Submission Guidelines
  • Become a Contributor
  • Core Program
  • Visit the Writers' Zone

LEGAL

  • Terms of Service
  • Privacy Policy

CONTACT US

  • 3343 Perimeter Hill Drive
  • Suite 215
  • Nashville, TN 37211
  • [email protected]

Let's be friends:

  • RSS
  • X
  • Facebook