Newsroom

Latest news

07/12/2024

GitLab Fixes Security Flaw That Lets Attackers Run Pipeline Jobs

Contrast Security CISO David Lindner said this vulnerability is something administrators need to take notice of, and heed GitLab’s advice to upgrade immediately.

“This is REALLY bad, as it effectively turns off access controls for running pipelines, which is the lifeblood of moving software from development to production,” Lindner wrote in an email. “This vulnerability could allow unauthorized users to execute pipeline jobs as any other user, which in turn could enable attackers to run malicious code, access sensitive data and compromise software integrity.”

Read more

07/12/2024

Unauthorized content alteration bug found in NSA platform

The U.S. National Security Agency's open-source SkillTree training platform on GitHub has been impacted by a medium severity cross-site request forgery vulnerability, tracked as CVE-2024-39326, which could be leveraged to facilitate unauthorized modifications of training content, SiliconAngle reports.

Read more

07/11/2024

GitLab patches 2nd critical pipeline vulnerability in last month

The critical vulnerabilities CVE-2024-6385 and CVE-2024-5655 could put developers’ projects at risk by enabling attackers to “run malicious code, access sensitive data and compromise software integrity,” Contrast Security CISO David Lindner told SC Media.

“This is REALLY bad, as it effectively turns off access controls for running pipelines, which is the lifeblood of moving software from development to production,” Lindner sai

Read more

Recent press releases

08/04/2025

Contrast ADR Marks One Year with Surging Growth, Expands Reach with New Developer and SecOps-Focused Integrations

One year after launch, Contrast ADR hits 40% adoption and adds GitHub Copilot and Sumo Logic integrations to boost runtime security and accelerate remediation.
Read more

06/09/2025

Contrast Introduces the First Unified Platform to See Application-Layer Attacks, Stop Breaches, and Remediate Vulnerabilities with AI

With its Northstar release, Contrast gives Development, AppSec, and SecOps a shared, real-time view of application-layer threats, pinpointing live vulnerabilities and enabling AI-powered remediation in minutes.

Read more

06/02/2025

Contrast Security strengthens channel-first strategy with promotion of award-winning executive Tracey Mead to Vice President of Global Alliances and Channels

Expanded role to accelerate global partner growth and fuel rising demand for Application Detection and Response 

Read more

Ready to see the Contrast Runtime Security Platform in action?

Try Contrast