Tomcat TLSv1.3 cipher configuration
A Tomcat update splits TLSv1.3 cipher configuration into a new attribute, silently dropping your Spring Boot cipher restrictions. Here's how …

Joe Kuhel
3,516 viewsA Tomcat update splits TLSv1.3 cipher configuration into a new attribute, silently dropping your Spring Boot cipher restrictions. Here's how …

Steve Poole
2,025 viewsfirst, a word about ecosystems Before we dive into Shai-Hulud, before we label it “sophisticated” or “advanced” or “next generation,” we …

Steve Poole
2,864 viewsThis is a follow-on to the article The Real Mechanics of Vulnerabilities in an Upstream/Downstream, Topsy-Turvy EOL World. What you'll learn …

Jonathan Vila
4,324 viewsSecure Java projects with SonarQube AI Code Assurance. Use AI CodeFix and the MCP Server to auto-remediate technical debt instantly.

Michal Maléř
4,138 viewsThis article explores how Quarkus can help organizations reduce costs, streamline development, and modernize their Java applications for …

Michal Maléř
4,634 viewsPublic clouds such as AWS, Microsoft Azure, and Google Cloud, and platforms like Red Hat OpenShift, favor services that start fast and stay …

Jonathan Vila
3,772 viewsYour code is safe, but are your dependencies? Part 3 reveals how SonarQube Advanced Security detects hidden CVEs, manages licenses, and …

Steve Poole
3,168 viewsIn this article you’ll learn Why CVEs record that a vulnerability exists, not that a usable fix exists How vulnerabilities are often …

Jonathan Vila
13,585 viewsAI MCP is awesome to connect our Agents to real time data, but also open a dangerous door to security threats
Anthony Layton
2,306 viewsWhen it comes to Java security, the first thing that comes to mind should be the JVM. If you’re relying on outdated, unpatched, or …