LinuxSecurity.com: Count vulnerabilities as defects. Programmers understand that for sure. Of course, you can't leave it all on them, because secure code development is not exactly taught in school (even today unfortunately), so go out and get them some training.
