The Ultimate Guide to Application Security
A curated Canadian edition of TechDay news, analysis, interviews, reviews, job moves, and related resources for Application Security.
What to know about Application Security
Application Security focuses on protecting software applications from vulnerabilities and cyber threats throughout their development and operational life cycles. This critical field addresses challenges such as runtime protection, secure coding practices, DevSecOps integration, API security, cloud-native environments, and mitigating attacks like DDoS, supply chain risks, and malicious bot traffic.
Exploring the latest stories in Application Security reveals how advancements like AI and automation are enhancing threat detection, vulnerability management, and developer workflows, while highlighting ongoing risks found in mobile apps, open source components, and cloud deployments. Readers can gain insights into best practices, emerging technologies, and strategies to safeguard applications against evolving cyber threats.
Whether you’re a developer, security professional, or business leader, staying informed about Application Security developments helps in building resilient software, maintaining compliance, and protecting user data in an increasingly complex digital landscape.
Canadian Application Security News
Regional stories with direct local relevance
Alberta uses Claude to scan 466 million lines of code
The province found hidden security flaws in public sector systems in hours, a task officials say could have taken a manual review 6.5 years.
eSentire launches Atlas Preempt for continuous testing
Continuous attack testing aims to help customers spot exploitable gaps before criminals do, including misconfigurations hiding outside core systems.
World Backup Day 2026: In the age of AI, what are you really backing up?
AI disruptions and cyberattacks are forcing organisations to back up models, prompts and knowledge bases, not just files.
Check Point launches Canada-only data region for WAF
Check Point debuts Canada-only WAF data region, promising full data residency, lower latency and AI-driven protection for local organisations.
Bell Cyber & Radware launch AI-driven cloud security
Bell Cyber and Radware have unveiled an AI-driven, fully managed cloud security service to shield apps, APIs and sites from automated attacks.
Analyst Insights
Research and market analysis connected to Application Security
Citrix adds MCP Gateway to NetScaler for AI traffic
Data Theorem launches AI security platform for apps
Gartner names Tenable leader in AI exposure assessment
Secure Code Warrior launches AI adoption model for CISOs
Checkmarx named leader in Gartner supply chain quadrant
Featured News
Humanoid robots, 0-day defence among Info-Tech trends for '27
Agentic AI, zero-day surge, sovereign cloud, and humanoid robots will define IT strategy in 2027, Info-Tech Research Group warns.
Exabeam: Ruthless efficiency can make agentic AI malicious
Behavioural analytics is becoming essential as AI agents can pursue tasks so efficiently that they may cause damage without any malicious intent.
Check Point Technologies: On vigilance, Mythos and beyond
AI-driven vulnerability scanning is forcing firms to rethink complacency as Check Point says existing defences still help against Mythos.
Exclusive: Reco COO on securing the AI inside your SaaS stack
Reco COO Zoe Hillenmeyer says enterprises typically underestimate their AI agent exposure by a factor of ten and that gap is widening.
Google Cloud CEO sets out enterprise AI agent plan
Enterprises will get one place to build, govern and run AI agents, as Google Cloud expands Gemini Enterprise across models, data and security.
Expert Columns
A strategic blueprint for governing AI-enabled software development
Why ERP is not just another platform you can rebuild with AI code
As agentic development accelerates, workflow auditability becomes a bottleneck
World Backup Day 2026: In the age of AI, what are you really backing up?
The evolving role of the CSO: From technical guardian to business strategist
Secure by default: Moving beyond secure by design
Why the next endpoint and SASE disruption will not come from a security vendor
The security challenges in AI-assisted software development
AI surge exposes cloud security gaps, report warns
Agentic AI double agents expose dangerous security gaps
Interviews
Interviews and video coverage from the networkRecent Application Security News
Cloudflare launches Precursor to spot bots in sessions
With automated traffic now overtaking human visits online, the tool is designed to catch bots that slip past login and checkout checks.
Google Cloud puts Cloud Run sandboxes into preview
Developers can now isolate AI-generated code and user scripts inside Cloud Run, reducing the risk of exposing credentials or host data.
NCC Group maps security gaps across AI coding agents
Weak default safeguards and uneven sandboxing could leave developers exposed to command execution before workspace trust is granted.
Google backs 33 cybersecurity startups in AI shift
New tools for governing AI agents are moving to the fore as Google picks 33 cybersecurity startups for its first cybersecurity forum cohort.
IBM & Red Hat launch Lightwell for open source fixes
Enterprises can now patch older open source software without disruptive upgrades, as IBM and Red Hat target stubborn vulnerability backlogs.
XBOW wins AWS application security competency status
The AWS badge could help XBOW win more enterprise deals as buyers seek continuous testing that shows which vulnerabilities are exploitable.
AI speeds coding but not enterprise software delivery
Enterprises risk slower returns from AI as manual approvals and release bottlenecks keep software lead times stuck at 30 to 45 days.
ManageEngine launches marketplace with 170 extensions
Enterprises can now add more tailored IT tools after the new Marketplace passed 170 extensions and 10,000 downloads worldwide.
NowSecure warns of AI oversight gap in mobile apps
Gaps in oversight leave most firms unable to see what AI is doing inside mobile apps, despite broad adoption and formal governance policies.
Ory unveils Agent DX for enterprise AI coding agents
Developers can now add authentication and access controls earlier in AI-built apps, as Ory's free plugins plug identity tools into coding agents.
AI-generated code is in production at 44.7% of firms
More than half of engineering teams are now using AI to write code, but weak oversight is leaving security, dependency and performance risks in production.
Dawnguard launches security platform & raises USD $6.3m
North American expansion is now being funded as the startup targets cloud risks introduced at the design stage, not after deployment.
LexisNexis & Promon team up on mobile fraud defence
Fraud teams will gain extra app-level signals as the firms combine mobile protection with identity intelligence to catch tampering and abuse.
Google Cloud uses AI agents to secure software lifecycle
Its internal security team says automated agents now speed vulnerability checks, patching and production monitoring as attacks intensify.
Reco launches agent security for enterprise AI risk
Enterprise security teams are being pushed to track what AI agents can access and do across apps, identities and workflows before data is exposed.
NCC Group joins OpenAI Daybreak cyber partner programme
The tie-up gives NCC Group early access to GPT-5.5-Cyber, as OpenAI seeks trusted testers for defensive uses of its cyber tools.
Dify flaws expose cross-tenant AI data, Zafran says
Users of Dify's cloud service could have had private chats and files exposed after Zafran Security disclosed four flaws in the AI platform.
F5 launches AI security platform, buys SurePath AI
Security teams are being offered new tools to track shadow AI and block prompt injection as enterprises rush to deploy agents and models.
Explainer: How loop engineering is changing coding
By focusing on evidence and small reversible changes, loop engineering could curb costly AI coding mistakes before they reach production.