AppSec stories
Continuous attack testing aims to help customers spot exploitable gaps before criminals do, including misconfigurations hiding outside core systems.
Growing AI use in coding is widening software risk, forcing security leaders to match training and controls to each adoption stage.
By focusing on evidence and small reversible changes, loop engineering could curb costly AI coding mistakes before they reach production.
Enterprise security teams gain a new AI-assisted way to spot exploitable code flaws, as IBM widens its cyber work with OpenAI.
The recognition comes as firms scramble to secure software pipelines, open-source code and AI assets against rising supply chain attacks.
The move aims to help defenders turn faster vulnerability discovery into working fixes, as OpenAI broadens access to its cyber tools and partners.
A single compromised laptop can expose thousands of live keys, according to GitGuardian's early field tests, as attacks shift to developer machines.
Public release of the Mini Shai-Hulud code means copycat attacks can now hit developers, CI/CD systems and open-source supply chains.
The move puts Broadridge among firms using frontier AI to harden financial software, where breaches can disrupt trading and client communications.
Enterprise teams using AI coding tools may face higher technical debt, security gaps and costs, according to new SIG research.
Regulators may soon demand proof of who did what as AI agents start opening merge requests in heavily audited development pipelines.
Enterprise teams are getting a single control plane to track agent sprawl, tighten permissions and curb AI spending as autonomous systems spread.
Government agencies will gain wider access to application security tools as the partnership places Checkmarx products on Carahsoft's procurement channels.
Regulated firms can now scan code for flaws without sending sensitive data to external AI services, as AISLE targets private deployments.
With AI speeding up attacks, 53% of security leaders say point-in-time tests are already outdated by the time reports land.
Government buyers will gain wider access to Checkmarx tools as Carahsoft opens procurement routes through reseller networks and federal contracts.
The deal gives customers red teaming and runtime protection for AI systems as enterprises rush to secure models and autonomous agents.
Exploited software flaws are now overtaking stolen passwords as the main breach route, sharpening pressure on security teams to patch faster.
The tool has already blocked more than 52,000 risky npm packages as supply chain attacks continue to hit software teams.
Runtime behaviour, not login checks, is now seen as the key control as businesses put AI agents into live systems and data.