AppSec stories
Endor Labs launches AURI to secure AI-driven coding
Last week
#
digital transformation
#
application security
#
devsecops
Endor Labs unveils AURI, a security intelligence platform embedding reachability-led checks into AI coding assistants and CI/CD pipelines.
Terra Security gains first AWS nod for AI threat tests
Last week
#
network infrastructure
#
devops
#
hyperscale
Terra Security becomes first AWS partner validated for Autonomous Security Validation, as AI-driven continuous threat testing gains pace.
Survey shows pentesters favour PTaaS over bug bounties
Last week
#
devops
#
application security
#
devsecops
New research from Cobalt finds 98% of surveyed pentesters prefer PTaaS to bug bounties and show almost no faith in AI-only security scanning.
JFrog flags 13 critical CI/CD flaws in GitHub workflows
Last week
#
siem
#
fintech
#
application security
JFrog warns 13 GitHub CI/CD workflow flaws, mostly critical, could let attackers hijack pipelines and steal secrets at scale.
Claude Code flaws expose new risks in AI dev tools
Last week
#
devops
#
cloud security
#
application security
Claude Code flaws found by Check Point could let malicious repos run code and grab API keys before developers confirm a project is trusted.
Endor Labs unveils AURI to secure AI-driven coding
Last week
#
devops
#
application security
#
devsecops
Endor Labs has launched AURI, an AI-aware security platform that embeds continuous code checks directly into agent-driven development workflows.
LevelBlue & Tenable expand exposure tools for partners
Last week
#
devops
#
digital transformation
#
cloud security
LevelBlue debuts Exposure Management for Partners with Tenable, giving MSSPs and MSPs tiered, unified exposure and risk visibility tools.
LevelBlue & Tenable launch exposure service for MSPs
Last week
#
digital transformation
#
cloud security
#
iot security
LevelBlue and Tenable have teamed up to launch a tiered exposure management service giving MSPs continuous, risk-based visibility.
Manifest flags AI readiness gap between execs & AppSec
Last week
#
digital transformation
#
cloud security
#
application security
Manifest research reveals executives overestimate AI security readiness, as AppSec teams warn of unmanaged tools, blind spots and rising risk.
The security challenges in AI-assisted software development
Last week
#
digital transformation
#
application security
#
devsecops
As AI tools spread through software teams, rising security flaws and shadow AI use are forcing leaders to tighten guardrails fast.
Chainguard extends secure libraries to Python, Java, JS
Last month
#
application security
#
devsecops
#
supply chain
Chainguard expands its rebuilt-from-source Libraries to Python, Java and JavaScript, targeting malware risks in AI-driven software supply chains.
OpenClaw AI assistant surge sparks major security fears
Last month
#
malware
#
phishing
#
application security
A rapid surge in OpenClaw AI assistant use has left tens of thousands of exposed systems and a trail of hijacked tools and malicious add-ons.
GitLab expands MSP partner push for agentic AI control
Last month
#
data protection
#
digital transformation
#
hyperscale
GitLab expands its MSP partner programme to deliver agentic AI-powered DevSecOps as a managed service with strict data sovereignty controls.
Datadog flags rising DevSecOps risk from ageing code
Last month
#
devops
#
siem
#
application security
Datadog warns 87% of organisations run software with exploitable flaws as ageing code, fast releases and automation amplify DevSecOps risk.
Security debt surges as legacy vulnerabilities pile up
Last month
#
data protection
#
devops
#
application security
Security debt hits 82% of organisations as legacy flaws linger over a year, with third-party code driving most critical vulnerabilities.
CIOs brace for AI-led cyber attacks but feel unready
Last month
#
digital transformation
#
cloud security
#
phishing
Most CIOs expect AI-driven cyber attacks within a year, but only a third feel prepared, exposing a widening gap in cyber resilience.
AI, cloud adoption driving new surge in cyber exposure
Last month
#
data protection
#
digital transformation
#
pam
Rapid AI and cloud adoption is fuelling a new wave of cyber risk, as Tenable warns of exposed software supply chains and “ghost” identities.
Anthropic unveils Claude Code Security to scan codebases
Last month
#
devops
#
cloud security
#
application security
Anthropic unveils Claude Code Security, an AI tool that scans codebases for complex bugs, verifies risks and suggests patches for developers.
Tenable warns of widening AI exposure gap in cloud
Last month
#
malware
#
digital transformation
#
public cloud
Tenable warns businesses that rapid AI and cloud adoption is creating an invisible exposure gap as identity and supply chain risks surge.
ActiveState unveils 79m-strong secure open source catalogue
Last month
#
devops
#
digital transformation
#
application security
ActiveState launches a 79m-component secure open source catalogue to centralise software supply chains and cut enterprise vulnerability risk.