AppSec stories
The new tools aim to cut the gap between finding a flaw and fixing it from weeks to hours as attacks accelerate.
Organisations using Microsoft automation can now keep credentials out of scripts, reducing the risk of exposed secrets in cloud workflows.
In two days, the system uncovered more than 100 critical bugs in stolen code repositories, outpacing manual review and aiding incident response.
Unauthorised access could let attackers send arbitrary commands to spacecraft and instruments via NASA's AIT-GUI console, now fixed in version 2.5.2.
Security teams are drowning in AI-generated bug reports, and 11 early users are already testing a system that filters the noise.
Verified access to Anthropic's Claude models should sharpen ArmorCode's exploitability scoring as security teams race to cut alert noise.
Security teams should treat AI patching with caution after 53.9% of 6,080 model-generated fixes failed or introduced new flaws.
Hong Kong saw a record 15,877 cyber incidents in 2025 as AI speeds attacks and shortens the window to exploit software flaws.
Prompt-injection attacks and data leaks are the main risks as businesses connect Copilot and Gemini to email, files and internal tools.
Defenders will test prompt-injection tactics against AI agents as CrowdStrike and AWS offer USD $100,000 in prizes for a virtual red-team contest.
The tie-up aims to help security teams turn validated AI findings into ranked fixes before vulnerabilities pile up and attackers move first.
Stolen credentials can become an operational foothold within hours, leaving annual assessments too slow to catch the real attack paths.
UK security leaders are warning that AI-generated code is outpacing controls, with a quarter already seeing incidents from flaws it introduced.
Accenture's double win underlines Wiz's push to deepen its Australian channel as customers seek help securing cloud and AI projects.
Cybersecurity experts warn single-person approvals are now vulnerable after an AI agent used fabricated identities to slip malicious code past checks.
Smaller security teams can now access autonomous testing on demand, as the platform drops its minimum commitment and adopts consumption pricing.
Security teams can now track newly disclosed CVEs in live systems, as RapidFort expands its supply chain tools into production monitoring.
Security teams can now stop rogue enterprise AI agents in seconds as Straiker adds runtime controls to its wider testing platform.
The update aims to cut remediation costs and stop teams wasting time by re-analysing vulnerabilities without enough business context.
AWS customers can now buy Chainguard Libraries through Security Hub Extended, as open-source dependency attacks push firms to tighten supply chain checks.