AppSec stories
A free account could have let attackers alter Zapier-maintained packages and hijack logged-in users' browser sessions, researchers said.
The award underscores rising demand for software tools that spot structural risk as AI coding assistants flood enterprise systems with new code.
The move targets vulnerabilities in software used by large firms, as AI makes it easier to find and exploit flaws.
Security teams in Australia and New Zealand may soon triage flaws faster as TrendAI uses Claude Opus 4.8 to assess exploitability and impact.
The funding will help firms spot hidden flaws and backdoors in compiled code as AI-generated software and supplier risk raise security concerns.
Developers using open-source tools face heightened supply-chain risk after the botnet lost all four of its command channels.
The platform aims to help AI developers move beyond benchmark tests, as models struggle to tackle real-world vulnerabilities safely and reliably.
The round values the software supply chain security company at USD $1 billion as AI coding boosts the flow of third-party code into production.
The new integration keeps passwords out of prompts and repos, reducing the risk of leaks as AI coding agents move into production workflows.
Security teams can now assess network, web and AI weaknesses together as Terra Security broadens continuous validation to infrastructure.
Independent security checks are gaining urgency as fast-growing AI and software firms face rising scrutiny from customers, partners and regulators.
Exposed systems are becoming the main target, as Rapid7 says flaws were used in 38% of incidents and patch windows shrank to five days.
The release gives security teams and developers new controls for credentials, merge requests and supply chain oversight as AI use grows.
Members are backing tougher open source security as OpenSSF expands guidance on regulation, Python coding and AI-driven vulnerability tools.
Most enterprise access still sits outside formal controls, leaving AI agents and unmanaged accounts to widen security and compliance risks.
Businesses can now run Claude-powered agents in isolated Cloudflare sandboxes, with tighter controls for private data, audit trails and scaling.
Many firms lack visibility over AI-written software, raising maintainability and security risks as adoption of coding assistants accelerates.
The findings suggest AI-assisted bug hunting is edging closer to practical exploitation, raising the stakes for software teams racing to patch flaws.
Enterprises are testing only about 32% of their attack surface, leaving many assets outside regular security checks as threats grow faster.
A JFrog study says weak package and container defences are leaving Indian organisations exposed as AI use adds new checks for developers.