AppSec stories
It aims to cut alert fatigue by using runtime data to validate threats, prioritise real risks and guide fixes across cloud and AI systems.
Exposed systems are becoming the main target, as Rapid7 says flaws were used in 38% of incidents and patch windows shrank to five days.
The release gives security teams and developers new controls for credentials, merge requests and supply chain oversight as AI use grows.
Members are backing tougher open source security as OpenSSF expands guidance on regulation, Python coding and AI-driven vulnerability tools.
Most enterprise access still sits outside formal controls, leaving AI agents and unmanaged accounts to widen security and compliance risks.
Businesses can now run Claude-powered agents in isolated Cloudflare sandboxes, with tighter controls for private data, audit trails and scaling.
Many firms lack visibility over AI-written software, raising maintainability and security risks as adoption of coding assistants accelerates.
The findings suggest AI-assisted bug hunting is edging closer to practical exploitation, raising the stakes for software teams racing to patch flaws.
Enterprises are testing only about 32% of their attack surface, leaving many assets outside regular security checks as threats grow faster.
Security teams may cut backlogs as validated HackerOne flaws are mapped into Wiz, linking exploit evidence to cloud assets for faster prioritisation.
Security teams can now rank cloud flaws by exploitability and impact, as validated HackerOne reports feed directly into Wiz's risk graph.
Security teams under pressure to prove real exploitability can now test live production systems for attack paths rather than theoretical flaws.
Security teams face new risks from AI coding tools as Cycode adds controls for prompts, generated code and unauthorised model use.
Security teams face a broader threat as criminals and state-backed actors use generative AI to speed hacks, phishing and malware.
MSPs will gain a single platform for cloud threat detection as the deal widens WatchGuard's reach into identity and SaaS security.
Organisations using AI in software development will get training on secure coding and governance as vulnerabilities and data risks mount.
The move aims to widen security coverage as firms struggle to test expanding attack surfaces quickly enough.
It aims to cut wasted search time for coding agents after tests found most of their work was reading files rather than editing code.
A flaw in a widely watched Microsoft repository could have let attackers run code and steal secrets through GitHub Actions, Tenable said.
Organisations using AI-assisted development can now get specialist secure coding training as KnowBe4 expands its library for technical teams.