AppSec stories
A flaw in a Microsoft GitHub workflow could let attackers run unauthorised code and steal repository secrets, Tenable said.
Ransomware pressure on US firms is intensifying debate over whether broader AI hacking tools will help defenders or aid criminals.
The Belfast-based software firm will use fresh capital to expand after strong growth, as AI coding tools heighten software supply chain risks.
Customers gain broader visibility into AI risks as Wiz adds cloud, edge and coding-tool coverage, with Red Agent now in public preview.
Boards face mounting pressure to fix AI-found code flaws faster, as CrowdStrike and partners launch a service to rank exploit risks.
Most firms are still flying blind on AI-generated code, even as 89% say they can secure it and 86% have already adopted it.
Hundreds of packages could have exposed API keys and logins after Claude Code saved approved commands in a file npm may publish by default.
Enterprises using autonomous AI agents could get tighter controls as the tie-up adds governance and live monitoring to Google Cloud deployments.
Security teams are struggling to review surging AI-generated code, with 62% saying the workload is getting harder to manage.
AI-driven attacks are pushing firms to hide systems from the public internet rather than rely on patching flaws after discovery.
Rising AI-generated vulnerability reports are leaving security teams with record backlogs and only hours to judge which flaws hackers can exploit.
AI coding agents are increasing supply chain risk, prompting new controls to verify third-party dependencies before they reach production.
A critical flaw in a widely used Microsoft code-sample repository could have let attackers steal secrets and run code through GitHub issues.
Boards are being pressed to abandon periodic patching as AI models can now uncover and chain software flaws faster than human teams can respond.
The framework is designed to expose hidden risks in production AI systems that can be missed by conventional one-off tests.
Mobile API calls can now be checked against app, device and session identity before access is granted, aiming to curb bot abuse and takeover attempts.
The Tel Aviv startup says enterprises need runtime controls as AI agents take on more privileged tasks across core business systems.
Rising use of AI assistants is making software harder to understand, prompting teams to revive stricter testing, controls and oversight.
Payment failures now surface in seconds for Modulus Labs after it unified monitoring and security, cutting resolution time by more than 40 per cent.
More than 500 senior leaders will gather in Melbourne next July as cyber risk, AI and resilience pressures push security teams to align.