CFOtech US - Technology news for CFOs & financial decision-makers

AppSec stories - Page 4

Peter

The security challenges in AI-assisted software development

Last month
#
digital transformation
#
application security
#
devsecops
As AI tools spread through software teams, rising security flaws and shadow AI use are forcing leaders to tighten guardrails fast.
Software supply chain security python java js ai circuits lock

Chainguard extends secure libraries to Python, Java, JS

Fri, 27th Feb 2026
#
application security
#
devsecops
#
supply chain
Chainguard expands its rebuilt-from-source Libraries to Python, Java and JavaScript, targeting malware risks in AI-driven software supply chains.
Story 300075

OpenClaw AI assistant surge sparks major security fears

Fri, 27th Feb 2026
#
malware
#
phishing
#
application security
A rapid surge in OpenClaw AI assistant use has left tens of thousands of exposed systems and a trail of hijacked tools and malicious add-ons.
Ian steward

GitLab expands MSP partner push for agentic AI control

Fri, 27th Feb 2026
#
data protection
#
digital transformation
#
hyperscale
GitLab expands its MSP partner programme to deliver agentic AI-powered DevSecOps as a managed service with strict data sovereignty controls.
Yadi narayana 01

Datadog flags rising DevSecOps risk from ageing code

Fri, 27th Feb 2026
#
devops
#
siem
#
application security
Datadog warns 87% of organisations run software with exploitable flaws as ageing code, fast releases and automation amplify DevSecOps risk.
Moody legacy code wall crumbling with bugs and stressed engineers

Security debt surges as legacy vulnerabilities pile up

Thu, 26th Feb 2026
#
data protection
#
devops
#
application security
Security debt hits 82% of organisations as legacy flaws linger over a year, with third-party code driving most critical vulnerabilities.
Cio nighttime office ai cyber attack warning screens digital storm

CIOs brace for AI-led cyber attacks but feel unready

Thu, 26th Feb 2026
#
digital transformation
#
cloud security
#
phishing
Most CIOs expect AI-driven cyber attacks within a year, but only a third feel prepared, exposing a widening gap in cyber resilience.
Cloudy asia pacific skyline ai data streams cyber risk art

AI, cloud adoption driving new surge in cyber exposure

Wed, 25th Feb 2026
#
data protection
#
digital transformation
#
pam
Rapid AI and cloud adoption is fuelling a new wave of cyber risk, as Tenable warns of exposed software supply chains and “ghost” identities.
Secure dev workstation multi monitors code warnings shield icon

Anthropic unveils Claude Code Security to scan codebases

Wed, 25th Feb 2026
#
devops
#
cloud security
#
application security
Anthropic unveils Claude Code Security, an AI tool that scans codebases for complex bugs, verifies risks and suggests patches for developers.
Ai cloud puzzle shields dark gaps leaking data hidden keys

Tenable warns of widening AI exposure gap in cloud

Mon, 23rd Feb 2026
#
malware
#
digital transformation
#
public cloud
Tenable warns businesses that rapid AI and cloud adoption is creating an invisible exposure gap as identity and supply chain risks surge.
Glowing secure data hub with network of open source package cubes

ActiveState unveils 79m-strong secure open source catalogue

Fri, 20th Feb 2026
#
devops
#
digital transformation
#
application security
ActiveState launches a 79m-component secure open source catalogue to centralise software supply chains and cut enterprise vulnerability risk.
Tangled digital network streamlining into central cyber shield

Brinqa unveils AI agents to streamline cyber risk data

Fri, 20th Feb 2026
#
devops
#
digital transformation
#
cloud security
Brinqa has rolled out AI agents to infer asset owners and deduplicate findings, aiming to cut cyber risk noise in sprawling IT estates.
Software engineer dual monitors security warnings cloud office scene

Checkmarx brings IDE-native security checks to Kiro

Thu, 19th Feb 2026
#
cloud security
#
application security
#
socs
Checkmarx adds IDE-native security checks to AI-focused Kiro, aiming to catch vulnerabilities earlier and cut security rework for teams.
Untitled design  67

Vehere strengthens North America sales with senior hires

Thu, 19th Feb 2026
#
firewalls
#
smart cities
#
digital transformation
Vehere boosts North America cyber sales push with senior hires Glen Hlavsa and Ali Abughannam to target enterprise NDR demand.
Untitled design  68

DryRun Security adds Andrew Peterson to drive AI shift

Thu, 19th Feb 2026
#
firewalls
#
application security
#
devsecops
DryRun Security appoints Signal Sciences Co-founder Andrew Peterson to its board to steer its AI-native code security push.
Cinematic soc night ai alert dashboards hidden apps control

Okta unveils tools to detect & govern shadow AI risks

Fri, 13th Feb 2026
#
pam
#
cloud security
#
application security
Okta launches Agent Discovery to uncover and rein in shadow AI agents, mapping risky app access and tightening identity-based controls.
Cinematic ai security engineer in glass soc with robotic arms

Backslash raises USD $19m to secure AI 'vibe coding'

Fri, 13th Feb 2026
#
manufacturing
#
digital transformation
#
pam
Backslash raises USD $19m to secure emerging AI 'vibe coding' workflows as autonomous agents reshape how enterprise software is built.
Cicd pipeline dark code scanned quarantined cloud security

CodeHunter pushes behavioural malware checks upstream

Thu, 12th Feb 2026
#
hybrid cloud
#
cloud security
#
application security
CodeHunter extends its behavioural malware analysis into CI/CD pipelines, targeting risky software artefacts before they reach production.
Secure cloud database stack with automatic pii data masking

Aerospike embeds default data masking in Database 8

Wed, 11th Feb 2026
#
data protection
#
application security
#
partner programmes
Aerospike Database 8 now embeds default dynamic data masking, tightening PII protection while easing compliance and operational overhead.
Uk datacenter night ultradns ddos botnet attack red alert

DigiCert sees record UltraDNS DDoS surge in December 2025

Fri, 6th Feb 2026
#
firewalls
#
network security
#
application security
DigiCert warns UltraDNS DDoS attacks spiked to record levels in December 2025, driven by massive Aisuru and Kimwolf botnets.