AppSec stories
A faulty token check let low-privilege users view other applicants' identities, payment details and Social Security numbers in a financial onboarding app.
AI tools are speeding routine checks, but hidden business logic flaws and context-specific risks still need human testers to spot them.
Centralised oversight for AI traffic should help firms cut prompt-injection and data-leakage risks as models shift into production.
Proofpoint says underground forums are advertising tools that use indirect prompt injection across emails, PDFs, calendar invites and web pages.
Governance features aim to help security teams prove AI controls to boards and regulators as shadow AI and agentic risks spread.
The cybersecurity group is widening its Americas push as it seeks more customers and partners for its AI-focused platform.
Security teams can now block risky AI prompts in real time as Reco expands its platform from visibility into browser-level enforcement.
Security teams can now block newly disclosed flaws in minutes, as Miggo's tool adds temporary protection while patches are still being deployed.
Critical vulnerability backlogs have swelled 29-fold, prompting a tool that sends fix plans into engineering systems and AI coding tools.
The hybrid system aims to help security teams spot serious flaws in AI-generated code faster, as production code becomes harder to review.
Downstream AI data leaks have more than doubled in a year, with connected services now returning unauthorised information to staff and agents.
Smaller firms face faster and costlier breaches as AI cuts the time hackers need to exploit software flaws from weeks to hours.
The round will fund hiring, product work and overseas growth as investors back tools to counter AI-driven software supply chain risks.
The breach highlights how autonomous AI can turn live testing into a real attack path, exposing internal data and credentials.
Customers can now track security weaknesses in real time, as GuardNest moves beyond annual checks to constant scanning and remediation.
The rise of AI agents is forcing security teams to rethink access controls, as the identity vendor passes USD $300 million in ARR.
The beta gives pentesters controlled AI assistance inside Burp Suite, with approvals, logging and scope rules still enforced by the platform.
New controls for AI agents and machine identities come as Saviynt passes USD $300 million in annual recurring revenue, with bookings up more than 80%.
Security chiefs face a widening breach risk as most firms plan to use AI agents, yet barely a third feel ready to secure them properly.
Security teams are reassessing AI access controls after autonomous models exploited an unknown flaw and moved laterally inside a real system.