IT Brief UK - Technology news for CIOs & IT decision-makers

AppSec stories

Cinematic ai code security engineer shielded by glowing sphere

Endor Labs unveils AURI to secure AI-driven coding

Today
#
devops
#
application security
#
devsecops
Endor Labs has launched AURI, an AI-aware security platform that embeds continuous code checks directly into agent-driven development workflows.
Digital shield enterprise cyber risk cloud network blue teal

LevelBlue & Tenable expand exposure tools for partners

Today
#
digital transformation
#
cloud security
#
application security
LevelBlue debuts Exposure Management for Partners with Tenable, giving MSSPs and MSPs tiered, unified exposure and risk visibility tools.
Msp security operations center analysts monitoring threat dashboards

LevelBlue & Tenable launch exposure service for MSPs

Today
#
digital transformation
#
cloud security
#
application security
LevelBlue and Tenable have teamed up to launch a tiered exposure management service giving MSPs continuous, risk-based visibility.
Split boardroom execs vs stressed engineers ai data leak scene

Manifest flags AI readiness gap between execs & AppSec

Yesterday
#
digital transformation
#
cloud security
#
application security
Manifest research reveals executives overestimate AI security readiness, as AppSec teams warn of unmanaged tools, blind spots and rising risk.
Peter

The security challenges in AI-assisted software development

4 days ago
#
digital transformation
#
application security
#
devsecops
As AI tools spread through software teams, rising security flaws and shadow AI use are forcing leaders to tighten guardrails fast.
Software supply chain security python java js ai circuits lock

Chainguard extends secure libraries to Python, Java, JS

Last week
#
application security
#
devsecops
#
supply chain
Chainguard expands its rebuilt-from-source Libraries to Python, Java and JavaScript, targeting malware risks in AI-driven software supply chains.
Story 300075

OpenClaw AI assistant surge sparks major security fears

Last week
#
malware
#
phishing
#
application security
A rapid surge in OpenClaw AI assistant use has left tens of thousands of exposed systems and a trail of hijacked tools and malicious add-ons.
Ian steward

GitLab expands MSP partner push for agentic AI control

Last week
#
data protection
#
digital transformation
#
hyperscale
GitLab expands its MSP partner programme to deliver agentic AI-powered DevSecOps as a managed service with strict data sovereignty controls.
Yadi narayana 01

Datadog flags rising DevSecOps risk from ageing code

Last week
#
devops
#
siem
#
application security
Datadog warns 87% of organisations run software with exploitable flaws as ageing code, fast releases and automation amplify DevSecOps risk.
Moody legacy code wall crumbling with bugs and stressed engineers

Security debt surges as legacy vulnerabilities pile up

Last week
#
data protection
#
devops
#
application security
Security debt hits 82% of organisations as legacy flaws linger over a year, with third-party code driving most critical vulnerabilities.
Cio nighttime office ai cyber attack warning screens digital storm

CIOs brace for AI-led cyber attacks but feel unready

Last week
#
digital transformation
#
cloud security
#
phishing
Most CIOs expect AI-driven cyber attacks within a year, but only a third feel prepared, exposing a widening gap in cyber resilience.
Cloudy asia pacific skyline ai data streams cyber risk art

AI, cloud adoption driving new surge in cyber exposure

Last week
#
data protection
#
digital transformation
#
pam
Rapid AI and cloud adoption is fuelling a new wave of cyber risk, as Tenable warns of exposed software supply chains and “ghost” identities.
Secure dev workstation multi monitors code warnings shield icon

Anthropic unveils Claude Code Security to scan codebases

Last week
#
devops
#
cloud security
#
application security
Anthropic unveils Claude Code Security, an AI tool that scans codebases for complex bugs, verifies risks and suggests patches for developers.
Ai cloud puzzle shields dark gaps leaking data hidden keys

Tenable warns of widening AI exposure gap in cloud

Last month
#
malware
#
digital transformation
#
public cloud
Tenable warns businesses that rapid AI and cloud adoption is creating an invisible exposure gap as identity and supply chain risks surge.
Glowing secure data hub with network of open source package cubes

ActiveState unveils 79m-strong secure open source catalogue

Last month
#
devops
#
digital transformation
#
application security
ActiveState launches a 79m-component secure open source catalogue to centralise software supply chains and cut enterprise vulnerability risk.
Software engineer dual monitors security warnings cloud office scene

Checkmarx brings IDE-native security checks to Kiro

Last month
#
cloud security
#
application security
#
soc
Checkmarx adds IDE-native security checks to AI-focused Kiro, aiming to catch vulnerabilities earlier and cut security rework for teams.
Untitled design  68

DryRun Security adds Andrew Peterson to drive AI shift

Last month
#
firewalls
#
application security
#
devsecops
DryRun Security appoints Signal Sciences Co-founder Andrew Peterson to its board to steer its AI-native code security push.
Cinematic soc night ai alert dashboards hidden apps control

Okta unveils tools to detect & govern shadow AI risks

Last month
#
pam
#
cloud security
#
application security
Okta launches Agent Discovery to uncover and rein in shadow AI agents, mapping risky app access and tightening identity-based controls.
Secure cloud database stack with automatic pii data masking

Aerospike embeds default data masking in Database 8

Last month
#
data protection
#
application security
#
partner programmes
Aerospike Database 8 now embeds default dynamic data masking, tightening PII protection while easing compliance and operational overhead.
Uk datacenter night ultradns ddos botnet attack red alert

DigiCert sees record UltraDNS DDoS surge in December 2025

Last month
#
firewalls
#
network security
#
application security
DigiCert warns UltraDNS DDoS attacks spiked to record levels in December 2025, driven by massive Aisuru and Kimwolf botnets.