AppSec stories
Endor Labs unveils AURI to secure AI-driven coding
Today
#
devops
#
application security
#
devsecops
Endor Labs has launched AURI, an AI-aware security platform that embeds continuous code checks directly into agent-driven development workflows.
LevelBlue & Tenable expand exposure tools for partners
Today
#
digital transformation
#
cloud security
#
application security
LevelBlue debuts Exposure Management for Partners with Tenable, giving MSSPs and MSPs tiered, unified exposure and risk visibility tools.
LevelBlue & Tenable launch exposure service for MSPs
Today
#
digital transformation
#
cloud security
#
application security
LevelBlue and Tenable have teamed up to launch a tiered exposure management service giving MSPs continuous, risk-based visibility.
Manifest flags AI readiness gap between execs & AppSec
Yesterday
#
digital transformation
#
cloud security
#
application security
Manifest research reveals executives overestimate AI security readiness, as AppSec teams warn of unmanaged tools, blind spots and rising risk.
The security challenges in AI-assisted software development
4 days ago
#
digital transformation
#
application security
#
devsecops
As AI tools spread through software teams, rising security flaws and shadow AI use are forcing leaders to tighten guardrails fast.
Chainguard extends secure libraries to Python, Java, JS
Last week
#
application security
#
devsecops
#
supply chain
Chainguard expands its rebuilt-from-source Libraries to Python, Java and JavaScript, targeting malware risks in AI-driven software supply chains.
OpenClaw AI assistant surge sparks major security fears
Last week
#
malware
#
phishing
#
application security
A rapid surge in OpenClaw AI assistant use has left tens of thousands of exposed systems and a trail of hijacked tools and malicious add-ons.
GitLab expands MSP partner push for agentic AI control
Last week
#
data protection
#
digital transformation
#
hyperscale
GitLab expands its MSP partner programme to deliver agentic AI-powered DevSecOps as a managed service with strict data sovereignty controls.
Datadog flags rising DevSecOps risk from ageing code
Last week
#
devops
#
siem
#
application security
Datadog warns 87% of organisations run software with exploitable flaws as ageing code, fast releases and automation amplify DevSecOps risk.
Security debt surges as legacy vulnerabilities pile up
Last week
#
data protection
#
devops
#
application security
Security debt hits 82% of organisations as legacy flaws linger over a year, with third-party code driving most critical vulnerabilities.
CIOs brace for AI-led cyber attacks but feel unready
Last week
#
digital transformation
#
cloud security
#
phishing
Most CIOs expect AI-driven cyber attacks within a year, but only a third feel prepared, exposing a widening gap in cyber resilience.
AI, cloud adoption driving new surge in cyber exposure
Last week
#
data protection
#
digital transformation
#
pam
Rapid AI and cloud adoption is fuelling a new wave of cyber risk, as Tenable warns of exposed software supply chains and “ghost” identities.
Anthropic unveils Claude Code Security to scan codebases
Last week
#
devops
#
cloud security
#
application security
Anthropic unveils Claude Code Security, an AI tool that scans codebases for complex bugs, verifies risks and suggests patches for developers.
Tenable warns of widening AI exposure gap in cloud
Last month
#
malware
#
digital transformation
#
public cloud
Tenable warns businesses that rapid AI and cloud adoption is creating an invisible exposure gap as identity and supply chain risks surge.
ActiveState unveils 79m-strong secure open source catalogue
Last month
#
devops
#
digital transformation
#
application security
ActiveState launches a 79m-component secure open source catalogue to centralise software supply chains and cut enterprise vulnerability risk.
Checkmarx brings IDE-native security checks to Kiro
Last month
#
cloud security
#
application security
#
soc
Checkmarx adds IDE-native security checks to AI-focused Kiro, aiming to catch vulnerabilities earlier and cut security rework for teams.
DryRun Security adds Andrew Peterson to drive AI shift
Last month
#
firewalls
#
application security
#
devsecops
DryRun Security appoints Signal Sciences Co-founder Andrew Peterson to its board to steer its AI-native code security push.
Okta unveils tools to detect & govern shadow AI risks
Last month
#
pam
#
cloud security
#
application security
Okta launches Agent Discovery to uncover and rein in shadow AI agents, mapping risky app access and tightening identity-based controls.
Aerospike embeds default data masking in Database 8
Last month
#
data protection
#
application security
#
partner programmes
Aerospike Database 8 now embeds default dynamic data masking, tightening PII protection while easing compliance and operational overhead.
DigiCert sees record UltraDNS DDoS surge in December 2025
Last month
#
firewalls
#
network security
#
application security
DigiCert warns UltraDNS DDoS attacks spiked to record levels in December 2025, driven by massive Aisuru and Kimwolf botnets.