AppSec stories
Growing demand for earlier code security has prompted Distology to add Snyk’s application and AI tools to its UK, DACH and Benelux channel offer.
A critical flaw in a widely used Microsoft code-sample repository could have let attackers steal secrets and run code through GitHub issues.
Boards are being pressed to abandon periodic patching as AI models can now uncover and chain software flaws faster than human teams can respond.
The framework is designed to expose hidden risks in production AI systems that can be missed by conventional one-off tests.
Mobile API calls can now be checked against app, device and session identity before access is granted, aiming to curb bot abuse and takeover attempts.
Businesses relying on obfuscation and embedded secrets in mobile apps may face easier API attacks as AI can mimic legitimate traffic.
The Tel Aviv startup says enterprises need runtime controls as AI agents take on more privileged tasks across core business systems.
Rising use of AI assistants is making software harder to understand, prompting teams to revive stricter testing, controls and oversight.
Security teams gain a single view of shadow AI as Cloudflare and Wiz connect traffic inspection with cloud asset mapping to spot exposed data.
Thousands of vetted cybersecurity staff will gain broader access to OpenAI tools as the company loosens safeguards for defensive research.
Attackers hid malware in familiar package workflows, prompting Sonatype to log 21,764 malicious open-source packages in the quarter.
Faster AI-led flaw discovery could overwhelm patching and disclosure processes, leaving companies with bigger backlogs and less time to respond.
Most engineering teams could struggle to meet EU Cyber Resilience Act reporting deadlines, with many still handling SBOMs manually or only after incidents.
Malicious downloads can now be caught at runtime, as the new tool records hidden network calls and file writes before deployment.
Security teams face a wider gap as enterprise AI moves into production, with data governance and runtime controls often managed separately.
Ransomware pressure on US firms is intensifying debate over whether broader AI hacking tools will help defenders or aid criminals.
Enterprises face faster phishing, deepfakes and automated exploits as security leaders say existing controls lag behind frontier AI models.
Australian developers can now access free vulnerability tools as Vulnetix takes a formal role in global software flaw tracking.
Australian organisations face fresh risk of cloud and identity compromise as the cyber watchdog reissues its alert on repository attacks.
The funding will help Qodo expand globally as enterprises look for ways to verify AI-written code before it reaches production systems.