AppSec stories
Netacea has unveiled Trust Layer, a server-side tool to classify and control surging AI agent and bot traffic before it hits apps.
Enterprises in Southeast Asia will get tighter control over software and AI assets as iZeno begins distributing JFrog’s security tools immediately.
As AI moves into production, enterprises face gaps between data governance and runtime controls that can expose sensitive information and policy breaches.
Security teams will gain visibility into AI agents in production, with new runtime controls aimed at spotting misuse, shadow AI and compromise paths.
Enterprises could spot compromised maintainers sooner, as the new tool maps open-source contributors, dependencies and policy breaches across builds.
Security teams now have a beta tool to probe large language model apps for prompt injection, jailbreaks and data theft before attackers do.
Sonatype says smaller AI tied to live software data can outsecure larger models on dependency upgrades, slashing risk and cost.
NSS Labs warns many enterprise AI guardrails fail basic security tests, urging independent, real-world validation of protections.
Red Hat reports 97% of organisations suffered cloud-native security incidents last year, exposing basic failings in configuration and governance.
Cloudsmith adds automated controls to quarantine and block risky dependencies, tightening enforcement on software supply chain security.
Veracode unveils an AI-driven tool that automatically fixes open-source vulnerabilities, tackling mounting security debt in software supply chains.
UiPath is pushing AI deeper into software testing, promising autonomous agents that transform quality assurance and developers' roles.
Aqua Security's Trivy GitHub Action was hijacked to ship infostealer code via CI/CD pipelines, exposing secrets across downstream users.
GitLab opens agentic AI to free-tier users, sets USD $0.25 flat fee for automated code reviews and expands security false-positive filtering.
Cobalt weaves AI into its pentesting platform, automating recon and triage while keeping human experts on complex attack paths.
NetSPI unveils an AI-powered overhaul of its pentesting platform UX, promising two-click workflows and sharper risk-based remediation focus.
Miggo and Grafana link runtime security to Grafana Cloud telemetry, promising major cuts to critical vulnerability noise for joint users.
Adoption among big enterprises has helped the cybersecurity start-up secure USD $28 million, as it expands tools for AI-driven software development.
Wallarm names Shayne Higdon chief executive in leadership reshuffle as it pivots from pure API protection to securing wider AI-driven risks.
Organisations test just a third of their attack surface as reliance on agentic AI grows, raising fresh concerns over unseen cyber risks.