AppSec stories
Smaller firms can now run web app pentests in hours, as Intruder's AI service cuts costs to a fraction of manual reviews.
Security teams could cut testing delays to hours as Intruder's AI tool scans web apps for flaws from source code access.
Security teams could cut hours from patching work as open-weight Antares models narrow flaws to the relevant code segment.
Developers using AI assistants could face stolen credentials and poisoned repositories as the worm hides inside normal coding workflows.
Businesses using AI coding tools face repeatable security gaps, as the new index found an average 15 vulnerabilities in each codebase.
The tool aims to help developers cut vulnerability backlogs and reach no exploitable flaws within 90 days as AI coding expands risk.
Security teams can now rank code flaws against wider business risk as Tenable One links static vulnerability data with cloud, identity and attack-path exposure.
Security teams are being warned to keep humans and strict controls in place as AI agents can miss context and leak sensitive code.
Defenders could gain a faster edge against AI-driven attacks as Google Cloud ties Gemini, Wiz, CodeMender and Mandiant into one platform.
The update aims to cut review bottlenecks by auto-fixing vulnerable dependencies and surfacing code flaws scanners often miss.
Security teams can now trace how one SAP flaw could spread across finance, payroll and supply chains, with access tightly restricted.
Developers face earlier checks on risky open-source dependencies as AI coding tools speed up software assembly and raise supply chain concerns.
Malicious package advisories jumped from 21 in 2023 to 1,576 in 2025, as attackers increasingly target developers before code reaches production.
Exposed serverless apps can let attackers steal tokens, read secrets and take over cloud projects if weak code is left unpatched.
Security teams can now rank code flaws against cloud and identity risks after Tenable folded application security data into its exposure platform.
Broader coverage in Mexico and Milan aims to cut latency for mobile security checks as fake app traffic grows more sophisticated.
Nearly half of commerce traffic across Akamai's network came from AI bots by late 2025, raising fraud and DDoS risks for retailers.
As AI coding speeds up, Checkmarx says its new agents can cut manual vulnerability fixes by up to 70% before code is committed.
Businesses may get security test results in hours as ITSEC Asia's new platform flags risks and keeps human consultants in the loop.
Banks risk repeating DevOps sprawl as DIY agentic AI pushes build costs above USD $1.4 million and delays production by up to 18 months.