IT Brief India - Technology news for CIOs & IT decision-makers

AppSec stories

Flux result c47fc794 21dd 4fb9 9c40 8c1333595464

Lineaje survey finds AI code confidence outpaces visibility

Today
#
digital transformation
#
application security
#
devsecops
Lineaje survey flags a widening governance gap as most firms use AI-generated code, yet few can fully see or track it.
Flux result b0e7cc49 91ef 4484 ba46 cdb3c997b1bf

Claude Code can leak secrets in public npm packages

Today
#
data protection
#
application security
#
devsecops
Check Point says Anthropic's Claude Code can quietly stash credentials in .claude/settings.local.json, which may be published in public npm packages.
Check point

Check Point teams with Google Cloud on AI agent security

Today
#
firewalls
#
data protection
#
digital transformation
Check Point and Google Cloud add governance and live monitoring to enterprise AI agents as firms race to secure autonomous workflows.
Flux result fc41b3aa 8862 4880 bcfd fc720050def5

AI coding speeds up, but security teams fall behind

Today
#
devops
#
digital transformation
#
application security
AI coding accelerates software delivery, but security teams struggle to keep up as more code, alerts and manual checks pile up.
Flux result 98c90454 e22b 40d3 87b0 b943c20a210c

Zscaler joins Anthropic Project Glasswing on cyber AI

Yesterday
#
firewalls
#
vpns
#
network security
Zscaler joins Anthropic's Project Glasswing to test Claude Mythos Preview in software scans, as the firm pushes zero trust against AI-driven attacks.
Flux result ad42d32c 7135 4932 a4cb b35aca0c1391

HackerOne launches h1 Validation to tackle AI flaws

Yesterday
#
devops
#
digital transformation
#
application security
HackerOne unveils h1 Validation as vulnerability reports surge 76% and AI tools speed up discovery, leaving firms struggling to triage real threats.
Flux result f2267c48 0574 4902 827d 0f5954093a18

Chainguard & Cursor tackle AI code supply chain risks

Yesterday
#
devops
#
application security
#
devsecops
Chainguard and Cursor strike partnership to embed verified open source dependencies into AI coding, aiming to curb supply chain risks at machine speed.
Flux result 5b734eba 1444 4464 96e8 27cf5fa2f10a

Tenable flags Microsoft GitHub workflow flaw exposing code

Yesterday
#
devops
#
cloud security
#
application security
Tenable warns a GitHub Actions bug in Microsoft's Windows-driver-samples repo could let attackers run code and steal secrets via public issues.
Flux result 1449a80a d271 47ab a1ef 916b32f14374

AI vulnerability discovery forces boards to rethink cyber risk

Yesterday
#
data protection
#
application security
#
iam
AI models that can hunt and chain software flaws are forcing boards to rethink cyber defences, while scrutiny grows over Anthropic's MCP design risks.
Flux result 808b973b 89ac 4abe 9c99 1ff6fe4ed0a5

LangWatch launches open-source tool for AI red-teaming

2 days ago
#
data protection
#
devops
#
data analytics
LangWatch releases open-source AI red-teaming framework to expose hidden vulnerabilities in production agents through multi-turn attack simulations.
Flux result 44e11089 0abf 4f3d 9c26 0684b856984e

Appdome launches identity-first mobile API protection

Last week
#
virtualisation
#
firewalls
#
endpoint protection
Appdome unveils mobile API defence that checks app, device and session identity before granting access, targeting bot abuse and takeover attacks.
Flux result bda8fa3f b9b2 421e 992b 6bbacbd7b7cc

Capsule Security raises $7 million to guard AI agents

Last week
#
pam
#
cloud security
#
application security
Capsule Security emerges from stealth with $7 million backing to police AI agents at runtime as enterprises widen their use.
Flux result 3fb02bd1 1848 4544 8c34 d894346384d2

AI coding boom deepens cognitive debt, says Thoughtworks

Last week
#
devops
#
digital transformation
#
application security
Thoughtworks warns AI-assisted coding is swelling software complexity, as developers lean on older controls to curb security and oversight risks.
Flux result 51cf6bc6 caf3 4086 9aca 43f89e74737d

Cloudflare, Wiz link AI security tools for unified view

Last week
#
firewalls
#
data protection
#
digital transformation
Cloudflare and Wiz team up to map shadow AI risks across cloud estates and protect sensitive data as firms race to secure chatbot deployments.
Flux result be5832d1 2647 4b40 8c3f 54ddb15bfb62

OpenAI expands cyber access for verified defenders

Last week
#
application security
#
socs
#
physical security
OpenAI broadens Trusted Access for Cyber to verified defenders, giving vetted users GPT-5.4-Cyber for tougher security work and code analysis.
Flux result 20e12820 27f4 4e8a 9da9 1c2ee2ea902d

Sonatype warns of surge in trusted open-source malware

Last week
#
application security
#
devsecops
#
supply chain
Sonatype flags 21,764 malicious open-source packages in Q1 2026, with npm hit hardest as attackers used trusted workflows to steal secrets.
Flux result 69d8aedf 698f 4136 9525 1ed7c7a0ec10

Forrester says Anthropic AI could break patch playbook

Last week
#
hybrid cloud
#
digital transformation
#
application security
Forrester warns Anthropic's Project Glasswing could overwhelm vulnerability management, as AI uncovers flaws faster than patching teams can respond.
Flux result 8ebd1272 347f 4407 acbc d4999522fad4

Permiso launches sandbox for AI agent skill security

This month
#
firewalls
#
network security
#
cloud security
Permiso launches SandyClaw sandbox to detonate AI agent skills and expose hidden runtime risks before they reach enterprise systems.
Flux result 4fd4ec51 3ee5 4138 9d86 cf53ec65c7ba

F5 & Forcepoint come together to secure enterprise AI

This month
#
data protection
#
hybrid cloud
#
digital transformation
F5 and Forcepoint have teamed up to link data discovery with runtime controls, aiming to curb AI risks as enterprises move systems into production.
Flux result 44bf25f6 2291 4d96 b9c5 c6f118652b40

JFrog & iZeno expand AI security tools in Southeast Asia

Last month
#
crm
#
data protection
#
devops
JFrog teams up with iZeno to bring software supply chain and AI governance tools to Southeast Asian enterprises amid rising compliance demands.