AppSec stories
Lineaje survey finds AI code confidence outpaces visibility
Today
#
digital transformation
#
application security
#
devsecops
Lineaje survey flags a widening governance gap as most firms use AI-generated code, yet few can fully see or track it.
Claude Code can leak secrets in public npm packages
Today
#
data protection
#
application security
#
devsecops
Check Point says Anthropic's Claude Code can quietly stash credentials in .claude/settings.local.json, which may be published in public npm packages.
Check Point teams with Google Cloud on AI agent security
Today
#
firewalls
#
data protection
#
digital transformation
Check Point and Google Cloud add governance and live monitoring to enterprise AI agents as firms race to secure autonomous workflows.
AI coding speeds up, but security teams fall behind
Today
#
devops
#
digital transformation
#
application security
AI coding accelerates software delivery, but security teams struggle to keep up as more code, alerts and manual checks pile up.
Zscaler joins Anthropic Project Glasswing on cyber AI
Yesterday
#
firewalls
#
vpns
#
network security
Zscaler joins Anthropic's Project Glasswing to test Claude Mythos Preview in software scans, as the firm pushes zero trust against AI-driven attacks.
HackerOne launches h1 Validation to tackle AI flaws
Yesterday
#
devops
#
digital transformation
#
application security
HackerOne unveils h1 Validation as vulnerability reports surge 76% and AI tools speed up discovery, leaving firms struggling to triage real threats.
Chainguard & Cursor tackle AI code supply chain risks
Yesterday
#
devops
#
application security
#
devsecops
Chainguard and Cursor strike partnership to embed verified open source dependencies into AI coding, aiming to curb supply chain risks at machine speed.
Tenable flags Microsoft GitHub workflow flaw exposing code
Yesterday
#
devops
#
cloud security
#
application security
Tenable warns a GitHub Actions bug in Microsoft's Windows-driver-samples repo could let attackers run code and steal secrets via public issues.
AI vulnerability discovery forces boards to rethink cyber risk
Yesterday
#
data protection
#
application security
#
iam
AI models that can hunt and chain software flaws are forcing boards to rethink cyber defences, while scrutiny grows over Anthropic's MCP design risks.
LangWatch launches open-source tool for AI red-teaming
2 days ago
#
data protection
#
devops
#
data analytics
LangWatch releases open-source AI red-teaming framework to expose hidden vulnerabilities in production agents through multi-turn attack simulations.
Appdome launches identity-first mobile API protection
Last week
#
virtualisation
#
firewalls
#
endpoint protection
Appdome unveils mobile API defence that checks app, device and session identity before granting access, targeting bot abuse and takeover attacks.
Capsule Security raises $7 million to guard AI agents
Last week
#
pam
#
cloud security
#
application security
Capsule Security emerges from stealth with $7 million backing to police AI agents at runtime as enterprises widen their use.
AI coding boom deepens cognitive debt, says Thoughtworks
Last week
#
devops
#
digital transformation
#
application security
Thoughtworks warns AI-assisted coding is swelling software complexity, as developers lean on older controls to curb security and oversight risks.
Cloudflare, Wiz link AI security tools for unified view
Last week
#
firewalls
#
data protection
#
digital transformation
Cloudflare and Wiz team up to map shadow AI risks across cloud estates and protect sensitive data as firms race to secure chatbot deployments.
OpenAI expands cyber access for verified defenders
Last week
#
application security
#
socs
#
physical security
OpenAI broadens Trusted Access for Cyber to verified defenders, giving vetted users GPT-5.4-Cyber for tougher security work and code analysis.
Sonatype warns of surge in trusted open-source malware
Last week
#
application security
#
devsecops
#
supply chain
Sonatype flags 21,764 malicious open-source packages in Q1 2026, with npm hit hardest as attackers used trusted workflows to steal secrets.
Forrester says Anthropic AI could break patch playbook
Last week
#
hybrid cloud
#
digital transformation
#
application security
Forrester warns Anthropic's Project Glasswing could overwhelm vulnerability management, as AI uncovers flaws faster than patching teams can respond.
Permiso launches sandbox for AI agent skill security
This month
#
firewalls
#
network security
#
cloud security
Permiso launches SandyClaw sandbox to detonate AI agent skills and expose hidden runtime risks before they reach enterprise systems.
F5 & Forcepoint come together to secure enterprise AI
This month
#
data protection
#
hybrid cloud
#
digital transformation
F5 and Forcepoint have teamed up to link data discovery with runtime controls, aiming to curb AI risks as enterprises move systems into production.
JFrog & iZeno expand AI security tools in Southeast Asia
Last month
#
crm
#
data protection
#
devops
JFrog teams up with iZeno to bring software supply chain and AI governance tools to Southeast Asian enterprises amid rising compliance demands.