AppSec stories
Enterprises face a new runtime security gap as AI agents increasingly access internal systems, files and tools without oversight.
Autonomous systems are now creating fresh avenues for code theft, remote execution and runaway cloud spending, Mandiant says.
The stealer's use of typosquatted npm packages has raised fears that bug bounty channels are being abused to monetise stolen developer data.
With most firms using AI in daily work but few staff ready for it, the programme targets non-developers handling sensitive data and automations.
The private previews aim to help security teams spot exploitable code chains and connect AI agents to Rubrik's governance tools more safely.
Companies selling software into the bloc now have 24 hours to flag exploited flaws, with fines reaching EUR €15 million for delays.
Attackers are compressing intrusions into hours, leaving defenders less time to spot and stop credential-harvesting campaigns.
Trusted partners and tighter guardrails are becoming essential as AI agents expand the attack surface and put data sovereignty on the line.
The collaboration could help security teams spot flaws before attackers exploit them, as exploitations increasingly happen on or before disclosure.
Security teams could get clearer visibility into compiled software, as RevEng.AI's new models aim to spot risks without source code.
Security teams could see fewer false positives and faster fixes as Cycode's new system blends rule-based checks with AI to trace attack paths.
As AI coding agents speed up development, JFrog is adding controls meant to keep governance, compliance and patching from lagging.
Independent testing found no critical, high or medium flaws in TiDB's platform as database buyers demand stronger proof of security.
Machine-speed discovery is shrinking defenders' lead time, as AI now uncovers obscure flaws and turns them into exploits before patches land.
Partners across EMEA and APAC gain a route into AI coding and DevSecOps projects as SonarQube checks aim to cut security and governance risks.
Many firms lack the capacity to fix existing flaws fast enough, leaving them exposed as AI-generated attacks scale up, experts warn.
Customers will get human-verified open source fixes as Broadcom expands Spring security coverage and counters risks from AI-generated patches.
APIs are now a major attack surface, making shared context between developers and SecOps vital to spot real threats and avoid false alarms.
Banks face new exposure from AI agents linking to internal systems, as the platform aims to block data leaks and unauthorised actions.
Blockchain apps risk losing new users unless developers simplify approvals and signing while keeping private keys and transactions secure.