AppSec stories
Ransomware pressure on US firms is intensifying debate over whether broader AI hacking tools will help defenders or aid criminals.
Enterprises face faster phishing, deepfakes and automated exploits as security leaders say existing controls lag behind frontier AI models.
AI coding agents are increasing supply chain risk, prompting new controls to verify third-party dependencies before they reach production.
A critical flaw in a widely used Microsoft code-sample repository could have let attackers steal secrets and run code through GitHub issues.
Boards are being pressed to abandon periodic patching as AI models can now uncover and chain software flaws faster than human teams can respond.
The framework is designed to expose hidden risks in production AI systems that can be missed by conventional one-off tests.
Mobile API calls can now be checked against app, device and session identity before access is granted, aiming to curb bot abuse and takeover attempts.
Businesses relying on obfuscation and embedded secrets in mobile apps may face easier API attacks as AI can mimic legitimate traffic.
The Tel Aviv startup says enterprises need runtime controls as AI agents take on more privileged tasks across core business systems.
Rising use of AI assistants is making software harder to understand, prompting teams to revive stricter testing, controls and oversight.
Security teams gain a single view of shadow AI as Cloudflare and Wiz connect traffic inspection with cloud asset mapping to spot exposed data.
Thousands of vetted cybersecurity staff will gain broader access to OpenAI tools as the company loosens safeguards for defensive research.
Attackers hid malware in familiar package workflows, prompting Sonatype to log 21,764 malicious open-source packages in the quarter.
Faster AI-led flaw discovery could overwhelm patching and disclosure processes, leaving companies with bigger backlogs and less time to respond.
Most engineering teams could struggle to meet EU Cyber Resilience Act reporting deadlines, with many still handling SBOMs manually or only after incidents.
Malicious downloads can now be caught at runtime, as the new tool records hidden network calls and file writes before deployment.
More than 500 senior leaders will gather in Melbourne next July as cyber risk, AI and resilience pressures push security teams to align.
Growing demand for earlier code security has prompted Distology to add Snyk’s application and AI tools to its UK, DACH and Benelux channel offer.
Australian developers can now access free vulnerability tools as Vulnetix takes a formal role in global software flaw tracking.
Australian organisations face fresh risk of cloud and identity compromise as the cyber watchdog reissues its alert on repository attacks.