ChannelLife US - Industry insider news for technology resellers

AppSec stories - Page 2

Editorial storm cloud cloud security failure server racks padlocks warnings

Red Hat finds cloud security incidents hit 97% of firms

Last month
#
data protection
#
hybrid cloud
#
cloud security
Red Hat reports 97% of organisations suffered cloud-native security incidents last year, exposing basic failings in configuration and governance.
Editorial software dev code review open source supply chain shield repair vulnerable deps

Veracode launches Fix for open-source vulnerability repair

Last month
#
devops
#
application security
#
devsecops
Veracode unveils an AI-driven tool that automatically fixes open-source vulnerabilities, tackling mounting security debt in software supply chains.
Img 20260304 wa0003

UiPath Accelerates AI in Software Development and Testing

Last month
#
devops
#
digital transformation
#
application security
UiPath is pushing AI deeper into software testing, promising autonomous agents that transform quality assurance and developers' roles.
Editorial compromised software supply chain key token leak dark

Trivy GitHub breach exposes CI/CD supply chain risk

Last month
#
devops
#
cloud security
#
application security
Aqua Security's Trivy GitHub Action was hijacked to ship infostealer code via CI/CD pipelines, exposing secrets across downstream users.
Ai assisted code review inclusive dev team modern office

GitLab widens AI access & sets flat review pricing

Last month
#
devops
#
application security
#
devsecops
GitLab opens agentic AI to free-tier users, sets USD $0.25 flat fee for automated code reviews and expands security false-positive filtering.
Bodie lowe

Wallarm appoints new chief executive as AI focus grows

Last month
#
cloud security
#
application security
#
physical security
Wallarm names Shayne Higdon chief executive in leadership reshuffle as it pivots from pure API protection to securing wider AI-driven risks.
Editorial corporate network cybersecurity analysts limited testing shadowed connections risk

Firms test just 32% of attack surface, study finds

Last month
#
devops
#
digital transformation
#
cloud security
Organisations test just a third of their attack surface as reliance on agentic AI grows, raising fresh concerns over unseen cyber risks.
Editorial cybersecurity analyst pen test results attack path cloud diagrams

Cobalt adds AI features to boost continuous pentests

Last month
#
devops
#
cloud security
#
application security
Cobalt weaves AI into its pentesting platform, automating recon and triage while keeping human experts on complex attack paths.
Cybersecurity analyst dashboard network risks two click workflow

NetSPI unveils AI-led workflow redesign for pentesting

Last month
#
devops
#
cloud security
#
application security
NetSPI unveils an AI-powered overhaul of its pentesting platform UX, promising two-click workflows and sharper risk-based remediation focus.
Isometric cloud security alerts to calm monitoring dashboard network

Miggo & Grafana link runtime security with telemetry

Last month
#
devops
#
cloud security
#
application security
Miggo and Grafana link runtime security to Grafana Cloud telemetry, promising major cuts to critical vulnerability noise for joint users.
Developer workspace secure containers kubernetes cloud diagrams

Chainguard unveils free starter pack for secure images

Last month
#
virtualisation
#
devops
#
cloud security
Chainguard launches a free Catalog Starter pack, giving developers five production-grade secure container images from its vast library.
Sleek enterprise datacenter servers shielded secure blue glow

Lineaje unveils UnifAI to secure enterprise agentic AI

Last month
#
data protection
#
digital transformation
#
application security
Lineaje launches UnifAI, a security and governance layer to centralise control, discovery and policy for enterprise agentic AI deployments.
Email attachment20260319 397718 mhgso7

HackerOne unveils live agentic AI prompt injection tests

Last month
#
data protection
#
devops
#
cloud security
HackerOne launches live Agentic Prompt Injection Testing to expose real-world AI exploit paths as prompt injection threats surge 540%.
Isometric secure software pipeline ai agents shielded supply chain

JFrog unveils MCP registry to secure AI coding agents

Last month
#
devops
#
digital transformation
#
application security
JFrog launches an MCP registry to centralise and secure AI coding agents, extending software supply chain controls to agent workflows.
Laptop code leaking secrets glowing keyholes cloud data exposure

AI surge drives record secrets sprawl across GitHub

Last month
#
cloud security
#
application security
#
socs
AI-fuelled coding drives record 29 million hardcoded secrets on GitHub in 2025, with leaks from AI tools and services surging sharply.
Modern corporate soc room with source code graphs and risk heatmaps

Secure Code Warrior unveils AI code governance tool

Last month
#
application security
#
devsecops
#
supply chain
Secure Code Warrior launches SCW Trust Agent: AI, giving security teams commit-level visibility and control over AI-influenced code.
Secure ai software engineer workstation multi screens cinematic night

Harness unveils AI Security & coding tools for DevSecOps

Last month
#
devops
#
application security
#
advanced persistent threat protection
Harness has launched AI Security and Secure AI Coding tools to spot and block vulnerabilities in AI-powered apps and AI-generated code.
Cinematic secure ops center unified access ai devices glowing vault

1Password debuts Unified Access to secure AI agents

Last month
#
data protection
#
cloud security
#
mdm
1Password unveils Unified Access to secure AI agents and machine credentials, promising endpoint-to-agent visibility for security teams.
Cinematic ai brain circuitry over glowing world map cyber competitions

AI agent from Tenzai ranks in top 1% of global CTFs

Last month
#
devops
#
application security
#
devsecops
Tenzai's autonomous AI agent has placed in the top 1% of major global hacking CTF contests, beating more than 125,000 human rivals.
Peter

Secure Code Warrior unveils AI tool to govern code risk

Last month
#
data protection
#
application security
#
devsecops
Secure Code Warrior launches SCW Trust Agent: AI to trace, rate and police AI-generated code risks directly at developers' commit point.