Source code stories
A faulty token check let low-privilege users view other applicants' identities, payment details and Social Security numbers in a financial onboarding app.
The pilot could speed up vulnerability hunting across government systems, but it also leaves human teams to verify and fix each AI flag.
Enterprises can now vet open-source dependencies before build time, as the catalogue adds independent malware and vulnerability checks for Python and Java.
Prompt-injection attacks and data leaks are the main risks as businesses connect Copilot and Gemini to email, files and internal tools.
The tie-up aims to help security teams turn validated AI findings into ranked fixes before vulnerabilities pile up and attackers move first.
Boards are under pressure to curb staff use of ChatGPT and similar tools, as pasted data could expose customer records and source code.
Organisations using Wayfinder Frontier AI Services will now get help turning validated vulnerabilities into prioritised fixes and post-deployment checks.
Organisations face a growing risk of silent data theft as criminals exploit cloud identities and credentials for extortion instead of encryption.
Critical vulnerability backlogs have swelled 29-fold, prompting a tool that sends fix plans into engineering systems and AI coding tools.
The hybrid system aims to help security teams spot serious flaws in AI-generated code faster, as production code becomes harder to review.
Downstream AI data leaks have more than doubled in a year, with connected services now returning unauthorised information to staff and agents.
Approved AI tools are cutting shadow use by staff, but Cohesity warns the bigger risk is corrupted enterprise knowledge and weak governance.
Security teams could cut hours from patching work as open-weight Antares models narrow flaws to the relevant code segment.
The tool aims to help developers cut vulnerability backlogs and reach no exploitable flaws within 90 days as AI coding expands risk.
Security teams are being warned to keep humans and strict controls in place as AI agents can miss context and leak sensitive code.
Developers using AI agents could avoid GitHub rate limits and outages as Entire opens a preview network mirroring repositories across regions.
Financial institutions still face hidden fourth-party risks even after Microsoft, Google Cloud, AWS and Oracle were designated as critical providers.
Users and researchers can now inspect how the Sydney-based search engine ranks results and handles privacy after its code was opened.
Smaller firms can now run web app pentests in hours, as Intruder's AI service cuts costs to a fraction of manual reviews.
Security teams could cut testing delays to hours as Intruder's AI tool scans web apps for flaws from source code access.