Tag: application-security
-
AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswing
Tags: access, ai, api, application-security, compliance, control, cyber, cybersecurity, data, exploit, flaw, reverse-engineering, risk, software, threat, tool, update, vulnerabilityWe spent 500+ hours and 40 billion tokens testing Anthropic’s Claude Mythos Preview for Project Glasswing. The takeaway: frontier AI won’t run your code security program, but used well, it can make one even stronger. Key takeaways Frontier AI dramatically scales security testing. In one month, Tenable dedicated 11 security experts and more than 40…
-
Hybridansatz für umfassendere Schwachstellenerkennung: Checkmarx stellt Checkmarx Fusion vor
Neue Architektur kombiniert bewährte AppSec-Scan-Engines mit KI-gestützter Analyse und ermöglicht eine präzisere Schwachstellenerkennung über den gesamten Softwareentwicklungszyklus hinweg. Checkmarx, Anbieter für autonome, Cloud-native Anwendungssicherheit, stellt mit Checkmarx Fusion einen neuen hybriden Scan-Ansatz vor, der ab sofort im Rahmen eines Early-Access-Programms für Kunden verfügbar ist. Checkmarx Fusion kombiniert die bewährten AppSec-Scan-Engines und den proprietären Sicherheitskontext… First…
-
Cycode Opens Early Access to Agentic Workflows for Application Security
Cycode is making Agentic Workflows available in early access, giving AI agents the ability to detect, prioritize and fix application-development risks as they appear. The company is demonstrating the capability at Black Hat USA 2026 in Las Vegas. Agentic Workflows operate across the application development lifecycle. Security teams define the triggers, actions and confidence thresholds,..…
-
AI pentesting tools are generating more findings than security teams can validate, new survey finds
New research from Pentest-Tools.com suggests that AI-assisted penetration testing tools are generating vulnerability findings faster than most security teams can verify them, creating a validation backlog that is offsetting the time AI was meant to save. The company surveyed 158 security practitioners in June 2026, including penetration testers, security engineers, AppSec and DevSecOps professionals, consultants,…
-
Using LLMs to Find & Prioritize Vulnerabilities Is No Easy Task
The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/finding-and-prioritizing-vulnerabilities-no-easy-task
-
Using LLMs to Find & Prioritize Vulnerabilities Is No Easy Task
The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/finding-and-prioritizing-vulnerabilities-no-easy-task
-
What Is Application Security? A Complete Guide
First seen on scworld.com Jump to article: www.scworld.com/tech-explainer/what-is-application-security-a-complete-guide
-
Apiiro CEO: Coding Agents Are the New Enterprise Perimeter
Idan Plotnik: AI Development Tools Have Become Enterprises’ Newest Attack Surface. Apiiro CEO Idan Plotnik says AI coding agents have become the enterprise’s newest security perimeter, prompting organizations to shift from application security posture management to automated protection as AI accelerates both software development and vulnerability exploitation. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/apiiro-ceo-coding-agents-are-new-enterprise-perimeter-a-32314
-
Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task
The latest large language models have high false-positive rates and fail to take into account the context of scans, leading to more work for AppSec professionals. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/finding-and-prioritizing-vulnerabilities-no-easy-task
-
Greenhat Announces Successful Delegation at Web Summit Vancouver 2026
Vancouver, Canada, July 14th, 2026, CyberNewswire Canadian Cybersecurity Leaders Celebrate Successful Web Summit Vancouver 2026 and Growing CanadaKorea Collaboration The Canadian Cyber Zone brought together cybersecurity, quantum security, application security, compliance, and international innovation leaders during one of Canada’s largest technology events The Canadian Cyber Zone announced the successful completion of its participation at Web…
-
Anthropic buffa Library Zero-Day Lets Attackers Trigger Memory-Amplification DoS
Anthropic’s Rust-based protobuf library, buffa, has been discovered to have a zero-day memory amplification denial-of-service (DoS) vulnerability. This flaw allows attackers to deplete system memory using relatively small inputs. Endor Labs identified the issue through its AI-powered static application security testing (SAST) engine and is now tracked as CVE-2026-55407. This situation underscores how logic flaws…
-
Aikido Buys Root for $70M to Automate Open-Source Patching
Deal Adds Hardened Packages, Automated CVE Fixes to Application Security Platform. Belgian software vendor Aikido Security acquired Boston-based Root for $70 million to embed automated vulnerability remediation into its application security platform, enabling enterprises to deploy hardened open-source packages and container images while reducing software supply-chain risk. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/aikido-buys-root-for-70m-to-automate-open-source-patching-a-32118
-
Robinhood Cuts Access Approval Time to Support High-Velocity Development
The fintech company’s engineering-first application security team re-engineered the process for granting system access, making it easier and more secure for developers working on their projects. Here are the lessons learned from Robinhood’s experience. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/robinhood-reengineered-access-approvals-for-high-velocity-development
-
Snyk Reportedly Cuts 90 Jobs to Accelerate AI Strategy
Interim CEO Ken MacAskill Says Changes Will Speed Product Development and Execution. Boston-based Snyk is reportedly eliminating about 90 jobs while reorganizing leadership, go-to-market operations and research to accelerate AI-focused application security development as the company navigates slowing growth, a CEO transition and intensifying market competition. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/snyk-reportedly-cuts-90-jobs-to-accelerate-ai-strategy-a-32081
-
Black Duck Lands Leader Spot in Gartner’s Brand-New Software Supply Chain Security Magic Quadrant
Application security firm Black Duck has been named a Leader in Gartner’s first-ever Magic Quadrant for Software Supply Chain Security, the company announced today. The inaugural report assessed 18 vendors against two axes, Completeness of Vision and Ability to Execute, and placed Black Duck firmly in the Leaders quadrant. The timing of the report reflects…
-
Best Practices für Anwendungssicherheit im KI-Zeitalter – KI-generierter Code überfordert klassische AppSec-Audits
First seen on security-insider.de Jump to article: www.security-insider.de/appsec-audits-ki-generierter-code-kontinuierliche-sicherheitspruefungen-a-7bcecd63096deca4e56a10fc634b655f/
-
95 Prozent der CISOs stehen unter Druck, Compliance-relevante Probleme der Cybersicherheit zurückzustellen
Checkmarx hat die Ergebnisse seines diesjährigen <> vorgestellt. Demnach nutzen inzwischen 96 Prozent der Entwicklerinnen und Entwickler KI-Tools in ihrer IDE und bewerten deren Nutzen überwiegend positiv. Allerdings geben lediglich 18 Prozent an, bereits während der Entwicklung kontinuierliche Sicherheitsprüfungen durchzuführen. Gleichzeitig geben 95 Prozent der CISOs an, unter Druck zu stehen, […] First seen on…
-
Known vulnerabilities behind most application security incidents
Eight in ten organizations took an application security hit during the past year tied to a vulnerability their team had already cataloged, according to a survey of 902 IT and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/03/csa-application-security-incidents/
-
Top 10 Best Static Application Security Testing (SAST) Tools for Security Teams in 2026
The complexity of modern software development requires security to be deeply embedded within the engineering pipeline rather than treated as an afterthought. Whether you are managing extensive front-end codebases or back-end API integrations, catching flaws before code is compiled is crucial. This proactive approach is the essence of Static Application Security Testing (SAST). By identifying…
-
What to Look for When Choosing an ASPM Platform
Application security posture management (ASPM) has become a foundational capability for software-as-a-service (SaaS) and software companies building increasingly complex, artificial intelligence-assisted applications. As engineering velocity increases and AI-generated code becomes part of everyday development workflows, security teams are under pressure to unify visibility, reduce fragmented tooling, and improve how risk isidentifiedand prioritized across the software…
-
AI agent finds 18-year-old remote code execution flaw in Nginx
Tags: ai, api, application-security, cve, cvss, data, dos, endpoint, exploit, flaw, github, leak, mitigation, network, open-source, remote-code-execution, risk, service, technology, update, vulnerability, wafngx_http_rewrite_module, a component that handles URL rewrites, and impacts Nginx versions from 0.6.27 to 1.30.0. The issue has been given a 9.2 CVSS severity score and was patched in versions 1.31.0 and 1.30.1.The commercial product, Nginx Plus, owned and developed by network and application security firm F5, is also vulnerable, and received patches in versions…
-
QA: Why Vulnerability Scans Are Giving Businesses a False Sense of Security
Phillip Wylie is an internationally recognised cybersecurity expert, ethical hacker and offensive security specialist with more than 28 years’ experience across IT, network security, application security, penetration testing, red teaming and social engineering. As co-author of The Pentester BluePrint, founder of The Pwn School Project and host of The Phillip Wylie Show, Phillip has built his career around…
-
Developer workstations are the new beachhead
Tags: access, application-security, attack, authentication, cloud, container, control, credentials, edr, endpoint, exploit, github, group, Hardware, identity, incident response, infrastructure, malware, mfa, monitoring, network, software, supply-chain, threat, updateThe economics that drive the convergence: A typical developer workstation holds SSH keys, cloud provider credentials, container registry tokens, Git authentication tokens and CI/CD pipeline secrets. Many developers have administrative access to internal package registries and deployment infrastructure. Their machines often sit outside the hardened perimeter that security teams build around production systems.From an attacker’s…
-
Official CheckMarx Jenkins package compromised with infostealer
Tags: application-securityCheckmarx warned over the weekend that a rogue version of its Jenkins Application Security Testing (AST) plugin had been published on the Jenkins Marketplace. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/official-checkmarx-jenkins-package-compromised-with-infostealer/
-
Malicious Hugging Face model masquerading as OpenAI release hits 244K downloads
Part of a broader AI supply chain targeting: HiddenLayer, in its advisory, said that it identified six additional Hugging Face repositories uploaded under a separate account that used nearly identical loader logic and shared infrastructure with the campaign.The researchers also linked elements of the operation to earlier software supply-chain attacks involving npm typosquatting campaigns and…
-
Application Security Strategies Are Changing as AI-generated Code Floods the SDLC
AI-generated code is changing AppSec workflows, forcing teams to rethink SDLC security, dependency checks, code review, and risk prioritization. First seen on hackread.com Jump to article: hackread.com/application-security-strategies-ai-generated-code-sdlc/
-
Claude Security Enters Public Beta for Enterprise Customers
Anthropic has officially launched the public beta of Claude Security, an advanced vulnerability detection and remediation tool now available to Claude Enterprise customers. Powered by the highly capable Claude Opus 4.7 model, this platform shifts application security testing from basic pattern matching to deep, contextual analysis. As AI accelerates the timeline between discovering and exploiting…
-
Bad Bots in the Agentic Age: What the 2026 Thales Bad Bot Report Reveals
Tags: ai, api, application-security, attack, automation, banking, business, container, control, crime, cyber, cybercrime, data, defense, detection, exploit, finance, fraud, identity, infrastructure, intelligence, Internet, LLM, malicious, monitoring, resilience, risk, service, threat, tool, vulnerabilityBad Bots in the Agentic Age: What the 2026 Thales Bad Bot Report Reveals josh.pearson@t“¦ Thu, 04/30/2026 – 07:31 The modern internet is becoming less human by the day. Bot traffic is increasing, and human traffic is shrinking. Malicious automated traffic is getting harder to spot. The Thales 2026 Bad Bot Report, now in it’s…
-
Checkmarx confirms LAPSUS$ hackers leaked its stolen GitHub data
Application security company Checkmarx has confirmed that the LAPSUS$ threat group leaked data stolen from its private GitHub repository. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/checkmarx-confirms-lapsus-hackers-leaked-its-stolen-github-data/

