AppSec stories
DigiCert sees record UltraDNS DDoS surge in December 2025
Last week
#
appsec
DigiCert warns UltraDNS DDoS attacks spiked to record levels in December 2025, driven by massive Aisuru and Kimwolf botnets.
Tenable reveals ‘LookOut’ flaws that endanger Google Looker
Last week
#
appsec
Tenable warns ‘LookOut’ flaws in Google Looker could hand attackers server control, expose secrets and enable cross-tenant cloud access.
Moltbook ‘vibe-coded’ flaw exposed AI chats & keys
Last week
#
appsec
Moltbook left a Supabase key exposed, leaking AI chats, 30,000 emails and 1.5 million API keys in a cautionary tale of vibe coding risk.
Qodo 2.0 debuts multi-agent AI code review upgrade
Last week
#
appsec
Qodo 2.0 launches multi-agent AI code review to boost trust in autogenerated code, claiming 11% better detection of critical issues.
Developers’ AI agents pose rising software supply risks
Last week
#
appsec
Developers granting AI agents broad, unsupervised access to code and systems are creating new software supply chain and data exposure risks.
DryRun unveils AI DeepScan Agent for faster code risk
Last week
#
appsec
DryRun launches DeepScan Agent, an AI tool that scans whole codebases in hours to rank real-world security risks and speed remediation.
Tenable reveals Looker flaws risking cross-tenant attacks
Last week
#
appsec
Tenable warns unpatched self-hosted Google Looker systems face remote takeover, data theft and cross-tenant cloud attack risks.
RapidFort raises USD $42m for automated vuln fixes
Last week
#
appsec
RapidFort secures USD $42m Series A to scale automated software supply chain security and continuous vulnerability remediation.
Security Journey unveils AI-era developer manifesto
Last week
#
appsec
Security Journey launches AI-era developer manifesto and revamped platform to embed secure coding into everyday workflows and tooling.
AI agents expose risks in insecure default databases
Last week
#
appsec
A security lapse at AI agent service Moltbook exposes risky default database settings, raising fresh alarms over agentic system safeguards.
DigiCert warns of prolonged online demand & attacks
Last month
#
appsec
DigiCert warns Q4 internet traffic stayed high as DDoS and app-layer attacks grew longer and more intense, eroding traditional peak seasons.
Hugging Face used to spread Android trojan TrustBastion
Last month
#
appsec
Cybercriminals abused Hugging Face to host rapidly mutating TrustBastion Android malware stealing credentials across Asia-Pacific.
AI security drives demand for faster pentesting models
Last month
#
appsec
AI security fears and rapid release cycles are pushing firms to demand faster, deeper pentesting - and many are ready to ditch existing vendors.
HackerOne unveils AI‑driven continuous pentesting service
Last month
#
appsec
HackerOne launches Agentic PTaaS, blending AI agents with human experts to deliver continuous, always-on penetration testing for enterprises.
AI reshapes data privacy as firms shift to real-time defence
Last month
#
appsec
AI-driven cloud adoption is forcing firms to swap static privacy checklists for continuous, real-time defence of sensitive data flows.
Cloudbrink boosts AI security for hybrid enterprises
Last month
#
appsec
Cloudbrink adds Safe AI controls to its zero trust platform, securing hybrid enterprise use of AI agents and browser-based AI services.
Radware buys Pynt to bolster pre-production API security
Last month
#
appsec
Radware acquires Pynt to add pre-production testing and deliver unified lifecycle API security from design through to runtime defence.
Radware unveils cloud service for unified API security
Last month
#
appsec
Radware launches cloud-based API Security Service unifying discovery, posture management and runtime defence to counter evolving API threats.
Attackers target AI agents with prompt & tool hacks
Last month
#
appsec
Attackers are already exploiting AI agents, extracting hidden prompts, bypassing safety checks and abusing tools tied to data and systems.
Cobalt launches two-way Microsoft Teams pentesting tool
Last month
#
appsec
Cobalt debuts a two-way penetration testing integration for Microsoft Teams, promising faster remediation and real-time security collaboration.