AppSec stories
Wiz expands AI security coverage across cloud & edge
Today
#
hyperscale
#
cloud security
#
edge computing
Wiz adds Red Agent preview and wider tools for AI code, Databricks, multicloud services and edge risk across cloud environments.
CrowdStrike launches AI security coalition with partners
Today
#
cloud security
#
application security
#
devsecops
CrowdStrike unveils AI security coalition with Accenture, EY, IBM Cybersecurity Services, Kroll and OpenAI to spot and fix code flaws faster.
Lineaje survey finds AI code confidence outpaces visibility
Yesterday
#
digital transformation
#
application security
#
devsecops
Lineaje survey flags a widening governance gap as most firms use AI-generated code, yet few can fully see or track it.
Claude Code can leak secrets in public npm packages
Yesterday
#
data protection
#
application security
#
devsecops
Check Point says Anthropic's Claude Code can quietly stash credentials in .claude/settings.local.json, which may be published in public npm packages.
Check Point teams with Google Cloud on AI agent security
Yesterday
#
firewalls
#
data protection
#
digital transformation
Check Point and Google Cloud add governance and live monitoring to enterprise AI agents as firms race to secure autonomous workflows.
AI coding speeds up, but security teams fall behind
Yesterday
#
devops
#
digital transformation
#
application security
AI coding accelerates software delivery, but security teams struggle to keep up as more code, alerts and manual checks pile up.
Tenable flags Microsoft GitHub workflow flaw risking code
Yesterday
#
cloud security
#
application security
#
physical security
Tenable warns that a flaw in Microsoft's Windows-driver-samples GitHub workflow could let attackers run code and steal secrets.
Zscaler joins Anthropic Project Glasswing on cyber AI
2 days ago
#
firewalls
#
vpns
#
network security
Zscaler joins Anthropic's Project Glasswing to test Claude Mythos Preview in software scans, as the firm pushes zero trust against AI-driven attacks.
HackerOne launches h1 Validation to tackle AI flaws
2 days ago
#
devops
#
digital transformation
#
application security
HackerOne unveils h1 Validation as vulnerability reports surge 76% and AI tools speed up discovery, leaving firms struggling to triage real threats.
Chainguard & Cursor tackle AI code supply chain risks
2 days ago
#
devops
#
application security
#
devsecops
Chainguard and Cursor strike partnership to embed verified open source dependencies into AI coding, aiming to curb supply chain risks at machine speed.
Tenable flags Microsoft GitHub workflow flaw exposing code
2 days ago
#
devops
#
cloud security
#
application security
Tenable warns a GitHub Actions bug in Microsoft's Windows-driver-samples repo could let attackers run code and steal secrets via public issues.
AI vulnerability discovery forces boards to rethink cyber risk
3 days ago
#
data protection
#
application security
#
iam
AI models that can hunt and chain software flaws are forcing boards to rethink cyber defences, while scrutiny grows over Anthropic's MCP design risks.
LangWatch launches open-source tool for AI red-teaming
3 days ago
#
data protection
#
devops
#
data analytics
LangWatch releases open-source AI red-teaming framework to expose hidden vulnerabilities in production agents through multi-turn attack simulations.
Appdome launches identity-first mobile API protection
Last week
#
virtualisation
#
firewalls
#
endpoint protection
Appdome unveils mobile API defence that checks app, device and session identity before granting access, targeting bot abuse and takeover attacks.
OpenAI broadens AI cyber tools as arms race heats up
Last week
#
data protection
#
ransomware
#
application security
OpenAI widens AI cyber tools to verified users as Anthropic keeps rivals guessing, fuelling debate over who gains an edge in the ransomware fight.
Capsule Security raises $7 million to guard AI agents
Last week
#
pam
#
cloud security
#
application security
Capsule Security emerges from stealth with $7 million backing to police AI agents at runtime as enterprises widen their use.
AI coding boom deepens cognitive debt, says Thoughtworks
Last week
#
devops
#
digital transformation
#
application security
Thoughtworks warns AI-assisted coding is swelling software complexity, as developers lean on older controls to curb security and oversight risks.
Cloudflare, Wiz link AI security tools for unified view
Last week
#
firewalls
#
data protection
#
digital transformation
Cloudflare and Wiz team up to map shadow AI risks across cloud estates and protect sensitive data as firms race to secure chatbot deployments.
OpenAI expands cyber access for verified defenders
Last week
#
application security
#
socs
#
physical security
OpenAI broadens Trusted Access for Cyber to verified defenders, giving vetted users GPT-5.4-Cyber for tougher security work and code analysis.
Sonatype warns of surge in trusted open-source malware
Last week
#
application security
#
devsecops
#
supply chain
Sonatype flags 21,764 malicious open-source packages in Q1 2026, with npm hit hardest as attackers used trusted workflows to steal secrets.