AppSec stories
A JFrog study says weak package and container defences are leaving Indian organisations exposed as AI use adds new checks for developers.
The new integration keeps passwords out of prompts and repos, reducing the risk of leaks as AI coding agents move into production workflows.
Security teams can now assess network, web and AI weaknesses together as Terra Security broadens continuous validation to infrastructure.
Independent security checks are gaining urgency as fast-growing AI and software firms face rising scrutiny from customers, partners and regulators.
Exposed systems are becoming the main target, as Rapid7 says flaws were used in 38% of incidents and patch windows shrank to five days.
The release gives security teams and developers new controls for credentials, merge requests and supply chain oversight as AI use grows.
Members are backing tougher open source security as OpenSSF expands guidance on regulation, Python coding and AI-driven vulnerability tools.
Most enterprise access still sits outside formal controls, leaving AI agents and unmanaged accounts to widen security and compliance risks.
Businesses can now run Claude-powered agents in isolated Cloudflare sandboxes, with tighter controls for private data, audit trails and scaling.
Many firms lack visibility over AI-written software, raising maintainability and security risks as adoption of coding assistants accelerates.
The findings suggest AI-assisted bug hunting is edging closer to practical exploitation, raising the stakes for software teams racing to patch flaws.
Enterprises are testing only about 32% of their attack surface, leaving many assets outside regular security checks as threats grow faster.
Security teams may cut backlogs as validated HackerOne flaws are mapped into Wiz, linking exploit evidence to cloud assets for faster prioritisation.
Security teams can now rank cloud flaws by exploitability and impact, as validated HackerOne reports feed directly into Wiz's risk graph.
Security teams under pressure to prove real exploitability can now test live production systems for attack paths rather than theoretical flaws.
Security teams face new risks from AI coding tools as Cycode adds controls for prompts, generated code and unauthorised model use.
Security teams face a broader threat as criminals and state-backed actors use generative AI to speed hacks, phishing and malware.
MSPs will gain a single platform for cloud threat detection as the deal widens WatchGuard's reach into identity and SaaS security.
Organisations using AI in software development will get training on secure coding and governance as vulnerabilities and data risks mount.
It aims to cut alert fatigue by using runtime data to validate threats, prioritise real risks and guide fixes across cloud and AI systems.