AppSec stories
Exploited software flaws are now overtaking stolen passwords as the main breach route, sharpening pressure on security teams to patch faster.
Enterprises can now trace hidden AI components in code to meet growing audit and compliance demands as production use outpaces governance.
Security chiefs are being given a framework to curb risks as AI spreads through coding, no-code tools and autonomous software workflows.
The tie-up gives NCC Group early access to GPT-5.5-Cyber, as OpenAI seeks trusted testers for defensive uses of its cyber tools.
Organisations risk missed exposures as cloud, APIs and AI systems change far faster than annual security checks can keep up.
Enterprise buyers are treating software supply chain security as a standalone priority as Gartner creates a dedicated Magic Quadrant for the category.
Users of Dify's cloud service could have had private chats and files exposed after Zafran Security disclosed four flaws in the AI platform.
The recognition underlines rising demand for tools that secure software builds before attackers can exploit open source dependencies and pipelines.
Security teams are being offered new tools to track shadow AI and block prompt injection as enterprises rush to deploy agents and models.
Growing AI use in coding is widening software risk, forcing security leaders to match training and controls to each adoption stage.
By focusing on evidence and small reversible changes, loop engineering could curb costly AI coding mistakes before they reach production.
Enterprise security teams gain a new AI-assisted way to spot exploitable code flaws, as IBM widens its cyber work with OpenAI.
The recognition comes as firms scramble to secure software pipelines, open-source code and AI assets against rising supply chain attacks.
The move aims to help defenders turn faster vulnerability discovery into working fixes, as OpenAI broadens access to its cyber tools and partners.
A single compromised laptop can expose thousands of live keys, according to GitGuardian's early field tests, as attacks shift to developer machines.
False negatives from automated scanning tools are fuelling a shift towards human-led AI security testing across large organisations.
Tech and software groups are most at risk as breaches, supplier access and stale credentials let attackers reach source code and customer data.
Researchers can now earn up to USD $6,000 for exposing flaws in Agoda's core web services, APIs and mobile app via HackerOne.
The deal gives customers red teaming and runtime protection for AI systems as enterprises rush to secure models and autonomous agents.
Continuous attack testing aims to help customers spot exploitable gaps before criminals do, including misconfigurations hiding outside core systems.