AppSec stories
Stolen credentials can become an operational foothold within hours, leaving annual assessments too slow to catch the real attack paths.
Buyers of AI tools now have a benchmark to judge testing providers, as CREST's new standard targets gaps in assurance and due diligence.
As attackers use AI to speed up phishing and malware, companies are being told that multi-factor authentication and patching matter more than ever.
Security teams could cut exposure faster as the model helps rank exploitable flaws and apply temporary defences before vendor fixes arrive.
Regulated teams can now keep AI processing inside GitLab Dedicated, with new secret handling, spending caps and security fixes added in 19.3.
Basic security lapses are leaving web apps exposed, with Barracuda saying routine misconfigurations account for most of 20 flaws per site.
Misconfigured models are giving attackers a fresh route into cloud systems, raising the risk of data theft and service compromise.
The new tool aims to catch Bitcoin software flaws between formal audits after a regression led to more than USD $116 million stolen.
Developers can now scan C code earlier in the process, as Endor Labs says its buildless AI SAST found 96 of 102 known bugs in tests.
Organisations using Microsoft automation can now keep credentials out of scripts, reducing the risk of exposed secrets in cloud workflows.
In two days, the system uncovered more than 100 critical bugs in stolen code repositories, outpacing manual review and aiding incident response.
Unauthorised access could let attackers send arbitrary commands to spacecraft and instruments via NASA's AIT-GUI console, now fixed in version 2.5.2.
Security teams are drowning in AI-generated bug reports, and 11 early users are already testing a system that filters the noise.
Verified access to Anthropic's Claude models should sharpen ArmorCode's exploitability scoring as security teams race to cut alert noise.
Blockchain apps risk losing new users unless developers simplify approvals and signing while keeping private keys and transactions secure.
Businesses facing faster AI-driven attacks can now use Visa's updated framework and advisory services to cut vulnerability fixes from weeks to hours.
Security teams gain a single workflow to validate real exploit paths as BreachLock folds autonomous testing into its wider platform.
Rising use of AI coding tools is widening software supply-chain risks for businesses across the Middle East, Türkiye and Africa.
The new tools aim to cut the gap between finding a flaw and fixing it from weeks to hours as attacks accelerate.
UK security leaders are warning that AI-generated code is outpacing controls, with a quarter already seeing incidents from flaws it introduced.