AppSec stories
Smaller firms can now run web app pentests in hours, as Intruder's AI service cuts costs to a fraction of manual reviews.
Security teams could cut testing delays to hours as Intruder's AI tool scans web apps for flaws from source code access.
Developers may get patched code faster as Google's preview agent scans repositories, tests exploits and drafts fixes for review.
Security teams could cut hours from patching work as open-weight Antares models narrow flaws to the relevant code segment.
Developers using AI assistants could face stolen credentials and poisoned repositories as the worm hides inside normal coding workflows.
The tool aims to help developers cut vulnerability backlogs and reach no exploitable flaws within 90 days as AI coding expands risk.
Security teams can now rank code flaws against wider business risk as Tenable One links static vulnerability data with cloud, identity and attack-path exposure.
Security teams are being warned to keep humans and strict controls in place as AI agents can miss context and leak sensitive code.
Defenders could gain a faster edge against AI-driven attacks as Google Cloud ties Gemini, Wiz, CodeMender and Mandiant into one platform.
The update aims to cut review bottlenecks by auto-fixing vulnerable dependencies and surfacing code flaws scanners often miss.
Security teams can now trace how one SAP flaw could spread across finance, payroll and supply chains, with access tightly restricted.
Developers face earlier checks on risky open-source dependencies as AI coding tools speed up software assembly and raise supply chain concerns.
Malicious package advisories jumped from 21 in 2023 to 1,576 in 2025, as attackers increasingly target developers before code reaches production.
Exposed serverless apps can let attackers steal tokens, read secrets and take over cloud projects if weak code is left unpatched.
Security teams can now rank code flaws against cloud and identity risks after Tenable folded application security data into its exposure platform.
Broader coverage in Mexico and Milan aims to cut latency for mobile security checks as fake app traffic grows more sophisticated.
Nearly half of commerce traffic across Akamai's network came from AI bots by late 2025, raising fraud and DDoS risks for retailers.
Only 8% of organisations have agentic AI in production, highlighting the governance gap Harness aims to close with its new tools.
Businesses using AI coding tools face repeatable security gaps, as the new index found an average 15 vulnerabilities in each codebase.
Businesses may get security test results in hours as ITSEC Asia's new platform flags risks and keeps human consultants in the loop.