Application Security
Obsidian Security has developed a platform for governing AI agents across third-party applications.
Hi, what are you looking for?
As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.
Obsidian Security has developed a platform for governing AI agents across third-party applications.
Five years after the initial release, the refresh introduces new elements, removes others, and updates terminology.
Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days.
Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues.
It will provide the tools and channels to report, patch, and disclose open source software vulnerabilities.
The security defects allow unauthenticated users to take control of the open source software supply chain.
By continuously analyzing security, infrastructure, and governance data, TrustCloud aims to give CISOs a real-time view of application risk and board-ready assurance.
Over two dozen organizations built a shared platform to triage vulnerabilities, fix them, and secure the software before patches arrive.
Security teams need more than visibility into AI applications, they need a repeatable framework for monitoring, investigating, and defending them in production.
Atsign’s AI Architect applies cryptographic protections to agentic software development, aiming to prevent attackers from exploiting vulnerabilities by making application identities effectively invisible.
As AI shortens the path from vulnerability disclosure to exploitation, researchers disagree on whether the problem is inadequate security tools or inadequate operational control.
Fake automated commits injected GitHub Actions workflows containing payloads to steal credentials, CI secrets, keys, and tokens.
The company blocked over 1.1 billion accounts and $2.2 billion in potentially fraudulent transactions.
Digital.ai’s latest threat report warns that agentic AI has erased the distinction between emerging and primary targets, enabling attackers to strike mobile apps within...
The company is expanding its platform’s capabilities with the acquisition of SecureIQx and Korbit.ai.
Mitiga researchers say attackers can silently redirect Claude Code MCP traffic, intercept OAuth tokens, and maintain persistent access to connected SaaS platforms.