Application Security
Agentic AI can be expensive to use, causing further and unpredictable pressure on tight budgets.
Hi, what are you looking for?
As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.
Agentic AI can be expensive to use, causing further and unpredictable pressure on tight budgets.
A long-lived NPM access token was used to bypass the GitHub Actions OIDC-based CI/CD publishing workflow and push backdoored package versions.
After validating stolen credentials using TruffleHog, the hacking group started AWS services enumeration and lateral movement activities.
The startup has built an edge security management (ESM) platform, an AI engine atop the entire edge security stack.
The hackers compromised GitHub Action tags, then shifted to NPM, Docker Hub, VS Code, and PyPI, and teamed with Lapsus$.
Raven’s platform observes applications at runtime to detect anomalous behavior and prevent cyberattacks.
New research shows attackers increasingly abusing APIs at machine speed as AI-driven systems widen exposure and amplify impact.
The startup relies on AI agents to identify software vulnerabilities and validate them before reporting.
The company will use the investment to expand its R&D team and operations, deepen platform capabilities, and scale go-to-market presence.
VS Code-integrated configuration files are automatically executed in Codespaces when the user opens a repository or pull request.
Rein aims to close the production visibility gap by stopping attacks inside the application runtime.
API cybersecurity will be a ping pong ball, battered between the rackets of AI-assisted attackers and AI-assisted defenders.
Vibe coding generates a curate’s egg program: good in parts, but the bad parts affect the whole program.
The developer security company has raised a total of more than $84 million in funding.
The worm exposed Trust Wallet’s Developer GitHub secrets, allowing attackers to publish a backdoor extension and steal funds from 2,520 wallets.
XSS remains the top software weakness, followed by SQL injection and CSRF. Buffer overflow issues and improper access control make it to top 25.
A researcher has pointed out that only instances using a newer feature are impacted by CVE-2025-55182.
The cybersecurity startup embeds AI agents into widely used tools to identify design flaws and eliminate them early.
Learn why legacy approaches fail to stop modern API threats and show how dedicated API security delivers the visibility, protection, and automation needed to...
A financially motivated threat actor automated the package publishing process in a coordinated tea.xyz token farming campaign.