Application Security
GitHub has made AI-powered Copilot Autofix generally available to help developers fix code vulnerabilities faster.
Hi, what are you looking for?
As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.
GitHub has made AI-powered Copilot Autofix generally available to help developers fix code vulnerabilities faster.
Vulnerabilities in Homebrew could have allowed attackers to load executable code and modify binary builds, security audit finds.
Researchers discovered and published details of an XSS attack that could potentially impact millions of websites around the world.
Heeler Security has raised $8.5 million in seed funding for its ProductDNA application security technology.
CISA says a SILENTSHIELD red team assessment found gaping holes in the security posture of a federal civilian executive branch organization.
Patch Tuesday: Enterprise software vendor SAP releases patches for high-severity vulnerabilities in multiple products and tools.
EVA Information Security has shared details on three CocoaPods vulnerabilities impacting millions of macOS and iOS applications.
The British company behind the popular Burp Suite pen-test utilities has banked a massive $112 million investment from Brighton Park Capital.
Most critical open source software contains code written in a memory unsafe language, US, Australian, and Canadian government agencies warn.
Aqua Security shows that code in repositories remains accessible even after being deleted or overwritten, continuing to leak secrets.
A critical vulnerability tracked as CVE-2024-34359 and dubbed Llama Drama can allow hackers to target AI product developers.
Adobe is providing incentives for bug bounty hackers to report security flaws in its implementation of Content Credentials and Adobe Firefly.
Malicious hackers are targeting SAP applications at an alarming pace, according to warnings from Onapsis and Flashpoint.
YL Ventures leads an early stage funding round for Miggo Security, a Tel Aviv startup working on application detection and response technology.
NightVision, an early stage startup in the application security testing space, has raised $5.4 million in seed funding.
A critical vulnerability in multiple programming languages allows attackers to inject commands in Windows applications.
A cross-site scripting vulnerability in the WP-Members Membership plugin could allow attackers to inject scripts into user profile pages.
Veracode announces a deal to acquire Longbow Security, a Texas seed-stage startup working on automated root cause analysis technology.
BlueFlag Security emerges from stealth mode with $11.5 million in a seed funding round led by Maverick Ventures and Ten Eleven Ventures.
GitHub’s code scanning autofix delivers remediation suggestions for two-thirds of the identified vulnerabilities.