Application Security

Virtual Event Today: Attack Surface Management Summit

Virtual Event Today: Attack Surface Management Summit 2026-09-16 at 17:35 By SecurityWeek News Join SecurityWeek today for a virtual summit exploring the strategies and tools organizations need to discover, prioritize, and defend their expanding attack surfaces. The post Virtual Event Today: Attack Surface Management Summit appeared first on SecurityWeek. This article is an excerpt from […]

Virtual Event Today: Attack Surface Management Summit Read More »

This Key Will Self-Destruct: An Open Standard for Revocable API Keys

This Key Will Self-Destruct: An Open Standard for Revocable API Keys 2026-09-09 at 13:00 By Matt Honea Every leaked credential should be dead, or dying, within sixty seconds of being found. Here’s a proposal to make that the default. The post This Key Will Self-Destruct: An Open Standard for Revocable API Keys appeared first on […]

This Key Will Self-Destruct: An Open Standard for Revocable API Keys Read More »

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites 2026-09-05 at 16:00 By Ionut Arghire Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first on SecurityWeek. This article […]

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites Read More »

AI AppSec tools agree on just 5% of security findings

AI AppSec tools agree on just 5% of security findings 2026-08-31 at 08:23 By Sinisa Markovic Software vulnerabilities are turning into exploits within hours, and application security teams carry patch backlogs that go back years. Top types of viable application attacks (Source: Contrast Security) Contrast Security’s AppSec Overflow 2026 report draws on telemetry collected from […]

AI AppSec tools agree on just 5% of security findings Read More »

Rethinking Application Security for the AI Era

Rethinking Application Security for the AI Era 2026-08-24 at 13:00 By Joshua Goldfarb As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. The post Rethinking Application Security for the AI Era appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Rethinking Application Security for the AI Era Read More »

Virtual Event Today: CodeSecCon – Secure Your Code and Applications

Virtual Event Today: CodeSecCon – Secure Your Code and Applications 2026-08-19 at 16:36 By SecurityWeek News CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained. The post Virtual Event Today: CodeSecCon – Secure Your Code and Applications appeared first on SecurityWeek. This […]

Virtual Event Today: CodeSecCon – Secure Your Code and Applications Read More »

Mozilla Issues New Firefox GPG Key Following Exposure

Mozilla Issues New Firefox GPG Key Following Exposure 2026-08-11 at 09:16 By Eduard Kovacs The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it. The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Mozilla Issues New Firefox GPG Key Following Exposure Read More »

Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds

Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds 2026-08-10 at 17:19 By Kevin Townsend The startup analyzes subtle telemetry signals to detect attacks that traditional security tools cannot see inside accelerator-powered AI infrastructure. The post Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds appeared first on SecurityWeek. This article is an […]

Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds Read More »

Chainloop: Open-source evidence store and policy engine for the software supply chain

Chainloop: Open-source evidence store and policy engine for the software supply chain 2026-08-10 at 08:30 By Sinisa Markovic Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable […]

Chainloop: Open-source evidence store and policy engine for the software supply chain Read More »

Obsidian Security Raises $85 Million at $1.1 Billion Valuation

Obsidian Security Raises $85 Million at $1.1 Billion Valuation 2026-08-04 at 15:00 By SecurityWeek News Obsidian Security has developed a platform for governing AI agents across third-party applications. The post Obsidian Security Raises $85 Million at $1.1 Billion Valuation appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Obsidian Security Raises $85 Million at $1.1 Billion Valuation Read More »

Qodana 2026.2 adds post-quantum crypto checks for JVM code

Qodana 2026.2 adds post-quantum crypto checks for JVM code 2026-08-03 at 14:21 By Anamarija Pogorelec Qodana 2026.2 shipped with new security inspections, published benchmark results, post-quantum cryptography checks, and coverage reporting that no longer has to be pointed at the reports. The security work sits in the .NET linter and runs by default. Qodana tracks […]

Qodana 2026.2 adds post-quantum crypto checks for JVM code Read More »

New GitHub, PyPI Policies Boost Supply Chain Security

New GitHub, PyPI Policies Boost Supply Chain Security 2026-07-27 at 17:26 By Ionut Arghire Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days. The post New GitHub, PyPI Policies Boost Supply Chain Security appeared first on SecurityWeek. This article is an excerpt from […]

New GitHub, PyPI Policies Boost Supply Chain Security Read More »

Vibe-Coded Apps Riddled With Exploitable Security Flaws

Vibe-Coded Apps Riddled With Exploitable Security Flaws 2026-07-22 at 16:00 By Kevin Townsend Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues. The post Vibe-Coded Apps Riddled With Exploitable Security Flaws appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Vibe-Coded Apps Riddled With Exploitable Security Flaws Read More »

20 open-source cybersecurity tools to keep your team ready for anything

20 open-source cybersecurity tools to keep your team ready for anything 2026-07-08 at 08:30 By Anamarija Pogorelec AI is changing how security teams find vulnerabilities, analyze code, test applications, and protect infrastructure. Developers are building tools to secure AI systems themselves, from coding agents and memory protection to model exposure discovery. This roundup covers recent […]

20 open-source cybersecurity tools to keep your team ready for anything Read More »

Nika: Open-source code analysis tool

Nika: Open-source code analysis tool 2026-07-01 at 09:00 By Mirko Zorz Many serious security bugs in web applications sit across several files at once. Request data enters through a controller, moves through data objects and service layers, and turns dangerous only when it reaches a sensitive operation such as a database query or a file […]

Nika: Open-source code analysis tool Read More »

Linux Foundation Unveils New Open Source Security Project Akrites

Linux Foundation Unveils New Open Source Security Project Akrites 2026-06-26 at 14:28 By Ionut Arghire It will provide the tools and channels to report, patch, and disclose open source software vulnerabilities. The post Linux Foundation Unveils New Open Source Security Project Akrites appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Linux Foundation Unveils New Open Source Security Project Akrites Read More »

Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking

Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking 2026-06-24 at 13:55 By Ionut Arghire The security defects allow unauthenticated users to take control of the open source software supply chain. The post Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking Read More »

Tech Coalition ‘Athena’ Targets OSS Vulnerabilities Ahead of Disclosure

Tech Coalition ‘Athena’ Targets OSS Vulnerabilities Ahead of Disclosure 2026-06-16 at 12:39 By Ionut Arghire Over two dozen organizations built a shared platform to triage vulnerabilities, fix them, and secure the software before patches arrive. The post Tech Coalition ‘Athena’ Targets OSS Vulnerabilities Ahead of Disclosure appeared first on SecurityWeek. This article is an excerpt […]

Tech Coalition ‘Athena’ Targets OSS Vulnerabilities Ahead of Disclosure Read More »

After AI Reaches Production: 12 Ways Security Teams Can Take Control

After AI Reaches Production: 12 Ways Security Teams Can Take Control 2026-06-10 at 14:22 By Joshua Goldfarb Security teams need more than visibility into AI applications, they need a repeatable framework for monitoring, investigating, and defending them in production. The post After AI Reaches Production: 12 Ways Security Teams Can Take Control appeared first on […]

After AI Reaches Production: 12 Ways Security Teams Can Take Control Read More »

Scroll to Top