Application Security

Rethinking Application Security for the AI Era

Rethinking Application Security for the AI Era 2026-08-24 at 13:00 By Joshua Goldfarb As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. The post Rethinking Application Security for the AI Era appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Rethinking Application Security for the AI Era Read More »

Virtual Event Today: CodeSecCon – Secure Your Code and Applications

Virtual Event Today: CodeSecCon – Secure Your Code and Applications 2026-08-19 at 16:36 By SecurityWeek News CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained. The post Virtual Event Today: CodeSecCon – Secure Your Code and Applications appeared first on SecurityWeek. This

Virtual Event Today: CodeSecCon – Secure Your Code and Applications Read More »

Mozilla Issues New Firefox GPG Key Following Exposure

Mozilla Issues New Firefox GPG Key Following Exposure 2026-08-11 at 09:16 By Eduard Kovacs The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it. The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Mozilla Issues New Firefox GPG Key Following Exposure Read More »

Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds

Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds 2026-08-10 at 17:19 By Kevin Townsend The startup analyzes subtle telemetry signals to detect attacks that traditional security tools cannot see inside accelerator-powered AI infrastructure. The post Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds appeared first on SecurityWeek. This article is an

Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds Read More »

Chainloop: Open-source evidence store and policy engine for the software supply chain

Chainloop: Open-source evidence store and policy engine for the software supply chain 2026-08-10 at 08:30 By Sinisa Markovic Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable

Chainloop: Open-source evidence store and policy engine for the software supply chain Read More »

Obsidian Security Raises $85 Million at $1.1 Billion Valuation

Obsidian Security Raises $85 Million at $1.1 Billion Valuation 2026-08-04 at 15:00 By SecurityWeek News Obsidian Security has developed a platform for governing AI agents across third-party applications. The post Obsidian Security Raises $85 Million at $1.1 Billion Valuation appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Obsidian Security Raises $85 Million at $1.1 Billion Valuation Read More »

Qodana 2026.2 adds post-quantum crypto checks for JVM code

Qodana 2026.2 adds post-quantum crypto checks for JVM code 2026-08-03 at 14:21 By Anamarija Pogorelec Qodana 2026.2 shipped with new security inspections, published benchmark results, post-quantum cryptography checks, and coverage reporting that no longer has to be pointed at the reports. The security work sits in the .NET linter and runs by default. Qodana tracks

Qodana 2026.2 adds post-quantum crypto checks for JVM code Read More »

New GitHub, PyPI Policies Boost Supply Chain Security

New GitHub, PyPI Policies Boost Supply Chain Security 2026-07-27 at 17:26 By Ionut Arghire Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days. The post New GitHub, PyPI Policies Boost Supply Chain Security appeared first on SecurityWeek. This article is an excerpt from

New GitHub, PyPI Policies Boost Supply Chain Security Read More »

Vibe-Coded Apps Riddled With Exploitable Security Flaws

Vibe-Coded Apps Riddled With Exploitable Security Flaws 2026-07-22 at 16:00 By Kevin Townsend Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues. The post Vibe-Coded Apps Riddled With Exploitable Security Flaws appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Vibe-Coded Apps Riddled With Exploitable Security Flaws Read More »

20 open-source cybersecurity tools to keep your team ready for anything

20 open-source cybersecurity tools to keep your team ready for anything 2026-07-08 at 08:30 By Anamarija Pogorelec AI is changing how security teams find vulnerabilities, analyze code, test applications, and protect infrastructure. Developers are building tools to secure AI systems themselves, from coding agents and memory protection to model exposure discovery. This roundup covers recent

20 open-source cybersecurity tools to keep your team ready for anything Read More »

Nika: Open-source code analysis tool

Nika: Open-source code analysis tool 2026-07-01 at 09:00 By Mirko Zorz Many serious security bugs in web applications sit across several files at once. Request data enters through a controller, moves through data objects and service layers, and turns dangerous only when it reaches a sensitive operation such as a database query or a file

Nika: Open-source code analysis tool Read More »

Linux Foundation Unveils New Open Source Security Project Akrites

Linux Foundation Unveils New Open Source Security Project Akrites 2026-06-26 at 14:28 By Ionut Arghire It will provide the tools and channels to report, patch, and disclose open source software vulnerabilities. The post Linux Foundation Unveils New Open Source Security Project Akrites appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Linux Foundation Unveils New Open Source Security Project Akrites Read More »

Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking

Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking 2026-06-24 at 13:55 By Ionut Arghire The security defects allow unauthenticated users to take control of the open source software supply chain. The post Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking Read More »

Tech Coalition ‘Athena’ Targets OSS Vulnerabilities Ahead of Disclosure

Tech Coalition ‘Athena’ Targets OSS Vulnerabilities Ahead of Disclosure 2026-06-16 at 12:39 By Ionut Arghire Over two dozen organizations built a shared platform to triage vulnerabilities, fix them, and secure the software before patches arrive. The post Tech Coalition ‘Athena’ Targets OSS Vulnerabilities Ahead of Disclosure appeared first on SecurityWeek. This article is an excerpt

Tech Coalition ‘Athena’ Targets OSS Vulnerabilities Ahead of Disclosure Read More »

After AI Reaches Production: 12 Ways Security Teams Can Take Control

After AI Reaches Production: 12 Ways Security Teams Can Take Control 2026-06-10 at 14:22 By Joshua Goldfarb Security teams need more than visibility into AI applications, they need a repeatable framework for monitoring, investigating, and defending them in production. The post After AI Reaches Production: 12 Ways Security Teams Can Take Control appeared first on

After AI Reaches Production: 12 Ways Security Teams Can Take Control Read More »

New Platform Uses Cryptographic Invisibility to Protect AI-Built Applications

New Platform Uses Cryptographic Invisibility to Protect AI-Built Applications 2026-06-09 at 18:18 By Kevin Townsend Atsign’s AI Architect applies cryptographic protections to agentic software development, aiming to prevent attackers from exploiting vulnerabilities by making application identities effectively invisible. The post New Platform Uses Cryptographic Invisibility to Protect AI-Built Applications appeared first on SecurityWeek. This article

New Platform Uses Cryptographic Invisibility to Protect AI-Built Applications Read More »

Known vulnerabilities behind most application security incidents

Known vulnerabilities behind most application security incidents 2026-06-03 at 07:40 By Anamarija Pogorelec Eight in ten organizations took an application security hit during the past year tied to a vulnerability their team had already cataloged, according to a survey of 902 IT and security professionals conducted by the Cloud Security Alliance. The pattern points to

Known vulnerabilities behind most application security incidents Read More »

Two New Reports Offer Competing Explanations for Cybersecurity’s Growing Crisis

Two New Reports Offer Competing Explanations for Cybersecurity’s Growing Crisis 2026-06-02 at 19:47 By Kevin Townsend As AI shortens the path from vulnerability disclosure to exploitation, researchers disagree on whether the problem is inadequate security tools or inadequate operational control. The post Two New Reports Offer Competing Explanations for Cybersecurity’s Growing Crisis appeared first on

Two New Reports Offer Competing Explanations for Cybersecurity’s Growing Crisis Read More »

Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack

Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack 2026-05-25 at 10:56 By Ionut Arghire Fake automated commits injected GitHub Actions workflows containing payloads to steal credentials, CI secrets, keys, and tokens. The post Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack appeared first on SecurityWeek. This article is an excerpt from

Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack Read More »

Scroll to Top