AppSec stories
Appdome launches identity-first mobile API protection
Yesterday
#
virtualisation
#
firewalls
#
endpoint protection
Appdome unveils mobile API defence that checks app, device and session identity before granting access, targeting bot abuse and takeover attacks.
Capsule Security raises $7 million to guard AI agents
2 days ago
#
pam
#
cloud security
#
application security
Capsule Security emerges from stealth with $7 million backing to police AI agents at runtime as enterprises widen their use.
AI coding boom deepens cognitive debt, says Thoughtworks
3 days ago
#
devops
#
digital transformation
#
application security
Thoughtworks warns AI-assisted coding is swelling software complexity, as developers lean on older controls to curb security and oversight risks.
Cloudflare, Wiz link AI security tools for unified view
3 days ago
#
firewalls
#
data protection
#
digital transformation
Cloudflare and Wiz team up to map shadow AI risks across cloud estates and protect sensitive data as firms race to secure chatbot deployments.
OpenAI expands cyber access for verified defenders
3 days ago
#
application security
#
socs
#
physical security
OpenAI broadens Trusted Access for Cyber to verified defenders, giving vetted users GPT-5.4-Cyber for tougher security work and code analysis.
Sonatype warns of surge in trusted open-source malware
3 days ago
#
application security
#
devsecops
#
supply chain
Sonatype flags 21,764 malicious open-source packages in Q1 2026, with npm hit hardest as attackers used trusted workflows to steal secrets.
Forrester says Anthropic AI could break patch playbook
4 days ago
#
hybrid cloud
#
digital transformation
#
application security
Forrester warns Anthropic's Project Glasswing could overwhelm vulnerability management, as AI uncovers flaws faster than patching teams can respond.
Cloudsmith survey finds SBOM gaps before cyber law
Last week
#
devops
#
cloud security
#
application security
Cloudsmith survey finds most engineering teams still lack automated SBOM checks, leaving many unready for fast EU Cyber Resilience Act audits.
Permiso launches sandbox for AI agent skill security
Last week
#
firewalls
#
network security
#
cloud security
Permiso launches SandyClaw sandbox to detonate AI agent skills and expose hidden runtime risks before they reach enterprise systems.
F5 & Forcepoint come together to secure enterprise AI
This month
#
data protection
#
hybrid cloud
#
digital transformation
F5 and Forcepoint have teamed up to link data discovery with runtime controls, aiming to curb AI risks as enterprises move systems into production.
F5 & Forcepoint join forces on enterprise AI security
Last month
#
data protection
#
digital transformation
#
application security
F5 and Forcepoint team up to give enterprises continuous AI security, linking data discovery with runtime controls to reduce risk in production systems.
Miggo expands runtime defence for AI agents & tools
Last month
#
firewalls
#
network security
#
cloud security
Miggo extends its runtime security platform to map, monitor and rein in AI agents and MCP toolchains as live behaviour becomes attack focus.
NetRise launches Provenance to trace open source risk
Last month
#
devops
#
iot security
#
iot
NetRise unveils Provenance, a tool to trace open source maintainers and stop risky dependencies before they spread through software.
Novee launches AI red teaming tool for LLM app risks
Last month
#
devops
#
cloud security
#
application security
Novee unveils an autonomous AI red teaming tool to probe LLM apps for prompt injection, jailbreaks and other emerging security flaws.
Sonatype finds live data beats larger AI models on upgrades
Last month
#
devops
#
application security
#
supply chain
Sonatype says smaller AI tied to live software data can outsecure larger models on dependency upgrades, slashing risk and cost.
NSS Labs backs AI guardrail tests amid security fears
Last month
#
firewalls
#
devops
#
digital transformation
NSS Labs warns many enterprise AI guardrails fail basic security tests, urging independent, real-world validation of protections.
Cloudsmith adds controls to block risky dependencies
Last month
#
devops
#
cloud security
#
application security
Cloudsmith adds automated controls to quarantine and block risky dependencies, tightening enforcement on software supply chain security.
Red Hat finds cloud security incidents hit 97% of firms
Last month
#
data protection
#
hybrid cloud
#
cloud security
Red Hat reports 97% of organisations suffered cloud-native security incidents last year, exposing basic failings in configuration and governance.
Veracode launches Fix for open-source vulnerability repair
Last month
#
devops
#
application security
#
devsecops
Veracode unveils an AI-driven tool that automatically fixes open-source vulnerabilities, tackling mounting security debt in software supply chains.
UiPath Accelerates AI in Software Development and Testing
Last month
#
devops
#
digital transformation
#
application security
UiPath is pushing AI deeper into software testing, promising autonomous agents that transform quality assurance and developers' roles.