AppSec stories
Researchers can now earn up to USD $6,000 for exposing flaws in Agoda's core web services, APIs and mobile app via HackerOne.
Gaps in oversight leave most firms unable to see what AI is doing inside mobile apps, despite broad adoption and formal governance policies.
Security teams are being pushed to react faster as AI-assisted attacks widen the gap between exploit discovery, patching and live defence.
Security risks are rising as AI coding tools become routine, leaving many firms unable to track how machine-generated code reaches production.
Developers can now add authentication and access controls earlier in AI-built apps, as Ory's free plugins plug identity tools into coding agents.
More than half of engineering teams are now using AI to write code, but weak oversight is leaving security, dependency and performance risks in production.
Customers can now query and act on API security data in plain English, but every change still needs human approval before it is applied.
North American expansion is now being funded as the startup targets cloud risks introduced at the design stage, not after deployment.
Enterprises can now trace hidden AI components in code to meet growing audit and compliance demands as production use outpaces governance.
Security chiefs are being given a framework to curb risks as AI spreads through coding, no-code tools and autonomous software workflows.
The tie-up gives NCC Group early access to GPT-5.5-Cyber, as OpenAI seeks trusted testers for defensive uses of its cyber tools.
Organisations risk missed exposures as cloud, APIs and AI systems change far faster than annual security checks can keep up.
Enterprise buyers are treating software supply chain security as a standalone priority as Gartner creates a dedicated Magic Quadrant for the category.
Users of Dify's cloud service could have had private chats and files exposed after Zafran Security disclosed four flaws in the AI platform.
The recognition underlines rising demand for tools that secure software builds before attackers can exploit open source dependencies and pipelines.
The new planning tool aims to cut bugs and security flaws before code is written, as the startup's seed funding reaches USD $17 million.
Enterprise customers face growing risks as autonomous software gains access to internal systems, prompting fresh demand for agent security tools.
The pact aims to help enterprises patch vulnerable open source code faster without forcing disruptive upgrades to production systems.
False negatives from automated scanning tools are fuelling a shift towards human-led AI security testing across large organisations.
Tech and software groups are most at risk as breaches, supplier access and stale credentials let attackers reach source code and customer data.