< ciso
brief />
Tag Banner

All news with #appsec tag

40 articles

AWS Continuum Adds CI/CD Integrated Pentesting

🛠️ AWS Continuum for Penetration Testing (formerly AWS Security Agent) now offers public preview CI/CD integration that makes penetration testing a deploy-time event. The service delivers findings—including severity, affected endpoints, and remediation guidance—directly in pipeline output while avoiding meaningful delays for non-security changes. Teams can paste an auto-generated pipeline snippet into existing workflows and complete setup in under five minutes, with application context bootstrapped automatically on first run.
read more →

Cloudflare launches Vulnerability Discovery and Remediation

🔍 Cloudflare is offering early access to Vulnerability Discovery and Remediation, a managed service that scans authorized customer codebases using OpenAI Daybreak models (including GPT-5.6 Cyber) to find and prioritize vulnerabilities. The service correlates source findings with production traffic, WAF signals, and security events to produce prioritized fixes and scoped WAF mitigations. Customers review proposed patches and rules before any change is made.
read more →

Black Hat roundup: Security vendors and AI trends

🔍 Andy Ellis reviews the vendor landscape at Black Hat, highlighting pervasive AI influence across booths and product messaging. He notes that while many vendors emphasize AI in Identity, SaaS, AppSec, and Data, nearly half did not explicitly reference agents or AI in their taglines. Ellis also identifies a market trichotomy: tools that report risk, tools that stop adversaries, and tools that prevent incidents, with diagnostic tools arguably overrepresented.
read more →

AI-Driven Development Raises App Vulnerability Risk

🔍 Sonatype finds enterprise applications now contain 4.31 times more critical and high-severity vulnerabilities since AI-driven software development accelerated. The firm analyzed four years of development data and reports application creation has increased nearly fivefold in the AI era. While the median age of unresolved vulnerabilities has fallen 59%, indicating faster fixes, the growth in risk outpaces traditional security processes.
read more →

AWS integrates Continuum into developer code workflows

🔒 AWS announced integrations that extend AWS Continuum into developer coding environments by partnering with Anthropic and OpenAI. The Preview of Continuum for code vulnerabilities delivers on-demand vulnerability discovery, contextual prioritization, sandbox validation, and remediation directly within coding assistants like Claude Code, Codex, and Kiro. Continuum orchestrates multiple models and tool integrations as a harness to select the best model per task and return prioritized, contextual fixes to developers, collapsing multi-team workflows into a single outcome.
read more →

Control Framework for Secure AI Coding Agents

🔒 This post presents an AppSec control framework for AI coding agents that balances developer productivity with risk management. It organizes controls into two pillars: author-time (shaping agent output in the IDE) and build-time (verifying and gating changes in the pipeline). The framework is tool- and cloud-agnostic and recommends deterministic, non-deterministic, and human controls to mitigate risks like prompt injection, insecure defaults, dependency issues, and overbroad access.
read more →

Google launches enterprise-ready CodeMender agent

🛡️ Google has made CodeMender available as a fully managed AI code security agent for enterprise customers via the Gemini Enterprise Agent Platform and AI Threat Defense. Originally a DeepMind research project, CodeMender now builds and runs PoC exploits in sandboxes, proposes tested fixes into pipelines, and offers multiple Gemini model options for cost and coverage balance. Features include secure traffic routing, data isolation, zero code retention and integrations with tools like VS Code and Antigravity.
read more →

CodeMender brings AI-driven code scanning and remediation

🛡️ CodeMender is a managed code security agent now available in preview, offering automated scanning and remediation using Google DeepMind–tuned models via the Gemini Enterprise Agent Platform or as part of AI Threat Defense. It prioritizes fixes by exploitability, runs proof-of-concept exploits in customer-managed sandboxes, and generates validated patches that integrate into developer workflows. The agent supports multiple languages, integrates with CI/CD and IDEs, and enforces enterprise-grade governance and data controls.
read more →

AWS launches Continuum to manage code vulnerabilities

🛡️ AWS has introduced Continuum, a new platform that manages code vulnerabilities across discovery, prioritization, validation and remediation. Launched at AWS Summit New York on June 17, Continuum ingests both structured and unstructured data from an organization’s environment and begins in a human-supervised "learn mode." The platform includes the AWS Security Agent and features for pen testing, code scanning and threat modelling, with outputs in STRIDE format.
read more →

AWS Continuum: Machine‑Speed Code Vulnerability Security

🛡️ AWS announces Continuum for code vulnerabilities in gated preview, designed to manage the full lifecycle of code vulnerabilities at machine speed. The service reasons over structured AWS data and unstructured organizational context, is model‑agnostic, and operates in continuous phases from discovery to remediation. It begins in a human‑in‑the‑loop learn mode and can be graduated to enforce mode for automated remediation, and incorporates pen testing, code scanning, and threat modeling capabilities.
read more →

AWS Security Agent adds Kiro and Claude Code support

🔒 AWS Security Agent (now part of AWS Continuum) adds support for Kiro and Claude Code, enabling developers to trigger security scans directly from their development environment. The agent now validates code scanner findings by simulating exploits in a sandbox to provide proof of exploit, reducing false positives and improving prioritization. Integrations include GitLab.com, GitLab Self Managed, GitHub Enterprise, Bitbucket, and Confluence, and features are available in all supported regions.
read more →

AWS introduces continuous modernization for codebases

🔍 AWS Transform today launched a Preview of continuous modernization that autonomously detects, prioritizes, and remediates technical debt across enterprise software portfolios. The capability brings visibility across thousands of repositories, supports assessments like agentic and modernization readiness, and integrates with AWS Security Agent to find and fix source code vulnerabilities. Customers can connect repositories from GitHub, GitLab, Bitbucket, and run analyses via the web console, CLI, Transform Kiro, or coding agents, with job state synchronized across surfaces. The service is available in US East (N. Virginia) and Europe (Frankfurt) regions.
read more →

UK government patches 400+ vulnerabilities via AI

🔎 The UK government's GC3 ran weekly in-person hackathons using frontier AI models to scan public code repositories across nine departments, identifying 407 findings including authentication bypasses, data exposure and remote code execution. Teams built diverse pipelines combining models and traditional tools like Gitleaks, Trivy and Semgrep, and all exploitable critical and high-risk issues were remediated. The initiative highlighted the benefits of tightly scoped model components, the need for human triage, and cost-effective scanning, though export restrictions on some models may affect future work.
read more →

Enterprises Ship Vulnerable AI-Generated Code Despite Risks

🛡️ New research from Checkmarx finds enterprises are increasingly shipping AI-generated code despite widespread vulnerabilities. The survey of 2,350 security leaders shows nearly half of production code is AI-built and organizations that rely heavily on AI introduce far more insecure code. Many firms lack formal AI governance and continue to accept or defer fixing known issues, while tool sprawl and developer pressure compound the problem.
read more →

Most Firms Admit Deploying Vulnerable Production Code

🔍 A new Checkmarx report found that 95% of CISOs have been pressured to deprioritize or delay reporting security issues, and 75% acknowledged their organizations knowingly deployed vulnerable code to production. Respondents cited compensating controls, deadlines, late detection, and difficulty of fixes as reasons. The survey of 2,350 security professionals also flagged limited remediation rates and rising risks from AI-generated code.
read more →

Embed security within agentic AI coding tools

🔒 Ox Security urges that appsec be integrated directly into AI coding tools as agentic development accelerates code changes beyond traditional pipelines. Speaking at Infosecurity Europe, field CTO Boaz Barzel argued that security must become a continuous, contextual property of creation rather than a bolt-on stage. He outlined four agentic attack surfaces—input, tools, execution and output—and advocated autonomous security agents that pentest and validate every commit to reduce MTTR and achieve full coverage.
read more →

Microsoft Build 2026: Securing Code, Agents, Models

🔒 At Microsoft Build 2026, Microsoft announced new security capabilities to integrate protection across the development lifecycle, addressing insecure code, agent proliferation, and model risk. The expanded preview of the multi-model agentic scanning harness (codename MDASH) integrates with Microsoft Defender to orchestrate hundreds of AI agents for exploit discovery. New tools such as Agent 365, MXC SDK, and Purview enhancements provide runtime controls, data protection, and governance to help developers and security teams act earlier and with consistent oversight.
read more →

Google integrates CodeMender into enterprise agent platform

🔒 Google is folding CodeMender into its broader Agent Platform strategy, expanding the AI-powered security agent from standalone vulnerability remediation toward an integrated, governed enterprise agent ecosystem. Launched in October 2025 to autonomously identify and patch vulnerabilities using Gemini models, CodeMender reportedly upstreamed dozens of fixes but lacks published performance metrics on accuracy and regressions. The integration emphasizes governance, observability, and identity, positioning CodeMender as a controlled participant in AI-native development and security pipelines rather than an unsupervised remediation tool.
read more →

Three-Quarters Admit Shipping Vulnerable Code

🛡️ New studies reveal that 75% of organizations often or sometimes deploy code they know is vulnerable, down from 81% last year but still alarmingly high. Checkmarx warns that AI-augmented attackers are dramatically shortening time-to-exploit, while Verizon’s DBIR links increased initial access to vulnerability exploitation aided by AI. A QBE survey found UK firms are worried about suppliers' AI use, yet few audit third-party AI or maintain formal AI governance.
read more →

AWS Security Agent: Full Repository Code Review Launch

🔒 AWS today introduced full repository code review in AWS Security Agent, a capability that performs deep, context-aware security analysis across entire codebases. Unlike traditional static scanners, it reasons about architecture, trust boundaries, and data flows to surface systemic vulnerabilities. When issues are identified, the scanner generates file- and line-specific remediation guidance and exploit proofs-of-concept to accelerate fixes; preview access is available at no extra charge in all Regions.
read more →