News

Copado Extends AI Reach to Surface Relationships Between Salesforce Code
Copado’s module maps Salesforce object relationships, cutting discovery time and boosting reuse, impact analysis, and DevOps best practices ...

Sentry Adds Tool for Monitoring MCP Servers to APM Platform
Sentry today added an ability to monitor Model Context Protocol (MCP) servers to its application performance monitoring (APM) platform ...

Survey Traces Large Amount of Breaches Back to Vulnerable Code
A survey of 1,519 application security stakeholders finds nearly all (98%) work for organizations that have experienced a security breach attributable to vulnerable code, with 81% acknowledging their organization has shipped code ...

Eclipse Foundation Publishes Toolkit to Simplify CRA Compliance
The Eclipse Foundation has launched the OCCTET project, offering open-source compliance tools to help smaller organizations meet the EU’s new Cyber Resilience Act requirements ...

Sonar Surfaces Multiple Caveats When Relying on LLMs to Write Code
New SonarSource research shows LLMs like GPT-4o, Claude Sonnet 4, and Llama-3.2 produce highly functional yet risky code — with frequent high-severity vulnerabilities, hard-coded credentials, and messy “code smells” that raise long-term ...

How Gemini CLI GitHub Actions is Changing Developer Workflows
Google's new Gemini CLI GitHub Actions transforms repository management with AI-powered automation for issue triage, code reviews and collaboration ...

ArmorCode Extends AI Tool to Generate Code Fixes for Specific Runtime Environments
ArmorCode, this week at the Black Hat USA 2025 conference, revealed it has extended its Anya artificial intelligence (AI) tool to generate suggested code fixes that are customized for specific runtime environments ...

Black Duck Software Extends AI Reach to IDE to Better Secure Code
Black Duck Software, this week at the Black Hat USA 2025 conference, revealed it has now integrated its artificial intelligence (AI) tool for securing software, dubbed Black Duck Assist, into the company’s ...

Cycode Delivers AI Agent to Assess How Exploitable Vulnerabilities Are
Cycode has added an artificial intelligence (AI) agent to its application security posture management (ASPM) platform that has been specifically trained to determine how exploitable a specific vulnerability found in an application ...

BMC Extends Scope and Reach of DevOps Mainframe Workflows
BMC has extended its DevOps analytics tool for mainframe environments, dubbed BMC AMI zAdviser Enterprise, to now be able to collect Git usage data to make it simpler to identify bottlenecks and ...

Survey Surfaces Multiple Persistent DevSecOps Challenges
A survey of leaders based in North America finds 62% work for organizations that knowingly release insecure code to meet delivery deadlines ...

R Systems Picks Anysphere to Build AI Coding Practice Around Cursor
R Systems International Limited, a global systems integrator, this week revealed it is building a coding practice based on Cursor, an artificial intelligence (AI) coding tool developed by Anysphere ...