Tag: application security
Are LLMs Equally Good (or Bad) at Building Secure Software?
An SCW study finds a large variance in how frontier and budget LLMs perform across different frameworks, and explains the striking cost variance ...
Production-Safe Testing: The Missing Piece in Most DevSecOps Strategies
Most DevSecOps teams invest heavily in security before deployment, yet attackers target the production environment where applications, APIs, and user behavior are constantly changing. If security validation stops before release, critical risks ...
Why CI/CD Security Testing Is Going Autonomous (and Why It Should Stay Local)
Continuous integration and delivery changed the tempo of software. Teams merge dozens of times a day, infrastructure is redefined on every commit, and a new build can reach production in minutes. Security ...
AI is Coding Us Into a Corner
AI-powered patching and coding is putting us on a track towards a deepening dependency on future frontier models. The modern tools we use today to fix yesterday’s coding problems are quietly creating ...
AI Moved the Bottleneck From Writing Code to Understanding and Trusting It
AI coding boosts velocity, but without stronger review, governance and codebase visibility, teams risk higher costs, security gaps and production failures. TL;DR ...
Why You Need AI Agent Security Validation in Software Testing
Engineering teams have been racing for the last two years to deploy AI agents that can find bugs faster than any QA team ever could. Autonomous testing agents can crawl through codebases, ...
AI Is Exposing a Growing Blind Spot in Open Source Security
With AI, teams across organizations are now building internal applications faster than ever, often pulling in open source libraries and frameworks without much thought about long-term support, lifecycle management, or security ownership ...
Survey Surfaces Depth of DevSecOps Crisis in the Age of AI
A global survey of 2,350 developers, CISOs and application security managers published this week finds that while nearly all respondents (96%) work for organizations that have embedded or connected artificial intelligence (AI) ...
Agentic DevSecOps: AI Security Co-Pilots for Your CI/CD PipelineÂ
The emergence of AI has brought endless possibilities and innovative opportunities in today’s ever-changing, fast-paced technology landscape. AI is helping development teams produce software significantly faster than ever before. AI-enabled DevSecOps tools ...
AI-Generated Apps Without DevOps: A Security Disaster Waiting to Happen
A small internal tool was built over a weekend. An engineer used an AI coding assistant to generate most of the backend. A simple interface was added, a few API calls were ...
Beyond the Build: Integrating Security into CI/CD Pipelines
In today's fast-paced software development landscape, Continuous Integration and Continuous Deployment (CI/CD) pipelines are essential for delivering applications efficiently. However, the speed and automation they offer can inadvertently introduce security vulnerabilities if ...
Chainguard Expands Repository to Add More Secure Open Source Libraries
Learn how Chainguard is strengthening software supply chains by expanding its secure repository of Java, JavaScript, and Python libraries, enabling DevOps teams to access components compliant with SLSA framework standards ...

