AppSec stories
Businesses may get security test results in hours as ITSEC Asia's new platform flags risks and keeps human consultants in the loop.
Security teams are being warned to keep humans and strict controls in place as AI agents can miss context and leak sensitive code.
Defenders could gain a faster edge against AI-driven attacks as Google Cloud ties Gemini, Wiz, CodeMender and Mandiant into one platform.
The update aims to cut review bottlenecks by auto-fixing vulnerable dependencies and surfacing code flaws scanners often miss.
Security teams can now trace how one SAP flaw could spread across finance, payroll and supply chains, with access tightly restricted.
Developers face earlier checks on risky open-source dependencies as AI coding tools speed up software assembly and raise supply chain concerns.
Malicious package advisories jumped from 21 in 2023 to 1,576 in 2025, as attackers increasingly target developers before code reaches production.
Exposed serverless apps can let attackers steal tokens, read secrets and take over cloud projects if weak code is left unpatched.
Security teams can now rank code flaws against cloud and identity risks after Tenable folded application security data into its exposure platform.
Broader coverage in Mexico and Milan aims to cut latency for mobile security checks as fake app traffic grows more sophisticated.
Nearly half of commerce traffic across Akamai's network came from AI bots by late 2025, raising fraud and DDoS risks for retailers.
As AI coding speeds up, Checkmarx says its new agents can cut manual vulnerability fixes by up to 70% before code is committed.
Defenders face shorter patching windows as Check Point says AI can now turn new flaws into working exploits within hours.
The controlled trial could help security teams cut false positives and speed remediation as frontier AI moves beyond finding bugs to validating risk.
Without stronger operational foundations, Asia Pacific firms risk turning new security tools into costly bottlenecks instead of productivity gains.
Smaller firms can now run web app pentests in hours, as Intruder's AI service cuts costs to a fraction of manual reviews.
Security teams could cut testing delays to hours as Intruder's AI tool scans web apps for flaws from source code access.
Banks risk repeating DevOps sprawl as DIY agentic AI pushes build costs above USD $1.4 million and delays production by up to 18 months.
Boards are being pushed to rethink data platforms and cyber controls as AI adoption exposes Australian firms to faster attacks and stricter governance demands.
The pilot could speed up vulnerability hunting across government systems, but it also leaves human teams to verify and fix each AI flag.