Application Security
80 материалов
- Axios NPM Package Breached in North Korean Supply Chain Attack
Supply Chain Security · Application Security
A long-lived NPM access token was used to bypass the GitHub Actions OIDC-based CI/CD publishing workflow and push backdoored package versions. The post Axios NPM Package Breached in North Korean Supply Chain Attack appeared first on SecurityWeek.
- TeamPCP Moves From OSS to AWS Environments
Cloud Security · Application Security
After validating stolen credentials using TruffleHog, the hacking group started AWS services enumeration and lateral movement activities. The post TeamPCP Moves From OSS to AWS Environments appeared first on SecurityWeek.
- Huskeys Emerges From Stealth With $8 Million in Funding
Cybersecurity Funding · Application Security
The startup has built an edge security management (ESM) platform, an AI engine atop the entire edge security stack. The post Huskeys Emerges From Stealth With $8 Million in Funding appeared first on SecurityWeek.
- From Trivy to Broad OSS Compromise: TeamPCP Hits Docker Hub, VS Code, PyPI
Application Security · Malware & Threats
The hackers compromised GitHub Action tags, then shifted to NPM, Docker Hub, VS Code, and PyPI, and teamed with Lapsus$. The post From Trivy to Broad OSS Compromise: TeamPCP Hits Docker Hub, VS Code, PyPI appeared first on SecurityWeek.
- Raven Emerges From Stealth With $20 Million in Funding
Cybersecurity Funding · Application Security
Raven’s platform observes applications at runtime to detect anomalous behavior and prevent cyberattacks. The post Raven Emerges From Stealth With $20 Million in Funding appeared first on SecurityWeek.
- API Threats Grow in Scale as AI Expands the Blast Radius
Artificial Intelligence · Application Security
New research shows attackers increasingly abusing APIs at machine speed as AI-driven systems widen exposure and amplify impact. The post API Threats Grow in Scale as AI Expands the Blast Radius appeared first on SecurityWeek.
- Zast.AI Raises $6 Million for AI-Powered Code Security
Cybersecurity Funding · Application Security
The startup relies on AI agents to identify software vulnerabilities and validate them before reporting. The post Zast.AI Raises $6 Million for AI-Powered Code Security appeared first on SecurityWeek.
- Backslash Raises $19 Million to Secure Vibe Coding
Cybersecurity Funding · Application Security
The company will use the investment to expand its R&D team and operations, deepen platform capabilities, and scale go-to-market presence. The post Backslash Raises $19 Million to Secure Vibe Coding appeared first on SecurityWeek.
- VS Code Configs Expose GitHub Codespaces to Attacks
Vulnerabilities · Application Security
VS Code-integrated configuration files are automatically executed in Codespaces when the user opens a repository or pull request. The post VS Code Configs Expose GitHub Codespaces to Attacks appeared first on SecurityWeek.
- Rein Security Emerges From Stealth With $8M, Bringing Inside-Out AppSec Approach
Cybersecurity Funding · Application Security
Rein aims to close the production visibility gap by stopping attacks inside the application runtime. The post Rein Security Emerges From Stealth With $8M, Bringing Inside-Out AppSec Approach appeared first on SecurityWeek.
- Cyber Insights 2026: API Security – Harder to Secure, Impossible to Ignore
Application Security
API cybersecurity will be a ping pong ball, battered between the rackets of AI-assisted attackers and AI-assisted defenders. The post Cyber Insights 2026: API Security – Harder to Secure, Impossible to Ignore appeared first on SecurityWeek.
- Vibe Coding Tested: AI Agents Nail SQLi but Fail Miserably on Security Controls
Artificial Intelligence · Application Security
Vibe coding generates a curate’s egg program: good in parts, but the bad parts affect the whole program. The post Vibe Coding Tested: AI Agents Nail SQLi but Fail Miserably on Security Controls appeared first on SecurityWeek.
- Aikido Security Raises $60 Million at $1 Billion Valuation
Cybersecurity Funding · Application Security
The developer security company has raised a total of more than $84 million in funding. The post Aikido Security Raises $60 Million at $1 Billion Valuation appeared first on SecurityWeek.
- Shai-Hulud Supply Chain Attack Led to $8.5 Million Trust Wallet Heist
Supply Chain Security · Application Security
The worm exposed Trust Wallet’s Developer GitHub secrets, allowing attackers to publish a backdoor extension and steal funds from 2,520 wallets. The post Shai-Hulud Supply Chain Attack Led to $8.5 Million Trust Wallet Heist appeared first on SecurityWeek.
- MITRE Releases 2025 List of Top 25 Most Dangerous Software Vulnerabilities
Vulnerabilities · Application Security
XSS remains the top software weakness, followed by SQL injection and CSRF. Buffer overflow issues and improper access control make it to top 25. The post MITRE Releases 2025 List of Top 25 Most Dangerous Software Vulnerabilities appeared first on SecurityWeek.
- React2Shell: In-the-Wild Exploitation Expected for Critical React Vulnerability
Application Security · Vulnerabilities
A researcher has pointed out that only instances using a newer feature are impacted by CVE-2025-55182. The post React2Shell: In-the-Wild Exploitation Expected for Critical React Vulnerability appeared first on SecurityWeek.
- Clover Security Raises $36 Million to Secure Software by Design
Cybersecurity Funding · Application Security
The cybersecurity startup embeds AI agents into widely used tools to identify design flaws and eliminate them early. The post Clover Security Raises $36 Million to Secure Software by Design appeared first on SecurityWeek.
- Watch Now: Protecting What WAFs and Gateways Can’t See – Register
Application Security
Learn why legacy approaches fail to stop modern API threats and show how dedicated API security delivers the visibility, protection, and automation needed to defend against today’s evolving risks. The post Watch Now: Protecting What WAFs and Gateways Can’t See – Register appeared first on SecurityWeek.
- Amazon Detects 150,000 NPM Packages in Worm-Powered Campaign
Application Security
A financially motivated threat actor automated the package publishing process in a coordinated tea.xyz token farming campaign. The post Amazon Detects 150,000 NPM Packages in Worm-Powered Campaign appeared first on SecurityWeek.
- Two New Web Application Risk Categories Added to OWASP Top 10
Application Security
OWASP has added two new categories to the revised version of its Top 10 list of the most critical risks to web applications. The post Two New Web Application Risk Categories Added to OWASP Top 10 appeared first on SecurityWeek.
- GlassWorm Malware Returns to Open VSX, Emerges on GitHub
Application Security
Three more VS Code extensions were infected last week and the malware has emerged in GitHub repositories as well. The post GlassWorm Malware Returns to Open VSX, Emerges on GitHub appeared first on SecurityWeek.
- Critical Flaw in Popular React Native NPM Package Exposes Developers to Attacks
Application Security
Arbitrary command/code execution has been demonstrated through the exploitation of CVE-2025-11953 on Windows, macOS and Linux. The post Critical Flaw in Popular React Native NPM Package Exposes Developers to Attacks appeared first on SecurityWeek.
- Bugcrowd Acquires Application Security Firm Mayhem
M&A Tracker · Application Security
Bugcrowd said the acquisition of Mayhem has nearly doubled its valuation — previously reported at over $1 billion. The post Bugcrowd Acquires Application Security Firm Mayhem appeared first on SecurityWeek.
- Who is Zico Kolter? A Professor Leads OpenAI Safety Panel With Power to Halt Unsafe AI Releases
Application Security
Kolter leads a panel at OpenAI that has the authority to halt the ChatGPT maker’s release of new AI systems if it finds them unsafe. The post Who is Zico Kolter? A Professor Leads OpenAI Safety Panel With Power to Halt Unsafe AI Releases appeared first on SecurityWeek.
- Webinar Today: Fact vs. Fiction – The Truth About API Security
Application Security
Get practical guidance to protect APIs against the threats attackers are using right now. The post Webinar Today: Fact vs. Fiction – The Truth About API Security appeared first on SecurityWeek.
- GitHub Boosting Security in Response to NPM Supply Chain Attacks
Supply Chain Security · Application Security
GitHub will implement local publishing with mandatory 2FA, granular tokens that expire after seven days, and trusted publishing. The post GitHub Boosting Security in Response to NPM Supply Chain Attacks appeared first on SecurityWeek.
- Shai-Hulud Supply Chain Attack: Worm Used to Steal Secrets, 180+ NPM Packages Hit
Supply Chain Security · Application Security
The packages were injected with malicious code to harvest secrets, dump them to a public repository, and make private repositories public. The post Shai-Hulud Supply Chain Attack: Worm Used to Steal Secrets, 180+ NPM Packages Hit appeared first on SecurityWeek.
- Highly Popular NPM Packages Poisoned in New Supply Chain Attack
Supply Chain Security · Application Security
Designed to intercept cryptocurrency transactions, the malicious code reached 10% of cloud environments. The post Highly Popular NPM Packages Poisoned in New Supply Chain Attack appeared first on SecurityWeek.
- GitHub Workflows Attack Affects Hundreds of Repos, Thousands of Secrets
Supply Chain Security · Application Security
A supply chain attack called GhostAction has enabled threat actors to steal secrets and exploit them. The post GitHub Workflows Attack Affects Hundreds of Repos, Thousands of Secrets appeared first on SecurityWeek.
- US, Allies Push for SBOMs to Bolster Cybersecurity
Risk Management · Application Security
SBOM adoption will drive software supply chain security, decreasing risks and costs, and improving transparency. The post US, Allies Push for SBOMs to Bolster Cybersecurity appeared first on SecurityWeek.
- CISA Requests Public Feedback on Updated SBOM Guidance
Supply Chain Security · Application Security
CISA has updated the Minimum Elements for a Software Bill of Materials (SBOM) guidance and is seeking public comment. The post CISA Requests Public Feedback on Updated SBOM Guidance appeared first on SecurityWeek.
- Watch Now: CodeSecCon – Where Software Security’s Next Chapter Unfolds (Virtual Event)
Application Security · Vulnerabilities
CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained. The post Watch Now: CodeSecCon – Where Software Security’s Next Chapter Unfolds (Virtual Event) appeared first on SecurityWeek.
- Now Live: CodeSecCon – Where Software Security’s Next Chapter Unfolds (Virtual Event)
Application Security · Vulnerabilities
Taking place August 12-13, CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained. The post Now Live: CodeSecCon – Where Software Security’s Next Chapter Unfolds (Virtual Event) appeared first on SecurityWeek.
- CodeSecCon 2025: Where Software Security’s Next Chapter Unfolds
Application Security · Vulnerabilities
Taking place August 12-13, CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained. The post CodeSecCon 2025: Where Software Security’s Next Chapter Unfolds appeared first on SecurityWeek.
- Flaw in Vibe Coding Platform Base44 Exposed Private Enterprise Applications
Application Security · Artificial Intelligence
Base44 owner Wix quickly patched a critical authentication bypass vulnerability discovered by researchers at Wiz. The post Flaw in Vibe Coding Platform Base44 Exposed Private Enterprise Applications appeared first on SecurityWeek.
- Seal Security Raises $13 Million to Secure Software Supply Chain
Application Security · Cybersecurity Funding
The open source security firm will use the investment to enhance go-to-market efforts and accelerate platform expansion. The post Seal Security Raises $13 Million to Secure Software Supply Chain appeared first on SecurityWeek.
- HeroDevs Raises $125 Million to Secure Deprecated OSS
Application Security · Cybersecurity Funding
HeroDevs has received a $125 million strategic growth investment from PSG to secure enterprise security stacks. The post HeroDevs Raises $125 Million to Secure Deprecated OSS appeared first on SecurityWeek.
- RevEng.ai Raises $4.15 Million to Secure Software Supply Chain
Application Security · Cybersecurity Funding
RevEng.ai has raised $4.15 million in seed funding for an AI platform that automatically detects malicious code and vulnerabilities in software. The post RevEng.ai Raises $4.15 Million to Secure Software Supply Chain appeared first on SecurityWeek.
- Thousands of SaaS Apps Could Still Be Susceptible to nOAuth
Identity & Access · Application Security
New research suggests more than 10,000 SaaS apps could remain vulnerable to a nOAuth variant despite the basic issue being disclosed in June 2023. The post Thousands of SaaS Apps Could Still Be Susceptible to nOAuth appeared first on SecurityWeek.
- Five Zero-Days, 15 Misconfigurations Found in Salesforce Industry Cloud
Application Security · Cloud Security
Security researchers uncover critical flaws and widespread misconfigurations in Salesforce’s industry-specific CRM solutions. The post Five Zero-Days, 15 Misconfigurations Found in Salesforce Industry Cloud appeared first on SecurityWeek.
- Watch Now: Why Context is a Secret Weapon in Application Security Posture Management
Application Security
Join the live webinar to understand why data in itself is not enough to make informed decisions for prioritization. The post Watch Now: Why Context is a Secret Weapon in Application Security Posture Management appeared first on SecurityWeek.
- Chinese Hacking Group ‘Earth Lamia’ Targets Multiple Industries
Application Security
Active since at least 2023, the hacking group has been targeting the financial, government, IT, logistics, retail, and education sectors. The post Chinese Hacking Group ‘Earth Lamia’ Targets Multiple Industries appeared first on SecurityWeek.
- OneDrive Gives Web Apps Full Read Access to All Files
Application Security · Cloud Security
Security researchers warn that OneDrive’s file sharing tool may grant third-party web apps access to all your files—not just the one you choose to upload. The post OneDrive Gives Web Apps Full Read Access to All Files appeared first on SecurityWeek.
- CodeAnt AI Raises $2 Million for Code Quality and Application Security Platform
Application Security · Cybersecurity Funding
Code quality and security firm CodeAnt has secured $2 million in seed funding and it has been valued at $20 million. The post CodeAnt AI Raises $2 Million for Code Quality and Application Security Platform appeared first on SecurityWeek.
- Ox Security Bags $60M Series B to Tackle Appsec Alert Fatigue
Application Security · Artificial Intelligence
Ox Security has raised a total $94 million since its launch in 2021 with ambitious plans to cash in on two fast-moving trends. The post Ox Security Bags $60M Series B to Tackle Appsec Alert Fatigue appeared first on SecurityWeek.
- AppSignal Raises $22 Million for Application Monitoring Solution
Cybersecurity Funding · Application Security
Application performance monitoring provider AppSignal has raised $22 million in a Series A funding round led by Elsewhere Partners. The post AppSignal Raises $22 Million for Application Monitoring Solution appeared first on SecurityWeek.
- Manifest Raises $15 Million for SBOM Management Platform
Application Security · Cybersecurity Funding
Software and AI supply chain transparency firm Manifest has raised $15 million in a Series A funding round led by Ensemble VC. The post Manifest Raises $15 Million for SBOM Management Platform appeared first on SecurityWeek.
- Endor Labs Raises $93 Million for AppSec Platform
Application Security · Cybersecurity Funding
Endor Labs has raised $93 million in a Series B funding round and announced a major expansion of its AppSec platform. The post Endor Labs Raises $93 Million for AppSec Platform appeared first on SecurityWeek.
- Miggo Security Banks $17M Series A for ADR Technology
Application Security
Israeli runtime application security startups closes a $17 million Series A round led by Florida‑based SYN Ventures and YL Ventures. The post Miggo Security Banks $17M Series A for ADR Technology appeared first on SecurityWeek.
- Open Source Security Firm Hopper Emerges From Stealth With $7.6M in Funding
Application Security · Cybersecurity Funding
Hopper has emerged from stealth mode with a solution designed to help organizations manage open source software risk. The post Open Source Security Firm Hopper Emerges From Stealth With $7.6M in Funding appeared first on SecurityWeek.
- Insurance Firm Lemonade Says API Glitch Exposed Some Driver’s License Numbers
Application Security · Data Breaches
Lemonade says the incident is not material and that its operations were not compromised, nor was its customer data targeted. The post Insurance Firm Lemonade Says API Glitch Exposed Some Driver’s License Numbers appeared first on SecurityWeek.
- GitHub Announces General Availability of Security Campaigns
Application Security
GitHub security campaigns make it easier for developers and security teams to collaborate on fixing vulnerabilities in their applications. The post GitHub Announces General Availability of Security Campaigns appeared first on SecurityWeek.
- Call Records of Millions Exposed by Verizon App Vulnerability
Mobile & Wireless · Application Security
A patch has been released for a serious information disclosure vulnerability affecting a Verizon call filtering application. The post Call Records of Millions Exposed by Verizon App Vulnerability appeared first on SecurityWeek.
- Compromised SpotBugs Token Led to GitHub Actions Supply Chain Hack
Supply Chain Security · Application Security
Evidence shows a SpotBugs token compromised in December 2024 was used in the March 2025 GitHub Actions supply chain attack. The post Compromised SpotBugs Token Led to GitHub Actions Supply Chain Hack appeared first on SecurityWeek.
- Google Releases Major Update for Open Source Vulnerability Scanner
Application Security
Google has integrated OSV-SCALIBR features into OSV-Scanner, its free vulnerability scanner for open source developers. The post Google Releases Major Update for Open Source Vulnerability Scanner appeared first on SecurityWeek.
- Popular GitHub Action Targeted in Supply Chain Attack
Supply Chain Security · Application Security
The tj-actions/changed-files GitHub Action, which is used in 23,000 repositories, has been targeted in a supply chain attack. The post Popular GitHub Action Targeted in Supply Chain Attack appeared first on SecurityWeek.
- Sola Security Deposits Hefty $30M Seed Funding
Application Security
The financing was provided by S Capital and investor Mike Moritz, S32, Glilot Capital Partners, and several angel investors. The post Sola Security Deposits Hefty $30M Seed Funding appeared first on SecurityWeek.
- OpenSSF Releases Security Baseline for Open Source Projects
Application Security
The Open Source Security Foundation (OpenSSF) has created a structured set of security requirements for open source projects. The post OpenSSF Releases Security Baseline for Open Source Projects appeared first on SecurityWeek.
- MirrorTab Raises $8.5M Seed Round to Take on Browser-Based Attacks
Application Security
San Francisco startup secures $8.5 million in seed funding led by Valley Capital Partners to tackle browser-based malware attacks. The post MirrorTab Raises $8.5M Seed Round to Take on Browser-Based Attacks appeared first on SecurityWeek.
- Semgrep Raises $100M for AI-Powered Code Security Platform
Application Security
San Francisco application security startup raises $100 million in a Series D funding round led by Menlo Ventures. The post Semgrep Raises $100M for AI-Powered Code Security Platform appeared first on SecurityWeek.
- How Agentic AI will be Weaponized for Social Engineering Attacks
Application Security · Cybercrime
With each passing year, social engineering attacks are becoming bigger and bolder thanks to rapid advancements in artificial intelligence. The post How Agentic AI will be Weaponized for Social Engineering Attacks appeared first on SecurityWeek.
- Abandoned Amazon S3 Buckets Could Have Enabled Attacks Against Governments, Big Firms
Application Security
150 abandoned Amazon S3 buckets could have been leveraged to deliver malware or backdoors to governments and Fortune companies. The post Abandoned Amazon S3 Buckets Could Have Enabled Attacks Against Governments, Big Firms appeared first on SecurityWeek.
- Oligo Raises $50M to Tackle Application Detection and Response
Application Security
Oligo Security has raised $50 million in Series B funding for its application detection and response (ADR) platform. The post Oligo Raises $50M to Tackle Application Detection and Response appeared first on SecurityWeek.
- Endor Labs and Allies Launch Opengrep, Reviving True OSS for SAST
Supply Chain Security · Application Security
Opengrep is a new consortium-backed fork of Semgrep, intended to be and remain a true genuine OSS SAST tool. The post Endor Labs and Allies Launch Opengrep, Reviving True OSS for SAST appeared first on SecurityWeek.
- Application Security Firm DryRun Raises $8.7 Million in Seed Funding
Application Security · Cybersecurity Funding
DryRun Security has raised $8.7 million in a seed funding round for its AI-powered application security solutions. The post Application Security Firm DryRun Raises $8.7 Million in Seed Funding appeared first on SecurityWeek.
- Cyber Insights 2025: APIs – The Threat Continues
Application Security · Cloud Security
APIs are easy to develop, simple to implement, and frequently attacked. They are prime and lucrative targets for cybercriminals. The post Cyber Insights 2025: APIs – The Threat Continues appeared first on SecurityWeek.
- CISA, FBI Update Software Security Recommendations
Application Security
CISA and the FBI have updated their guidance regarding risky software security bad practices based on feedback received from the public. The post CISA, FBI Update Software Security Recommendations appeared first on SecurityWeek.
- US Government Agencies Call for Closing the Software Understanding Gap
Application Security
CISA and other agencies call to action for the US government to take steps to close the software understanding gap. The post US Government Agencies Call for Closing the Software Understanding Gap appeared first on SecurityWeek.
- Google Releases Open Source Library for Software Composition Analysis
Application Security
Google releases OSV-SCALIBR, an open source library for software composition analysis and file system scanning. The post Google Releases Open Source Library for Software Composition Analysis appeared first on SecurityWeek.
- Cisco Unveils New AI Application Security Solution
Application Security · Artificial Intelligence
Cisco has unveiled AI Defense, a solution designed to help organizations protect development and use of AI applications. The post Cisco Unveils New AI Application Security Solution appeared first on SecurityWeek.
- AI Won’t Take This Job: Microsoft Says Human Ingenuity Crucial to Red-Teaming
Application Security · Risk Management
Redmond's AI Red Team says human involvement remains irreplaceable in addressing nuanced risks. The post AI Won’t Take This Job: Microsoft Says Human Ingenuity Crucial to Red-Teaming appeared first on SecurityWeek.
- Google Open Sources Security Patch Validation Tool for Android
Application Security · Mobile & Wireless
Google has announced the open source availability of Vanir, a patch validation tool for Android platform developers. The post Google Open Sources Security Patch Validation Tool for Android appeared first on SecurityWeek.
- GitHub Launches Fund to Improve Open Source Project Security
Application Security
GitHub has launched a $1.25 million fund to be invested in improving the security of 125 open source projects. The post GitHub Launches Fund to Improve Open Source Project Security appeared first on SecurityWeek.
- Low-Code, High Risk: Millions of Records Exposed via Misconfigured Microsoft Power Pages
Application Security · Data Protection
Security researcher investigated Microsoft Power Pages installations and found several with misconfigurations allowing unintentional access to confidential data. The post Low-Code, High Risk: Millions of Records Exposed via Misconfigured Microsoft Power Pages appeared first on SecurityWeek.
- API Security Matters: The Risks of Turning a Blind Eye
Application Security · Data Protection
Willfully ignoring important security issues to make our lives easier is, unfortunately, something that does happen in the security field. The post API Security Matters: The Risks of Turning a Blind Eye appeared first on SecurityWeek.
- US, Australia Release New Security Guide for Software Makers
Application Security
CISA, FBI, and ACSC have published guidance to help software manufacturers establish secure deployment processes. The post US, Australia Release New Security Guide for Software Makers appeared first on SecurityWeek.
- CISA, FBI Seek Public Comment on Software Security Bad Practices Guidance
Application Security
CISA and the FBI are requesting public comment on new guidance regarding risky software security bad practices. The post CISA, FBI Seek Public Comment on Software Security Bad Practices Guidance appeared first on SecurityWeek.
- DefectDojo Raises $7 Million for Application Security Platform
Application Security · Cybersecurity Funding
Application security and vulnerability management platform DefectDojo has raised $7 million in Series A funding. The post DefectDojo Raises $7 Million for Application Security Platform appeared first on SecurityWeek.
- Software Security Firm RunSafe Raises $12 Million in Series B Funding
Application Security · Cybersecurity Funding
RunSafe Security has raised $12 million in a Series B funding round for a solution designed to help companies develop secure software. The post Software Security Firm RunSafe Raises $12 Million in Series B Funding appeared first on SecurityWeek.
- Operant AI Lands $10M Investment to Boost Runtime Protection for Cloud and AI
Application Security
Operant AI, a startup specializing in runtime protection for cloud applications, APIs, and AI systems, secures new $10 million investment. The post Operant AI Lands $10M Investment to Boost Runtime Protection for Cloud and AI appeared first on SecurityWeek.
