software-development
92 articles with this tag
INFO
INFO
INFO
LOW
INFO
INFO
INFO
INFO
INFO
INFO
HIGH
INFO
INFO
CRITICAL
INFO
CRITICAL
HIGH
INFO
INFO
INFO
INFO
MEDIUM
INFO
LOW
INFO
INFO
MEDIUM
INFO
MEDIUM
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
LOW
HIGH
INFO
INFO
HIGH
CRITICAL
INFO
LOW
INFO
INFO
INFO
INFO
HIGH
INFO
INFO
INFO
HIGH
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
HIGH
INFO
INFO
INFO
INFO
INFO
INFO
INFO
MEDIUM
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
A security framework for coding agents and their harnesses
Secure AI Coding: Governing every agent, artifact, and identity
CISA review makes the case for eliminating vulnerability classes
Production data in testing is still common, and Tricentis’ CISO wants it gone
Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt
STOP Blaming Users for Insecure Software
AI can find zero-days but still can’t reliably write secure code
Code fixers have fired up the AI warp drive. Strange new worlds await
Packer v1.16.0 brings verifiable provenance to machine images
Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion
[NEU] [hoch] GitLab: Mehrere Schwachstellen
NetBSD brings its Englightenment port up to snuff
Growing Up The Hard Way
Human oversight is still critical as AI patching tools miss security risks
Microsoft CVP explains why killing Windows legacy code takes so long
[NEU] [hoch] Jenkins Plugins: Mehrere Schwachstellen
[NEU] [mittel] Autodesk FBX SDK: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode mit den Rechten des Dienstes
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps
The Agent Development Lifecycle has arrived on Cloudflare
Run CI/CD for millions of repos — on your platform, on Cloudflare
Prompting for Patches That Fix Vulns Without Adding New Ones - Keith Hoodlet - ASW #394
Before the first prompt: Code execution paths in trusted coding-agent projects
Balancing speed and safety: A control framework for AI coding agents
GitHub revamps bug bounty program with new VIP tier, payout changes
The AI code vulnerabilities that grow with your app
Source Code Analysis: A Pentester's Guide
[NEU] [mittel] Apache Ivy: Schwachstelle ermöglicht Manipulation von Dateien
AI Engineer World’s Fair 2026: The Runtime Is Where Agent Trust Is Won
AI coding assistants bypass safety filters through workflow manipulation
Your coding agent says no in chat and yes in the code
How we built saga rollbacks for Cloudflare Workflows
Best practices for AI in open-source work
Beyond the benchmark: Advancing security at AI speed
A Note to Our Customers and Partners
The New Security Control Point: Governing AI Agents Inside the Execution Loop
Sniff out stale AI override advice with this open source CLI
Why Does It Matter Who or What Created the Code? - Matias Madou - ASW #387
Reachability makes AI threat modeling worth the trust
Spotlight on SIG Storage
NanoClaw now armed with JFrog for safer packages
AI Coding Adoption Hits 97% but Governance Lags Behind
Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure
The New Security Risks of the Agentic Development Lifecycle
How to Secure AI Agents: A Practical Overview for Development Teams
Malicious npm packages abuse dependency confusion to profile developer environments
The AI Era Is Creating a Bug Hunting Arms Race
Google folds CodeMender into agent ecosystem amid push for AI-led AppSec
Three-Quarters of Firms Knowingly Ship Vulnerable Code
CVE Lite CLI: Open-source dependency vulnerability scanner
LaunchDarkly adds real-time controls for AI agents in production
Microsoft details new AI system for vulnerability discovery
KDE gets over €1 million investment to strengthen security and core infrastructure
[NEU] [hoch] Microsoft Developer Tools: Mehrere Schwachstellen
OpenAI’s Daybreak uses Codex Security to identify risky attack paths
OpenAI Launches Daybreak for AI-Powered Vulnerability Detection and Patch Validation
Redox gets partial window pixel updating, tmux, and more
[NEU] [hoch] Jenkins Plugins: Mehrere Schwachstellen
Extending Ruzzy with LibAFL
Aptori expands its platform with autonomous offensive testing to reduce security bottlenecks
Trailmark turns code into graphs
Microsoft taps Anthropic’s Mythos to strengthen secure software development
LLM Security Automation Isn’t a Drop-In Scanner Yet
GitLab 18.11 brings agentic AI to security fixes, CI pipelines, and delivery analytics
Project Glasswing and open source software: The good, the bad, and the ugly
The case for fixing CWE weakness patterns instead of patching one bug at a time
KDE is bringing back its classic Oxygen and Air themes
Big-endian testing with QEMU
Cybersecurity in the age of instant software
How we made Trail of Bits AI-native (so far)
GitLab Multiple Vulnerabilities
LLVM Adventures: Fuzzing Apache Modules
Sandboxing AI coding agents with kernel-level enforcement: built-in profiles for Claude Code, Codex, and OpenCode
Hyoketsu - Solving the Vendor Dependency Problem in Reverse Engineering
The Invisible Rewrite: Modernizing the Kubernetes Image Promoter
Building AI Teams: How Docker Sandboxes and Docker Agent Transform Development
Software Development Practices Help Enterprises Tackle Real-Life Risks
Secure by Design: Building security in at the beginning
Flaws in Claude Code Put Developers' Machines at Risk
Why the shift left dream has become a nightmare for security and developers
Security Compass brings policy-driven security and compliance to agentic AI development
The new paradigm for raising up secure software engineers
Product engineering teams must own supply chain risk
How to Eliminate the Technical Debt of Insecure AI-Assisted Software Development
CodeHunter expands behavioral intent analysis to secure the software supply chain
Backslash Security raises $19 million to address AI coding security risks
Vouch: earn the right to submit a pull request
Vibe Coding Is Killing Open Source Software, Researchers Argue
How Secure by Design helps developers build secure software
Die besten DAST- & SAST-Tools
Introducing the AI Security Fabric: Empowering Software Builders in the Era of AI
Celebrating our 2025 open-source contributions
Seven habits that help security teams reduce risk without slowing delivery