ResearchAI Won't Fix Your Broken Security Model
You ve likely seen the pitch: AI will transform your vulnerability management, speed up triage, and catch threats before humans can. What vendors don t mention is that adding AI to a flawed security m
Expert perspectives on application security, compliance, and emerging threats
ResearchYou ve likely seen the pitch: AI will transform your vulnerability management, speed up triage, and catch threats before humans can. What vendors don t mention is that adding AI to a flawed security m
ResearchAbout six months ago, questions started popping up in our Slack channel. An engineer asked about ChatGPT usage policies. Another wondered how to scan AI-generated pull requests. Recently, a compliance
ResearchThe Question at Hand Your dependency scanner flagged 47 suspicious packages last month. By the time it caught them, developers had already run npm install, pulled in transitive dependencies, and possi
ResearchScope This guide covers how to identify and prioritize security-relevant code changes that ship without CVE assignments or security advisories. You ll learn to build a process that catches exploitable
Get weekly security insights and compliance updates delivered to your inbox.
ResearchPurpose of the Template Your Third-Party Notices (TPNs) likely sit in a compliance folder as a lengthy PDF with inconsistent formatting. While they re generated for legal reasons, they don t contribut
ResearchRethinking Vulnerability Disclosure Many security teams treat vulnerability disclosure as a mere compliance task. You might post a security.txt file, set up a [email protected] email that routes to
ResearchYour team just adopted an AI coding assistant. You ve reviewed the privacy settings, turned off model training, and assumed you re protected. Meanwhile, the tool is uploading your entire Git history t
ResearchThe Challenge Your compliance team just finished mapping your organization s software dependencies. The audit revealed something uncomfortable: seventeen of your critical libraries are maintained by s
ResearchThe Problem: Why This Matters Now Your developers are using AI coding assistants, connecting them to databases, APIs, and internal systems. They re loading third-party skills that execute code in thei
ResearchYour compliance team is hearing the same message from every business unit: deploy AI faster. But when you ask about security controls, threat models, or data governance, you get blank stares. This gap
ResearchThese myths persist because they allow teams to avoid uncomfortable conversations about accountability. When your auditor asks who owns security for the 247 open source packages in your application, p
ResearchAfter Zafran Security published their DifyTap research, compliance teams began questioning tenant isolation in multi-tenant AI platforms. This issue is not limited to Dify, which boasts over 146,000 G
ResearchThe Challenge Your development team has boosted sprint velocity by 40%. Code moves from developer workstations to production faster than ever. Pull requests that once took days now close in hours. The
ResearchCISA launched a new nomination form in late 2024 that allows researchers, vendors, and industry partners to submit vulnerabilities directly to the Known Exploited Vulnerabilities (KEV) catalog. Since
ResearchYour organization now requires a Software Bill of Materials (SBOM) for every release, and your CI/CD pipeline generates them automatically. However, a recent study of 25,882 Java SBOMs revealed that 7
ResearchThe Challenge The European Union s draft of the Cyber Resilience Act (CRA) initially treated open source software like commercial products, imposing liability on community maintainers—volunteers often