ResearchStop Using LLMs to Generate Secrets
Your CI/CD pipeline might be generating passwords right now. If you re using AI coding assistants, there s a good chance those passwords are predictable and undetectable by your secret scanners. Resea
Expert perspectives on application security, compliance, and emerging threats
ResearchYour CI/CD pipeline might be generating passwords right now. If you re using AI coding assistants, there s a good chance those passwords are predictable and undetectable by your secret scanners. Resea
ResearchScope This guide covers how to identify and prioritize security-relevant code changes that ship without CVE assignments or security advisories. You ll learn to build a process that catches exploitable
ResearchPurpose of the Template Your Third-Party Notices (TPNs) likely sit in a compliance folder as a lengthy PDF with inconsistent formatting. While they re generated for legal reasons, they don t contribut
ResearchLast week, security researchers found that an attacker published malicious npm packages to the official @asyncapi namespace without stealing any credentials. They hijacked the project s GitHub Actions
Get weekly security insights and compliance updates delivered to your inbox.
ResearchRethinking Vulnerability Disclosure Many security teams treat vulnerability disclosure as a mere compliance task. You might post a security.txt file, set up a [email protected] email that routes to
ResearchYour team just adopted an AI coding assistant. You ve reviewed the privacy settings, turned off model training, and assumed you re protected. Meanwhile, the tool is uploading your entire Git history t
ResearchYou ve probably heard the pitch: Our AI agent will analyze your cloud infrastructure and find security gaps you didn t know existed. What you don t hear is what happens when that agent misclassifies a
ResearchUnderstanding the Concerns Recently, I ve observed heated debates among security engineers about whether to restrict GitHub Copilot in their environments. The discussions often lack concrete data on h
ResearchThe Challenge Your compliance team just finished mapping your organization s software dependencies. The audit revealed something uncomfortable: seventeen of your critical libraries are maintained by s
ResearchYour security scanning tool flags a malicious commit. You block it by hash. Two hours later, the same code appears under a different hash with GitHub s green Verified checkmark intact. The signature d
ResearchWhen Wiz published the GhostApproval pattern on July 8, they exposed a significant security issue: six major AI coding assistants were allowing malicious repositories to trick developers into granting
ResearchThese questions come from security engineers and developers who ve sat through too many supply chain security is important presentations without getting practical answers. You re building software tha
ResearchYour security team is evaluating AI systems that don t just analyze threats but conduct their own research, generate tools, and make operational decisions. Before you deploy autonomous AI in productio
ResearchYour AI coding agent just installed a new skill from the marketplace. The static scanner gave it a clean bill of health. Three days later, you re investigating why production data is leaving your netw
ResearchThe Problem: Why This Matters Now Your developers are using AI coding assistants, connecting them to databases, APIs, and internal systems. They re loading third-party skills that execute code in thei
ResearchYour compliance team is hearing the same message from every business unit: deploy AI faster. But when you ask about security controls, threat models, or data governance, you get blank stares. This gap