IncidentAI Flagged 27 Bugs. Only 7 Got Fixed.
What Happened The DARPA Artificial Intelligence Cyber Challenge (AIxCC) concluded with a $30,500,000 prize pool, showcasing AI s potential in vulnerability detection. Seven teams deployed AI systems a
Expert perspectives on application security, compliance, and emerging threats
IncidentWhat Happened The DARPA Artificial Intelligence Cyber Challenge (AIxCC) concluded with a $30,500,000 prize pool, showcasing AI s potential in vulnerability detection. Seven teams deployed AI systems a
ResearchYour team ships code 55% faster with AI assistance. But when that code breaks in production at 2 AM, can they fix it? This isn t a hypothetical problem. According to Octopus Deploy research, 73% of or
IncidentSecureLayer7 released Sandyaa in late 2024 under an MIT license. This tool uses large language models to scan source code for vulnerabilities and then writes exploit code to prove they re real. Within
GeneralGitHub forecasts 14 billion commits in 2026—a 10x increase from pre-AI levels. Your security team is already feeling it. Pull requests arrive faster, code reviews pile up, and the quality of code comi
Get weekly security insights and compliance updates delivered to your inbox.
IncidentA critical authentication bypass in the Burst Statistics WordPress plugin gave attackers admin-level access to thousands of websites. Here s what happened, which controls failed, and what your team ne
IncidentIncident Overview Attackers compromised the node-ipc npm package by exploiting an expired domain linked to a maintainer s account. They published malicious versions (11.0.0, 11.1.0, and 12.0.0) contai
ResearchImagine your team just renewed all your domains. Six months later, one expires because the credit card on file failed. A week after that, someone else registers it. They now control a domain that your
GuidesYou ve probably heard the advice: Just use Django s built-in protections or Static analysis will catch everything. These shortcuts sound efficient, but they re creating a generation of Python develope
GeneralScope - What This Guide Covers This guide focuses on the operational changes in application security as AI agents take on end-to-end vulnerability management. It provides frameworks for establishing g
IncidentWhat Happened Between early December 2024 and January 16, 2025, attackers exploited a critical vulnerability in FunnelKit s Funnel Builder plugin to inject malicious JavaScript into WooCommerce checko
IncidentWhat Happened On April 13, Microsoft rejected a security researcher s vulnerability report for Azure Backup for AKS (Azure Kubernetes Service). The researcher, Justin O Leary, identified a privilege e
IncidentDiscovery of a Long-Overlooked Vulnerability An AI-powered security agent uncovered a vulnerability that had eluded human researchers for over a decade, exploiting it within 48 hours of deployment. Th
DeadlinesThe EU s Cyber Resilience Act (CRA) introduces a new compliance requirement: software and network-connected products now need the same CE marking as electronics and machinery. By December 2027, if you
IncidentWhat Happened TeamPCP compromised Mistral AI s codebase management system, extracting nearly 450 repositories. They are selling the complete source code for $25,000 on underground forums, threatening
IncidentWhat Happened In early 2025, threat actor TeamPCP compromised TanStack s distribution infrastructure and released trojanized versions of npm and PyPI SDKs. Two OpenAI employee devices installed these
IncidentOn May 14, 2026, three malicious versions of node-ipc—a package with millions of weekly downloads—were published to npm. These versions (9.1.6, 9.2.3, and 12.0.1) contained a credential-stealing paylo