Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The latest News and Information on Application Security including monitoring, testing, and open source.

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Insignary Launches Clarity AIR: Closing the Blind Spot Between What Your Developers Declare and What's Actually in Your Code. New snippet-level scanning shows security and compliance leaders which open-source code and which AI-written code never made it into a manifest.

How to Build the Business Case for ASPM Software

Start with what the current backlog already costs: analyst hours spent on triage, developer time lost to duplicate tickets, slow MTTR, and manual reporting. Then tie each benefit of ASPM software to one of those costs, such as fewer tickets per fix or faster remediation. Compare pricing models on your real numbers, including integration upkeep, and propose a measurable pilot on five to ten high-value applications. Most AppSec teams don’t need to be sold on ASPM software.

How Aikido helps you meet SOC 2 Type 1 and Type 2

If you've ever gone through a SOC 2 audit, you know the drill. It’s weeks of screenshotting dashboards and chasing down evidence across some dozen tools, while hoping the auditor doesn't ask a follow-up question you can't answer. Fortunately, SOC 2 doesn't have to be that painful, especially if the tools you already use for security are generating the evidence for you as a byproduct of just doing their job. That's what Aikido Security can do for application and cloud security.

State of Application Security

Our View from the Front Lines of Technical Assessments Kroll analyzed five years of penetration testing data. Of the trends that emerged, we focus on three in this report: the static application security testing (SAST)/software composition analysis (SCA) plateau, the need for more attention around authentication and authorization, and the security health divergence, which shows that regulation is not a reliable predictor of attack surface health.

AI is building your software. Who's making the security decisions?

AI coding assistants are changing how software gets built. Traditional AppSec tools focus heavily on scanning the final code artifact, but as AI agents move from simple code dependencies to autonomous decision-makers and execution paths, traditional security controls enter the process too late.

How to Choose an Application Security Solution

Most teams need a combination of application security tools rather than a single one. Common categories are SAST, DAST, IAST/RASP, SCA, API and container security, and ASPM, and each covers a different stage of development. When you evaluate options, look for coverage that matches your stack, integration with developer workflows, accurate findings, risk-based prioritization, and actionable remediation guidance.

Why Application Security Testing Isn't Disappearing - and How Veracode is Shaping What Comes Next

Application security testing (AST) is the practice of scanning software for vulnerabilities using static, dynamic, and component-level analysis – then managing those flaws through remediation, validation, and certification. A new independent report from FOURCASTERS and Lionfish Tech Advisors confirms that AST is not becoming obsolete. AI and cloud platforms are changing how testing gets delivered, but the need for independent testing, flaw lifecycle management, and validation has only grown.

Mobile App Security: Reverse-Engineering APKs and IPAs to Uncover Hidden Attack Vectors

Buried in OpenAI’s evaluations of its GPT-6 Astra model sits a finding that mobile teams should sit with for a minute. The model reverse-engineered compiled software well enough to escape a browser sandbox and chain privilege-escalation flaws on a hardened operating system, according to the company’s published evaluations. Reading compiled binaries used to be specialist work priced in weeks, and now it’s something machines do quickly and well.

How attackers use AI models to find code vulnerabilities

AI models accelerate software development, but attackers use those same capabilities to hunt for pipeline vulnerabilities. Asaf Saar (EVP and Chief Product Officer, Mend.io) and Christian Jensen (VP Engineering, Tricentis) break down why full visibility is required to secure AI-native software.