#AppSec
11 stories taggedAppSec.

CodeSecCon Brings Developers and Security Teams Together to Fix a Growing Blind Spot
A virtual conference focused on building safer software is drawing both coders and cybersecurity professionals to the same table, a pairing that rarely happens and badly needs to.

AI is getting better at breaking software than fixing it
Multiple studies show artificial intelligence tools write insecure code nearly as often as they did a year ago, even as those same tools grow sharper at finding and exploiting the very flaws they leave behind.

AI Coding Tools Carry Real Security Risks, and the Danger Depends on What You're Building With
A new study tested 16 major AI coding assistants and found an average of 15 security flaws per project. The safest choice for one type of software can be one of the worst for another.

From Prevention to Resilience: Cybersecurity’s New Paradigm
As breaches become inevitable, organizations must focus on operational resilience, not just perimeter defense.

OpenAI Hands GPT-5.5-Cyber to 'Trusted Defenders' Under Daybreak
The model is pitched at deep codebase analysis and vuln patching. The interesting part is who gets access — and what shows up in the post-mortem when they don't.

AWS Continuum Wants to Close the Gap Between AI-Generated Code and AI-Fixed Vulnerabilities
Amazon's new agentic security service promises continuous discovery, triage, and remediation. In practice, it's a bet that the same AI acceleration creating your backlog can also drain it.

AI Red Teaming Grew Up. The Job Description Is Still Being Written.
The tools broke when LLMs arrived. Now the discipline is rebuilding itself in real time — and the threat model includes teenagers with too much free time.

Knowingly Shipping Vulnerable Code Has Become Standard Practice, Survey Finds
A Checkmarx survey of 2,350 security leaders finds nearly half of production code is AI-generated — and enterprises are deploying it despite knowing it carries unresolved flaws.

Mythos Isn't Vapor: Inside the SAST Tool Quiet-Skeptics Are Starting to Believe
A short defense of a controversial static analysis startup, and what its findings actually look like under the hood.

Shadow Builders: When Employees Ship Production Apps Without Auth
Vibe-coded internal tools are graduating to public URLs, and most identity stacks never see them coming.

Google Repositions CodeMender within AI Ecosystem
Shift from standalone security tool to integrated AI agent marks strategy pivot.