#software security
9 stories taggedsoftware security.

Zhipu's GLM-5.3 AI Model: A Double-Edged Sword in Cybersecurity
Zhipu's new AI model excels at finding security flaws but raises concerns about misuse.

Your GitHub activity logs are a smoke detector you forgot to switch on
Two researchers showed at Black Hat USA 2026 that the evidence needed to catch software supply-chain attacks has been sitting inside GitHub all along. Their open-source tool turns that evidence into working alerts.

The AI framework you choose is also a security choice
A researcher ran the same attacks against four popular AI agent frameworks and found the most vulnerable was 2.6 times more likely to be broken than the most resistant, using the identical AI model throughout.

CISA Publishes Open Source Security Playbook for Federal Agencies
The new guidance lays out how agencies should vet, use, and publish open source code, and introduces a trust framework called C4.

Cisco's Antares AI Helps Code Reviewers Find Vulnerabilities Faster
Cisco introduces the Antares AI models to streamline the process of finding potential security issues in large code repositories.

Cisco Builds Cheaper AI Tools to Hunt Security Flaws in Software Code
The company's new Antares models scan source code for known vulnerabilities at a fraction of what larger AI systems cost. Here is what that means for businesses that write or buy software.

Capital One Releases Free AI Security Tool That Hunts Down Code Flaws Automatically
VulnHunter scans software for exploitable weaknesses and suggests fixes. The bank is giving it away free, arguing no single company can solve this problem alone.

Five Government Agencies Tell Software Makers: Open a Front Door for Bug Reporters
CISA and four allied agencies have published a joint guide urging tech companies to set up formal programmes so security researchers can safely report flaws before criminals find them first.

Security Debt Is Growing Faster Than Companies Can Fix It. Here Is What That Means.
Eight in ten organisations are sitting on a backlog of unresolved security flaws that stretch back more than a year. A practical framework, first outlined in CSO Online, explains how to turn that problem into a board-level conversation.