#software-security

[ follow ]
Software development
fromTNW | Apps
2 days ago

GitLab 19.0 targets the gap between writing code and shipping it

GitLab 19.0 expands Duo agent orchestration across the software lifecycle and adds SBOM-based dependency scanning plus new AI model integrations.
Software development
fromZDNET
3 days ago

You can't install Deepin Desktop from the official Fedora repo anymore - here's why

SUSE and Fedora removed Deepin packages after policy violations and bypassed security review mechanisms, leaving strict code review as the only path forward.
Software development
fromZDNET
3 days ago

Linus Torvalds admits he has a 'love-hate relationship with AI'

AI tools increase Linux kernel contribution volume but introduce new social and security stresses; programmers remain essential and release stability has shifted recently.
#vibe-coding
fromMarTech
5 days ago
Software development

Risks to look out for when using vibe coding to replace SaaS | MarTech

fromIT Pro
6 months ago
Artificial intelligence

Vibe coding security risks and how to mitigate them

Vibe coding accelerates software creation but frequently produces insecure code and can introduce vulnerabilities, compliance gaps, and technical debt.
fromIT Pro
7 months ago
Artificial intelligence

Is vibe coding the future?

Vibe coding speeds development but reduces developer oversight and context, increasing vulnerability risk unless governance, auditing, and full SDLC practices are integrated.
Software development
fromMarTech
5 days ago

Risks to look out for when using vibe coding to replace SaaS | MarTech

Vibe coding can cut costs but increases quality, security, integration, and maintenance risks without planning and oversight.
Information security
fromArs Technica
6 days ago

Bug bounty businesses bombarded with AI slop

AI-generated bug reports are flooding bug bounty programs with false, low-quality submissions, forcing some companies to suspend or change these schemes.
Information security
fromtheregister
1 week ago

Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits

AI-based code scanning is rapidly increasing vulnerability discovery, driving more patches and greater administrative workload while raising risks if patches break systems.
Information security
fromSecurityWeek
1 week ago

Adobe Patches 52 Vulnerabilities in 10 Products

Adobe released patches for 52 vulnerabilities across 10 products, including critical flaws enabling arbitrary code execution and privilege escalation.
Information security
fromtheregister
1 week ago

Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged

A modified Checkmarx Jenkins AST plugin was published on the Jenkins Marketplace, and untrusted versions must be replaced with the verified release.
Information security
fromTechzine Global
2 weeks ago

Mozilla: AI-powered bug detection produces very few false positives

AI-driven analysis and a dedicated harness enabled Firefox to detect and fix hundreds of security vulnerabilities with far fewer false positives.
#ai-assisted-development
Software development
fromDevOps.com
2 weeks ago

The Messy Reality of Vibe Coding - DevOps.com

AI-assisted development increases risk visibility when paired with safety systems, review, and multi-model cross-checking rather than blanket bans or panic.
Software development
fromDevOps.com
2 weeks ago

The Messy Reality of Vibe Coding - DevOps.com

AI-assisted development increases risk visibility when paired with safety systems, review, and multi-model cross-checking rather than blanket bans or panic.
Soccer (FIFA)
fromFast Company
2 weeks ago

Mythos AI may be a cybersecurity threat, but it follows the rules of the game

Claude Mythos Preview demonstrated unprecedented vulnerability discovery capabilities, finding thousands of zero-day exploits, but represents an acceleration of existing threats rather than a fundamentally new cybersecurity risk.
DevOps
fromInfoQ
2 weeks ago

Leading Open Source Author Calls for Verification over Trust in Software Supply Chains

Software security must prioritize verification over trust, with curl implementing extensive controls including code review, complexity limits, and 200+ CI jobs to prevent compromise at scale.
#cybersecurity
Information security
fromSecurityWeek
1 month ago

Are SBOMs Failing? Supply Chain Attacks Rise as Security Teams Struggle With SBOM Data

SBOMs and VEX statements fail to enhance software supply chain security due to poor decision-making and inconsistent interpretation of available data.
#ai
Artificial intelligence
fromwww.cbc.ca
1 month ago

Anthropic's latest AI model is sparking fears from cybersecurity experts and the banking sector. Here's why. | CBC News

Mythos, Anthropic's advanced AI model, poses cybersecurity risks by uncovering vulnerabilities faster than they can be fixed.
fromTechCrunch
1 month ago
Information security

Anthropic debuts preview of powerful new AI model Mythos in new cybersecurity initiative | TechCrunch

Anthropic released Mythos, a powerful AI model for cybersecurity, to select partners for scanning software vulnerabilities under Project Glasswing.
fromSecurityWeek
1 month ago
Venture

Depthfirst Raises $80 Million in Series B Funding

Depthfirst raised $80 million in Series B funding, totaling $120 million, to enhance software security with its new AI model Dfs-mini1.
Artificial intelligence
fromwww.cbc.ca
1 month ago

Anthropic's latest AI model is sparking fears from cybersecurity experts and the banking sector. Here's why. | CBC News

Mythos, Anthropic's advanced AI model, poses cybersecurity risks by uncovering vulnerabilities faster than they can be fixed.
Information security
fromTechCrunch
1 month ago

Anthropic debuts preview of powerful new AI model Mythos in new cybersecurity initiative | TechCrunch

Anthropic released Mythos, a powerful AI model for cybersecurity, to select partners for scanning software vulnerabilities under Project Glasswing.
Venture
fromSecurityWeek
1 month ago

Depthfirst Raises $80 Million in Series B Funding

Depthfirst raised $80 million in Series B funding, totaling $120 million, to enhance software security with its new AI model Dfs-mini1.
#open-source
Python
fromThe Hacker News
1 month ago

The State of Trusted Open Source Report

AI is reshaping software development and security, influencing container image usage and vulnerability management.
Python
fromThe Hacker News
1 month ago

The State of Trusted Open Source Report

AI is reshaping software development and security, influencing container image usage and vulnerability management.
Information security
fromTechzine Global
2 months ago

Chainguard introduces a secure catalog for agent skills

Chainguard launches Agent Skills service to secure AI agent components in software development, addressing supply chain vulnerabilities from malicious skills shared across open platforms.
Information security
fromSecurityWeek
2 months ago

OpenAI Rolls Out Codex Security Vulnerability Scanner

OpenAI launches Codex Security, an AI vulnerability scanner that identifies complex security issues and proposes patches, now available to ChatGPT Pro and Enterprise customers with free access for one month.
#ai-assisted-coding
fromZDNET
4 months ago
Software development

Why your coding skills are more essential than ever in the AI age

fromZDNET
4 months ago
Software development

Why your coding skills are more essential than ever in the AI age

Information security
fromTheregister
3 months ago

Dutch defense chief: F-35s can be jailbroken like iPhones

The Netherlands' defense secretary claimed F-35 software can be jailbroken like an iPhone, implying European operators could modify it without US permission.
fromSecurityWeek
3 months ago

How to Eliminate the Technical Debt of Insecure AI-Assisted Software Development

This extends to the software development community, which is seeing a near-ubiquitous presence of AI-coding assistants as teams face pressures to generate more output in less time. While the huge spike in efficiencies greatly helps them, these teams too often fail to incorporate adequate safety controls and practices into AI deployments. The resulting risks leave their organizations exposed, and developers will struggle to backtrack in tracing and identifying where - and how - a security gap occurred.
Artificial intelligence
Information security
fromTheregister
3 months ago

How the GNU C Compiler became the Clippy of cryptography

Modern compilers optimize away security protections, causing constant-time and other defensive code to fail and reintroducing side-channel vulnerabilities.
Software development
fromTheregister
3 months ago

Dev used Claude to build TrapC, memory-safe extension of C

TrapC, a memory-safe C variant with interpreter itrapc and compiler trapc, is nearly ready for testing; code complete and debugging targets a Q1 2026 release.
Information security
fromComputerWeekly.com
4 months ago

Cyber body ISC2 signs on as UK software security ambassador | Computer Weekly

ISC2 joined the UK Software Security Ambassador Scheme to advise on promoting secure-by-design practices and supporting adoption of the Software Security Code of Practice.
#ai-code-generation
fromIT Pro
8 months ago
Software development

Senior developers are all in on vibe coding, but junior staff lack the experience to spot critical flaws

fromIT Pro
8 months ago
Software development

Senior developers are all in on vibe coding, but junior staff lack the experience to spot critical flaws

Software development
fromTheregister
4 months ago

Microsoft wants to replace its entire C and C++ codebase

Microsoft plans to replace its C and C++ codebase with Rust by 2030 using AI-driven translation tools and hiring engineers to build the necessary infrastructure.
#generative-ai
fromDevOps.com
8 months ago
Software development

Coding at the Speed of AI: Innovation, Vulnerability, and the GenAI Paradox - DevOps.com

fromDevOps.com
8 months ago
Software development

Coding at the Speed of AI: Innovation, Vulnerability, and the GenAI Paradox - DevOps.com

fromTheregister
5 months ago

AWS announces trio of autonomous AI agents for developers

AWS claims the vibe coding IDE Kiro is designed to avoid all the pitfalls of letting AI do your development, like surprise drive deletions and database wipeouts. Users will have to put a lot of trust in those claims. Aside from those worst-case scenarios, AWS is fully aware that AI coding tools have "introduced new friction" into developers' workloads. "You can find yourself acting as the human 'thread' that holds work together," AWS said, describing scenarios like contextualizing tasks, manually coordinating cross-repository changes, and collating information across tickets and pull requests.
Artificial intelligence
fromenglish.elpais.com
5 months ago

Adriana Groh: The internet works thanks to a shared infrastructure that nobody owns, but that we must take care of'

All programmers, from hobbyists to those working at Microsoft or Google, use open-source software, which is present in between 70% and 90% of the computer applications we use today. No one starts a project from scratch; instead, they turn to libraries like GitHub or GitLab to download packages of code already written, reviewed, and improved by the community. Developers spend an average of two-thirds of their time adapting open-source software to their needs, and they build their application on top of that.
Germany news
fromApp Developer Magazine
1 year ago

Safe c plus plus proposal abandoned after community pushback

The Safe C++ proposal, which sought to introduce a memory-safe subset of the language inspired by the guarantees found in newer languages like Rust, has been abandoned by its lead author. This development occurs as pressure mounts from government agencies and industry leaders to address critical vulnerabilities often found in legacy codebases, which form the backbone of global digital infrastructure.
Tech industry
from24/7 Wall St.
6 months ago

JFrog (FROG) Is Up 24% Today: 3 Things We Learned From Earnings

JFrog (NASDAQ: FROG) stunned investors with a blowout third quarter that sent shares soaring more than 24%. The DevOps platform provider not only delivered its eighth straight beat on both revenue and earnings but also showcased accelerating cloud adoption, record profitability, and a growing foothold in AI-driven software delivery. Here are three key takeaways from the results and management's commentary.
Software development
Information security
fromInfoWorld
6 months ago

OpenAI launches Aardvark to detect and patch hidden bugs in code

Aardvark integrates into development pipelines to provide continuous, automated vulnerability analysis, repository-wide threat modeling, and sandboxed exploit validation.
fromTechCrunch
8 months ago

Vibe coding has turned senior devs into 'AI babysitters,' but they say it's worth it | TechCrunch

She called vibe coding a beautiful, endless cocktail napkin on which one can perpetually sketch ideas. But dealing with AI-generated code that one hopes to use in production can be "worse than babysitting," she said, as these AI models can mess up work in ways that are hard to predict. She had turned to AI coding in a need for speed with her startup, as is the promise of AI tools.
Software development
fromDevOps.com
8 months ago

Warp Embeds AI Agents into a CLI to Provide Better Feedback Loop - DevOps.com

Warp has added a version of its artificial intelligence (AI) agent for writing code that integrates directly within a command line interface (CLI). Company CEO Zach Lloyd said rather than working with AI agents within the context of an integrated development environment, Warp Code embeds AI agents with a CLI that is likely to prove more appealing to some developers and many DevOps engineers that prefer a traditional terminal-based coding experience.
Artificial intelligence
fromeLearning Industry
9 months ago

Secure Your eLearning Software: 10 Steps To Lock It Down Before Launch

Launching an eLearning platform without securing software can lead to cyberattacks, data leaks, and malware infections, jeopardizing user safety and brand reputation.
Online learning
Artificial intelligence
fromDevOps.com
9 months ago

ArmorCode Extends AI Tool to Generate Code Fixes for Specific Runtime Environments - DevOps.com

ArmorCode introduced new features for its Anya AI tool to enhance code remediation, supply chain visibility, and collaboration between development and cybersecurity teams.
fromIT Pro
10 months ago

Developers face a torrent of malware threats as malicious open source packages surge 188%

"Attackers are no longer simply experimenting with open source. The numbers are telling us that threat actors have identified data as the most profitable target, and developers as the easiest way in."
Privacy technologies
DevOps
fromVuejobs
10 months ago

Intermediate Fullstack Engineer (Ruby/vue.js), Software Supply Chain Security: Pipeline Security at GitLab

GitLab emphasizes collaborative software development to enhance organizational security and efficiency through AI-driven innovation.
Artificial intelligence
fromIT Pro
11 months ago

AI-generated code is in vogue: Developers are now packing codebases with automated code - but they're overlooking security and leaving enterprises open to huge risks

The rise of AI in development is leading to codebases that are predominantly AI-generated.
fromIT Pro
11 months ago

Shifting left might improve software security, but developers are becoming overwhelmed - communication barriers, tool sprawl, and 'vulnerability overload' is causing serious headaches for development teams

"Everyone talks about shifting left, but few are seeing the security gains they expected. Most organizations have tools in place, but they still struggle with noise, process friction, and developer resistance."
Software development
Software development
fromDevOps.com
11 months ago

Futurum Group Survey Surfaces DevSecOps Progress on Multiple Fronts - DevOps.com

Investments in software supply chain security are critical, with ASPM and DevSecOps automation being top priorities.
[ Load more ]