Composition Analysis stories
Sonatype says smaller AI tied to live software data can outsecure larger models on dependency upgrades, slashing risk and cost.
Cloudsmith adds automated controls to quarantine and block risky dependencies, tightening enforcement on software supply chain security.
Veracode unveils an AI-driven tool that automatically fixes open-source vulnerabilities, tackling mounting security debt in software supply chains.
Keysight debuts SBOM Manager to automate software bills of materials as EU and US cyber rules tighten transparency and compliance demands.
Harness has launched AI Security and Secure AI Coding tools to spot and block vulnerabilities in AI-powered apps and AI-generated code.
ActiveState launches Curated Catalog, a private, pre-vetted open source repository to tighten software supply chain security for enterprises.
Manifest unveils SBOM generator for unmanaged C and C++ code, tackling critical supply chain blind spots in embedded and safety systems.
ActiveState appoints seasoned open source leader Abby Kearns as Chief Executive, sharpening its focus on managed open source security.
Secure.com warns most apps hide critical flaws in open source components, as unpatched dependencies and licence risks leave firms exposed.
Endor Labs unveils AURI, a security intelligence platform embedding reachability-led checks into AI coding assistants and CI/CD pipelines.
Manifest research reveals executives overestimate AI security readiness, as AppSec teams warn of unmanaged tools, blind spots and rising risk.
Security debt hits 82% of organisations as legacy flaws linger over a year, with third-party code driving most critical vulnerabilities.
Rapid AI and cloud adoption is fuelling a new wave of cyber risk, as Tenable warns of exposed software supply chains and “ghost” identities.
ActiveState launches a 79m-component secure open source catalogue to centralise software supply chains and cut enterprise vulnerability risk.
Armis launches AI-native Centrix platform to secure application code, aiming to cut false alarms and safeguard AI-assisted development.
Veracode upgrades its Package Firewall and testing tools to block malicious software packages before they enter development pipelines.
AI adoption is set to double ROI by 2026 as businesses move to focused integration amid security challenges, says Harness Field CTO Martin Reynolds.
Backslash adds cross-tool governance to discover, vet and monitor 'Skills' powering AI coding assistants like Cursor, Claude Code and Copilot.
Endor Labs acquires Autonomous Plane to add reachability-led container image analysis, promising fewer false positives for security teams.
Fragmented security tools and manual remediation overload developers, causing burnout that threatens productivity and cybersecurity in fast-paced AI-driven workplaces.