Why Critical Doesn’t Always Mean Urgent

AppSec teams aren’t failing to find risk in their applications, they’re overwhelmed by it. A constant flood of critical alerts, false positives, and disconnected security findings has created a severe signal‑to‑noise problem, making it nearly impossible to distinguish business risk from background static. Every commit now triggers a chain reaction of scans across SAST, SCA, […]
Et Tu, RDP? Detecting Sticky Keys Backdoors with Brutus and WebAssembly

Regardless of whether the cause is a malicious file replacement or a vulnerable VPN client, the enabler is the absence of Network Level Authentication (NLA). This is often flagged in Nessus as “Terminal Services Doesn’t Use Network Level Authentication (NLA) Only” (Plugin ID 58453). Without NLA, the server initiates a full, resource-intensive graphical session (the […]
Angular SSR Vulnerability Enables SSRF

A critical vulnerability has been discovered in Angular Server-Side Rendering (SSR) that could allow attackers to manipulate request handling and trigger unauthorized server-side requests. Tracked as CVE-2026-27739, the vulnerability arises from how Angular SSR reconstructs request origins using HTTP headers such as Host and X-Forwarded-*. In affected versions, these headers were not strictly validated before being used to build request URLs. […]
The 89% Problem: How LLMs Are Resurrecting the « Dormant Majority » of Open Source

AI coding assistants are quietly resurrecting millions of abandoned open source packages. For the last decade, developers relied on a simple heuristic for open source security: Prevalence \= Trust. If a package was downloaded millions of times a week (lodash, react, requests), we assumed it was « safe enough » because thousands of eyes were on it. […]
Confident Developers Are the New Security Risk

AI coding tools have fundamentally changed how software gets built. After attending and speaking with security and development leaders at OnPoint Ski & Snowboard CyberCon 2026, one theme stood out to me: teams are shipping more code, in more languages, across more projects than ever before. Features that used to take days now take minutes and complex logic can be scaffolded from […]
The State of New York Prohibits Credit Information in Employment Decisions

On April 18, 2026, the state of New York employers are prohibited from utilizing credit information in employment related decision-making (with a few exceptions). This new Senate Bill S3072 mirrors what New York City has been doing for years in the SCDEA Act or the Stop Credit Discrimination in Employment Act.
The Evolution of OSS Index in the Age of AI

In the past 12 months, enterprise software development has changed faster than at any other point in our lifetime. *** This is a Security Bloggers Network syndicated blog from 2024 Sonatype Blog authored by Mitchell Johnson. Read the original post at: https://www.sonatype.com/blog/the-evolution-of-oss-index-in-the-age-of-ai Source link
Axios DoS Vulnerability in Node.js Apps

A newly disclosed vulnerability tracked as CVE-2026-25639 puts Node.js applications using Axios at risk of remote Denial-of-Service attacks. By sending a specially crafted configuration object, attackers can trigger a fatal runtime error inside Axios’s internal request handling logic, causing the Node.js process to crash instantly. While Axios is commonly used in both browsers and backend […]
Snyk and uv, Better Together
Python powers today’s AI revolution, from machine learning frameworks to agentic workflows and data science pipelines. But for years, Python’s packaging ecosystem has lagged behind developer expectations: slow installs, painful dependency resolution, and tooling fragmentation. This is where uv comes in. And now, paired with Snyk, teams can ensure speed doesn’t come at the cost […]
Why Claude’s Announcement Signals a Bigger Shift

Let’s start this article by stating that the launch of Claude Code Security is good news for the industry. Not because it replaces traditional application security. Not because it suddenly makes AI-generated code safe. But because it validates something many security leaders already know: AI coding introduces new risks that require AI-native, agentic application security. In an era where code is […]
