60-Second Read: AI-Assisted Coding, Vibe Coding, and Agentic Coding Explained

Timothy Jung
December 19 2025

Why Read This? Ask ten people what AI-assisted coding, vibe coding, or agentic coding mean – and you’ll likely get ten different answers. These terms are often mixed together, even though they describe very different ways of building software, aimed at very different audiences. The goal of this short read is to remove the confusion. […]

Introducing Apiiro AI-SAST: Static Scanning Reimagined – From Code to Runtime

Matan Giladi, Neta Coral
December 18 2025

Static Application Security Testing (SAST) is a legacy technology, invented decades ago and largely unchanged since. With the rapid adoption of AI coding assistants and agentic coding tools, development velocity and the application attack surface have increased exponentially, pushing traditional SAST beyond its breaking point. What was once an application security engineer and developer problem […]

Apiiro Achieves True Runtime API Endpoint Matching

Karen Cohen, Ella Bor
December 10 2025

AppSec teams face an explosion of API-related risks that are difficult to track, prioritize, and remediate. Many ASPM providers claim they offer true code-to-runtime endpoint matching, but in a best-case scenario, they can only match the runtime host or project to its code application or repository – not to the specific line of code. This […]

A Triple Recognition: After Gartner and IDC, Apiiro Named the Most Innovative ASPM Provider Worldwide in Frost & Sullivan’s 2025 Frost Radar™

Timothy Jung
December 9 2025

Frost & Sullivan has named Apiiro the most innovative Application Security Posture Management (ASPM) provider worldwide, recognizing Apiiro’s unique ability to prioritize the needs of an enterprise customer base while also pushing the envelope on AppSec innovation. This distinction reinforces Apiiro’s position as the most innovative ASPM company — not just for building groundbreaking technology, […]

Critical Vulnerability – RCE in React Server Components & Next.js

Nadav Shakarzy
December 4 2025

On December 3, 2025, coordinated disclosures revealed critical remote code execution (RCE) vulnerabilities in React Server Components (RSC) and Next.js: At the core, the issue is unsafe deserialization in the RSC “Flight” protocol. With a single crafted HTTP request to an exposed RSC / Server Function endpoint, an attacker can reach pre-auth arbitrary code execution […]

Shai-Hulud 2: A New Wave of npm Supply Chain Malware Targeting Developers and CI/CD Systems

Nadav Shakarzy
November 25 2025

A new and significantly more aggressive wave of Shai-Hulud malware is rapidly propagating across the npm ecosystem. Known as Shai-Hulud 2, this campaign is infecting hundreds of open-source packages with a trojanized preinstall script that executes an obfuscated Bun-based payload. Once activated, the malware steals sensitive credentials—including API tokens, SSH keys, cloud access keys, and […]

Apiiro Welcomes Former GitHub CEO Thomas Dohmke as Strategic Advisor to Safeguard AI Before Code Generation and Prevent Risks at Enterprise Scale

Idan Plotnik
November 24 2025

The software industry is in the middle of its most profound shift. AI is no longer an assistant on the sidelines; it is writing the majority of new code across modern engineering organizations in Fortune 500 enterprises. This pace unlocks incredible innovation, but it also introduces unprecedented risk. Today, I’m excited to share that Thomas […]

How to Detect and Stop Source Code, Data, and Secrets Exposure

Nadav Shakarzy
November 10 2025

When it comes to threats to source code, inadvertent leaks are far more common than open theft. Robust governance is the best way to identify and stop potential source code exposures – but shifts in security priorities have made this difficult, even for the largest organizations. Cloud-based source control systems, muddled identity models and democratized […]

Confidence in Agentic Code Fixes is rising – but not without a strong ASPM program

Timothy Jung
October 30 2025

The latest analysis from 451 Research and Daniel Kennedy indicates that security leaders are citing a lack of coordination between AST tools as a major pain point – and the complexity of application security tools is the #1 issue for InfoSec experts today. The Rise of Agentic AI — and the New Security Imperative In […]