Blog
Insights, research, and product updates on agentic development security.
All blog posts
- Finding 6 CVEs in Open-Source AI Tools with Apiiro AI-SAST
- Guardian Agent for Developers: Preventing and AutoFixing Agentic Development Risks
- The Cheapest Token Is the One You Never Spend
- Top 10 AI SAST Tools for Agentic Development in 2026
- Preventing the Risks AI Ships: Healthcare Organization Achieves 80% Risk Elimination with Guardian Agent
- Apiiro Named a Leader in the Gartner® Magic Quadrant™ for Software Supply Chain Security
- Introducing AI Threat Modeling: Preventing Risks Before Code Exists
- Introducing Apiiro: Reinventing the secure development lifecycle
- Detect and prevent the SolarWinds build-time code injection attack
- Top 5 tips to prevent the SolarWinds Solorigate supply chain attack
- SDLC and DevSecOps: Moving to a continuous and simultaneous model
- Rethinking DevSecOps: Moving to a risk-based SDLC
- Taking security challenges from a board-level discussion to a DevSecOps solution
- Stop treating all applications the same: Business impact and your AppSec program
- Detection and prevention of malicious commits to the PHP repository
- Code risk is multi-dimensional: How to build an AppRisk program
- Visibility in application and cloud security is ripe for innovation
- Security Alerts: Don't developers have something better to do with their time?
- The secrets about exposed secrets in code
- Shut down your application security program
- Application security is tactical. Application risk is strategic.
- Gartner continues the push for software supply chain security
- Risk-based change management for the entire SDLC
- Top 3 things we learned since winning the RSA Innovation Sandbox
- Don’t just shift left! Extend across layers with infrastructure as code security
- From phishing to developers: What are the new attack vectors?
- Better together: Security champions and application security engineers
- Part 1: What we learned about AppSec programs from the Twitch code leak
- Developer intentionally corrupts npm libraries, exposing weaknesses in OSS supply chain security
- Security during design isn't just lip service: AppSec starts at the user story
- Legacy SAST has grown stale: It’s time for a new approach
- Secure your SDLC to avoid being the source of a supply chain attack
- A leap forward in risk-based AppSec: The cloud native application protection platform (CNAPP)
- The OWASP Top 10: A new approach for cloud-native applications
- What is DevSecOps? A primer
- Detecting Secrets in Code is a Feature, Not a Solution
- Malicious Kubernetes Helm charts can be used to steal sensitive information from Argo CD deployments
- Where cloud-native AppSec mistakes are made: Known vs. unknown vulnerabilities
- Detect application architecture drift early in the SDLC
- Shift-left API security: Protect your APIs before releasing to the cloud
- What you need to know: 0-day vulnerability in Spring core framework (Spring4Shell)
- Go beyond OSS dependencies with your SBOM
- Apiiro extends right! From code to runtime
- Inside Toyota’s secret leak from a supply chain vulnerability
- How to mitigate API risks during development
- 8 key NIST guidelines in new federal regulations to be aware of
- The practical guide to software bill of materials (SBOM)
- What is static application security testing (SAST)?
- Stop wasting your time on irrelevant changes while developing software
- Dropbox developer account breached: 130 private repositories, secrets leak
- Apiiro’s AI engine detected a software supply chain attack in PyPI
- OpenSSL 3.0.7: Newest vulnerability patch aftermath
- New OpenSSL critical CVE: What you need to know
- Apiiro partners with Nuaware to transform how companies in EMEA secure their cloud applications
- Say Hello to Apiiro’s New Risk Graph™ Explorer
- Software supply chain attacks caused PyPI to temporarily suspend new users and projects
- 4 highlights from the 2023 Gartner® Innovation Insight for Application Security Posture Management (ASPM)
- Security industry veteran Moti Gindi joins the Apiiro as Chief Product Officer
- Self-enhancing pattern detection with LLMs: Our answer to uncovering malicious packages at scale
- Top 5 AppSec metrics to track, right from Apiiro's new dashboards
- The eXtended Software Bill of Materials (XBOM): A Game Changer for Application and Supply Chain Security
- Automating material code change detection for continuous compliance
- The 6 non-negotiables of reducing modern application attack surfaces
- Streamlining material code change detection and response for SEC compliance
- Unwavering empathy, resilience, and reliability during wartime challenges
- 3 dimensions of application risk you need to prioritize and reduce your alert backlog
- Go beyond detection with Apiiro’s new actionable secrets security features
- CVE-2023-4863: Leverage Apiiro to determine risk from new WebP 0-day
- ASPM breakdown: Pros and cons of different application security posture management approaches
- Uncovering shadow GenAI frameworks in your codebase with Apiiro
- Apiiro and Wiz partner to unite application and cloud security
- Introducing Apiiro SSCS: Software supply chain security with the power of ASPM
- LLM Code Authorship Detection: Unmasking Malicious Package Contributions
- PCI DSS 4.0: What it Means for AppSec and How Apiiro’s Deep ASPM Helps
- A dataset-free approach to leveraging LLMs for malicious code detection
- Apiiro + Akamai technical alliance: Complete code-to-runtime API security
- Navigate uncharted risk across your software supply chain with Apiiro's Risk Graph Explorer
- Over 100,000 Infected Repos Found on GitHub
- Apiiro + Secure Code Warrior: Uplevel your AppSec program with hyper-relevant secure code training
- Contextual prioritization funnel: Narrow-in on real, business-critical app risks with Apiiro
- Streamlining application risk response for the enterprise with ServiceNow integration
- Omdia Application Security Posture Management Market Landscape: 4 Key ASPM Questions Answered
- From metrics to meaning: Optimizing your AppSec program with Apiiro Reports
- Introducing AI-Driven Risk Detection at Design Phase: Revolutionizing AppSec with AI-Powered Pre-Code Security
- Cementing our open ASPM platform commitment with our new integrations program, SHINE
- Apiiro Leads the Charge in Secure by Design: Among First 25 to Sign America's Cyber Defense Agency Pledge
- ASPM's Secret Weapon: AI-Powered Code-to-Runtime Software Inventory
- Apiiro's Countdown to Black Hat USA 2024
- Unifying Offensive And Defensive AppSec With Apiiro + Bugcrowd
- Apiiro and Aerowave Join Forces to Revolutionize Application Security
- Aligning Teams, Managing Risks: Boost Your AppSec Program with Apiiro Organizational Teams & Custom Reports
- Enable AppSec Enhancements by Apiiro with Comprehensive Identity Matching
- New from Apiiro: Detect and Address AppSec Risks with Apiiro Native LLM Models Before Code is Even Written
- Fortune 100 Insurance Provider Projected to Save $3M in Security Savings with AppSec Automation, and the 2nd-Largest ASPM Deal in History
- Revolutionizing Application Security: Apiiro Unveils Groundbreaking Code-to-Runtime Technology
- A Year of Collaboration: Apiiro and Akamai Technical Alliance Strengthen
- Introducing Code-to-Runtime: Enriching AppSec with True End-to-End Visibility
- Apiiro Lands the Largest ASPM Deal in the Market with a Fortune 10 Global Enterprise
- ASPM Overview Dashboard: Empowering AppSec Leadership
- Drive Application Risk Reduction with Apiiro’s Team Leaderboard
- ASPM vs. CSPM: Key Differences, Overlaps, and Choosing the Right Approach
- Closing the Loop Between Application and Infrastructure Security with Our New Tenable Integration
- ASPM vs ASOC: Unveiling the Key to Application Security Success in 2025
- Best 10 Container Security Tools for 2025
- Top 7 ASPM Best Practices for Building Robust Application Security
- Gartner on ASPM: What it Means for Your Security Strategy
- What is Agentic AI?
- Faster code, greater risks: The security trade-off of AI-driven development
- CI/CD Pipeline Security: Best Practices to Safeguard Your Software Supply Chain
- Agile Penetration Testing: Adapting Scope and Targets through Material Code Change Detection
- AppSec Is a Data Problem
- Continuous, Accurate Threat Modeling Is Now a Reality with Apiiro’s Software Graph Visualization
- Introducing Software Tech Stack Inventory: The Foundation of Scalable AppSec
- Visual Intelligence for Software Risk: Introducing Software Graph Visualization from Apiiro
- Top 8 Continuous Security Monitoring Tools for 2025
- Mitigating SCA Vulnerabilities: Strengthening Your Software Supply Chain for Maximum Security
- Agentic AI Risk Management: What Every CISO Needs to Know in 2025
- The top software security standards for modern applications
- AI-Generated Code Security: Security Risks and Opportunities
- Gartner® Publishes First-Ever Market Guide for Software Supply Chain Security—Here’s Why ASPM is Included
- How to Strengthen Security in AI-Driven Software Engineering
- Webinar Recap: Reimagining Application Security Posture Management
- How to Run an Application Vulnerability Scanning: Step by Step
- Practical prevention of the next supply chain attack: Lessons from the tj-actions/changed-files Incident
- Application Security vs. Product Security: Key Differences, Pros, and Cons
- Gartner Warns of Growing API Security Gaps—And AI-Driven Development Is the Cause
- Gartner Highlights the Growing Importance of ASPM – Here’s How Apiiro Stands Out
- Web application security testing checklist: steps + real-world breach examples
- Introducing Apiiro’s Code-to-Runtime Integration for ServiceNow CMDB
- The 16 best infrastructure as code (IaC) tools in 2025
- The Latest Shai-Hulud Ongoing Package Supply Chain Worm
- Best practices for integrating agentic AI into app security
- Apiiro Recognized as a Leader in the 2025 IDC MarketScape for Application Security Posture Management
- Top 11 code security tools in 2026 every security team should evaluate
- Securing code with Cursor and Windsurf: advanced vulnerability detection & remediation
- Nx Supply Chain Breach Shows Why Malicious Package Detection Matters
- Toward Secure Code Generation with LLMs: Why Context Is Everything
- Just Released: The 2025 Gartner Hype Cycle for Application Security – Featuring Apiiro
- A Completely New Way to Fix Design and Code Risks: Meet Apiiro’s AutoFix Agent
- Preventing Incidents at Scale: Introducing Apiiro’s AutoFix Agent
- Moving from AppSec to ASPM: the evolution of application security
- 4x Velocity, 10x Vulnerabilities: AI Coding Assistants Are Shipping More Risks
- PBOM vs SBOM – Building a Complete Security Bill of Materials
- Why generative AI security remains the blind spot for application security teams
- Vibe coding security vulnerabilities best practices: protecting your applications
- Why ~50% of CVEs in the Last 6 Months Trace Directly to Code‑Level Vulnerabilities
- How to detect and prevent application security vulnerabilities in modern apps
- Webinar Recap: Aligning CMDB and Vulnerability Response with Real-Time Code Context
- Secure vibe-coding is an oxymoron: Here’s how to change that
- AI Software Composition Analysis: How to Maximize Security and Compliance in Modern Development
- 11 best SAST tools for 2025: how to choose the right SAST solution
- GenAI is already in your code — what’s at risk depends on your industry
- Secure Software Design: Best Practices to Build Safe, Resilient Applications
- Shai-Hulud 2: A New Wave of npm Supply Chain Malware Targeting Developers and CI/CD Systems
- How to Detect and Stop Source Code, Data, and Secrets Exposure
- 10 Best Practices That Will Transform Your Code Review Processes
- 12 Best Open Source Vulnerability Management Tools for 2026
- Apiiro Welcomes Former GitHub CEO Thomas Dohmke as Strategic Advisor to Safeguard AI Before Code Generation and Prevent Risks at Enterprise Scale
- Critical Vulnerability – RCE in React Server Components & Next.js
- Application Security Risk Assessment: The Complete 2026 Checklist for Dev Teams
- Why 2026 Demands Better Application Security Training for Developers
- Building Bridges Between Security and R&D: Apiiro’s Continuous Investment in Finding the Right Code Owner
- Webinar Recap: The Evolution of AppSec for the AI Era
- Gartner Ranks Apiiro #1 in ASPM in 2025 Magic Quadrant for Application Security Testing (AST)
- Top 10 Application Security Testing Tools for 2026
- The Top Code Execution Risks in Agentic AI Systems in 2026
- Confidence in Agentic Code Fixes is rising – but not without a strong ASPM program
- Modern Application Security Best Practices for an AI-Driven SDLC
- Introducing Apiiro’s New OSS Licenses Experience
- Securing AI-Assisted Software Development: Google + Apiiro
- Secure and Govern Your AI Early — Before It Becomes a Production Risk
- Multi-Agent Networks in Application Security: Strategies & Benefits
- Apiiro Achieves True Runtime API Endpoint Matching
- Why SAST and SCA Together Still Leave High-Risk Gaps
- What DORA Means for Security and Risk Teams in 2026
- A Triple Recognition: After Gartner and IDC, Apiiro Named the Most Innovative ASPM Provider Worldwide in Frost & Sullivan’s 2025 Frost Radar™
- Key Benefits of Application Security Testing Orchestration for Engineering Teams
- How to Choose the Best Code Security Platform for Your Team
- Introducing the SDLC System of Record (SoR): Unified, Audit-Ready Supply Chain Compliance
- AI Is Writing the Code. Who’s Securing It? A Conversation with Thomas Dohmke
- Cybersecurity Threat Assessment: A Step-by-Step Guide for AppSec Teams
- OWASP Israel Panel: AI Velocity and the Breaking Point of Security Frameworks
- Introducing OSS Package Reputation & Health Insights in Apiiro: Open-Source Ease and a Secure SDLC
- Apiiro is Recognized as an Application Security Platform Leader in the Latio 2026 AppSec Report
- Why Open Source License Compliance Is Now Your AppSec Team's Problem
- Gartner Report on Guardian Agents Signals a New Era for AI Governance
- Best 16 DevSecOps Tools (And How To Choose the Right One)
- Extended Security Posture Management vs ASPM: What's the Real Difference?
- Best 8 DevOps Security Tools for Modern CI/CD Pipelines
- Panel Discussion: How AI Is Redefining Development Speed and Security
- Introducing Apiiro Guardian Agent: Preventing Vulnerable and Non-Compliant Code from Ever Being Created
- Guardian Agent: Guard AI to Generate Compliant Code with Zero Vulnerabilities
- Application Security Automation: Why Context Matters More Than Coverage
- More Code = Wider Attack Surface: AI Coding Assistants Deliver Productivity at the Cost of More Endpoints and More OSS Sprawl
- 10 Best DAST Tools for Modern Application Security Testing
- STRIDE vs. DREAD vs. PASTA: Choosing the Right Threat Modeling Framework
- Apiiro AI-SAST: Static Scanning Reimagined – From Code to Runtime – for the AI Era
- Why DAST Tools Miss Real IDOR Vulnerabilities (And How AI Helps)
- 60-Second Read: AI-Assisted Coding, Vibe Coding, and Agentic Coding Explained
- When Static Rules Met a Dynamic Attack Surface: Why AI Coding Assistants Must Think Like the AI Era – Not Like 80s Firewalls
- Secret Detection in Application Security: How Teams Actually Prevent Credential Leaks
- Introducing Apiiro AI-SAST: Static Scanning Reimagined – From Code to Runtime
- Security Tools Were Built for Humans. We Built One for AI Agents. Introducing Apiiro CLI
- Introducing AI Threat Modeling
- Half of Google's Code Is Now AI-Generated. Here's What That Means for Security Leaders.