AI SAST: Code Security for the Agentic SDLC
Endor Labs has launched an AI-powered Static Application Security Testing (SAST) tool for C code that detects more vulnerabilities than traditional scanners without requiring a software build. By comb…
Endor Labs has launched an AI-powered Static Application Security Testing (SAST) tool for C code that detects more vulnerabilities than traditional scanners without requiring a software build. By comb…
A critical sandbox escape vulnerability in isolated-vm, a JavaScript library downloaded over 1 million times per week and used in AI agent frameworks including n8n, Sim.ai, Mastra, and Activepieces, w…
A developer built sentrymcp, a static and runtime security scanner for MCP servers, in Rust. The tool detects code vulnerabilities, tool poisoning, and missing authentication, and includes a runtime p…
GitHub introduced four agent apps—Amplitude, Endor Labs, LaunchDarkly, and PagerDuty—that integrate software delivery workflows directly into GitHub, enabling developers to scope, secure, roll out, an…
A Stanford randomized trial found that developers using an AI assistant wrote SQL-injection-vulnerable code 36% of the time versus 7% for the control group, yet rated their own code as more secure, an…
Endor Labs found that OpenAI's GPT-5.5 scored 61.5% functional correctness in its native Codex harness but 87.2% in Cursor's harness, a 25.7-point swing, while Anthropic's Opus 4.7 scored 87.2% in Cla…
Endor Labs' AI-powered static application security testing (SAST) tool discovered a zero-day vulnerability named Memory-Y, according to a Hacker News post by user usman_oiu. The finding highlights the…
Refuse, a pre-install security shim that blocks vulnerable package installs before they reach the disk, has launched to address a surge in supply-chain attacks targeting AI coding agents. The tool int…
Anthropic's Rust protobuf library buffa contains a denial-of-service vulnerability (CVE-2026-55407) that allows attackers to trigger excessive memory allocation, up to 22x the input size, via an unkno…
Anthropic, Google, Microsoft, OpenAI, AWS, and 15 other organizations launched Akrites under the Linux Foundation, a coordinated body for AI-era vulnerability discovery, remediation, and disclosure in…
A coalition of major technology companies and organizations, including Amazon Web Services, Google, Microsoft, and OpenAI, announced the launch of Akrites, a coordinated effort to remediate vulnerabil…
Kilo Security Agent uses AI-powered reachability analysis to reduce false positives in dependency alerts, addressing the problem that over 90% of flagged vulnerabilities are not exploitable in practic…
Anthropic's Claude Fable 5 model, when paired with the Cursor agent harness, achieved 72.6% FuncPass and 29% SecPass on 200 real-world vulnerability-fixing tasks, topping the fair leaderboard. The sam…