What Is AI Pentesting and How Does It Works?
AI pentesting uses reasoning-capable AI models to autonomously find, exploit, and validate security vulnerabilities in running applications, particularly context-dependent flaws like broken authorizat…
AI pentesting uses reasoning-capable AI models to autonomously find, exploit, and validate security vulnerabilities in running applications, particularly context-dependent flaws like broken authorizat…
A new attack exploits Git's support for symlinks to trick AI coding assistants into writing an attacker's SSH key into a victim's authorized_keys file. The technique, which involves committing a malic…
Snyk released VulnBench JS 1.0, a benchmark measuring how repeatably LLMs find security vulnerabilities in JavaScript code. Across 300 scans, reference-matched findings were stable, but 80 of 161 uniq…
Snyk security researchers found that 13.4% of 3,984 AI agent skills from ClawHub and skills.sh contain critical security flaws, with 36.82% having at least one security issue, including malware, crede…
The National Institute of Standards and Technology (NIST) announced on April 15, 2026, that the National Vulnerability Database (NVD) will adopt a risk-based triage model, abandoning universal enrichm…
Snyk CEO Ken MacAskill announced layoffs on June 24, 2026, citing the need to move faster in the AI era. The company is reducing team sizes and simplifying its structure to focus on AI security produc…
Snyk analyzed nearly 10,000 developer environments and found that 43% run multiple AI coding tools, 50.8% have at least one MCP server installed, and 1 in 7 of those had security findings. The researc…
Evo announced Agentic Development Security (ADS), a new solution designed to secure AI-driven software development by embedding security into workflows to provide visibility, governance, and control o…
Evo Security launched Agentic Development Security (ADS) in open preview, introducing a new control point that governs AI agent behavior inside the execution loop. The solution addresses risks emergin…
Snyk is offering its full AI Security Platform free to open source maintainers through the Secure Developer Program, providing risk-based prioritization and automated remediation to help them manage v…
AI Engineer Rodrigo shares a typical day at Snyk's Lisbon office, including morning walks with his dog, a train commute, focused work, virtual team syncs, and evening socializing. The office environme…
The US government ordered Anthropic to disable its Fable 5 and Mythos 5 AI models globally on June 12, 2026, just three days after their launch, due to national security concerns over Mythos 5's excep…
Anthropic disabled access to its Claude Fable 5 and Mythos 5 models worldwide on June 12, 2026, to comply with a US government export-control directive targeting foreign national access, citing nation…
A new approach to secure AI code generation uses type-level security to make entire classes of web vulnerabilities uncompilable, inspired by Rust's memory safety guarantees and the Trusted Types API. …
Snyk advises organizations to shift AI security budgets from fragmented tool spending to unified investments in visibility, governance, and control across the full AI lifecycle. The company warns that…
AI agents are introducing new security risks in software development by autonomously planning, building, and shipping code, shifting the security focus from artifact inspection to trusting the agent s…
On May 25, 2026, Johannes Link, the maintainer of the Java testing library jqwik, released version 1.10.0 containing a hidden prompt injection that instructed AI coding agents to delete all jqwik test…
Relay Network, a B2C communications platform, adopted AI coding assistants like GitHub Copilot while maintaining zero critical and high-severity security issues by embedding security into engineering.…
Snyk released an experimental CLI experience for its Remediation Agent, designed to fix software composition analysis (SCA) issues at scale by combining frontier AI models with Snyk's security intelli…
Snyk announces Continuous Offensive Security, a new AI-driven pentesting service that leverages LLMs to find context-dependent vulnerabilities like IDOR and authentication bypasses, which traditional …