eCommerceNews US - Technology news for digital commerce decision-makers
United States
American Edition · 2026

The Ultimate Guide to Application Security

A curated American edition of TechDay news, analysis, interviews, reviews, job moves, and related resources for Application Security.

What to know about Application Security

Application Security focuses on protecting software applications from vulnerabilities and cyber threats throughout their development and operational life cycles. This critical field addresses challenges such as runtime protection, secure coding practices, DevSecOps integration, API security, cloud-native environments, and mitigating attacks like DDoS, supply chain risks, and malicious bot traffic.

Exploring the latest stories in Application Security reveals how advancements like AI and automation are enhancing threat detection, vulnerability management, and developer workflows, while highlighting ongoing risks found in mobile apps, open source components, and cloud deployments. Readers can gain insights into best practices, emerging technologies, and strategies to safeguard applications against evolving cyber threats.

Whether you’re a developer, security professional, or business leader, staying informed about Application Security developments helps in building resilient software, maintaining compliance, and protecting user data in an increasingly complex digital landscape.

American Application Security News

Regional stories with direct local relevance

Analyst Insights

Research and market analysis connected to Application Security

Expert Columns

Interviews

Interviews and video coverage from the network

Recent Application Security News

Sygnia finds AI onboarding flaw exposing client data
Identity and Access Management

Sygnia finds AI onboarding flaw exposing client data

A faulty token check let low-privilege users view other applicants' identities, payment details and Social Security numbers in a financial onboarding app.

Last week

Cycode launches agentic workflows for security teams
App development

Cycode launches agentic workflows for security teams

Security teams can now automate triage and remediation as risks emerge, with early access to AI agents that still require human oversight.

Last week

NCC Group says human testers still vital in AI security
Digital Transformation

NCC Group says human testers still vital in AI security

AI tools are speeding routine checks, but hidden business logic flaws and context-specific risks still need human testers to spot them.

Last week

Cobalt launches autonomous pentest for continuous testing
Threat detection

Cobalt launches autonomous pentest for continuous testing

Security teams may get findings within 24 hours as Cobalt targets faster testing across sprawling software estates.

Last month

Synack study finds major blind spots in security testing
Digital Transformation

Synack study finds major blind spots in security testing

Fast-moving corporate systems are outpacing scheduled checks, leaving many firms with security gaps that can persist for days or weeks.

Last month

CISA uses Anthropic AI to hunt flaws in federal code
Security Operations Centres

CISA uses Anthropic AI to hunt flaws in federal code

The pilot could speed up vulnerability hunting across government systems, but it also leaves human teams to verify and fix each AI flag.

Last month

RapidFort & ReversingLabs add security checks to libraries
Threat intelligence

RapidFort & ReversingLabs add security checks to libraries

Enterprises can now vet open-source dependencies before build time, as the catalogue adds independent malware and vulnerability checks for Python and Java.

Last month

Baz launches Planner with USD $9 million seed raise
Authentication

Baz launches Planner with USD $9 million seed raise

The new planning tool aims to cut bugs and security flaws before code is written, as the startup's seed funding reaches USD $17 million.

Last month

Straiker raises USD $64 million to secure AI agents
Digital Transformation

Straiker raises USD $64 million to secure AI agents

Enterprise customers face growing risks as autonomous software gains access to internal systems, prompting fresh demand for agent security tools.

Wed, 1st Jul 2026

Cobalt study says automated AI tests miss key flaws
Chief Information Security Officer

Cobalt study says automated AI tests miss key flaws

False negatives from automated scanning tools are fuelling a shift towards human-led AI security testing across large organisations.

Tue, 30th Jun 2026

Minimus opens full image catalogue without registration
Supply Chain

Minimus opens full image catalogue without registration

Developers can now pull thousands of hardened container images for free, as the company drops registration and expands access across its library.

Sat, 27th Jun 2026

DevOps breaches hit tech firms in trust chain attacks
Digital Transformation

DevOps breaches hit tech firms in trust chain attacks

Tech and software groups are most at risk as breaches, supplier access and stale credentials let attackers reach source code and customer data.

Fri, 26th Jun 2026

QuSecure appoints ex-CIA officer to advisory board
Digital Transformation

QuSecure appoints ex-CIA officer to advisory board

The move comes as US agencies shift from planning to implementation of post-quantum cryptography, exposing legacy systems to future quantum attacks.

Tue, 23rd Jun 2026

White House AI order draws fresh cybersecurity scrutiny
Identity and Access Management

White House AI order draws fresh cybersecurity scrutiny

Voluntary model reviews may leave gaps as advanced AI systems move closer to critical infrastructure and enterprise data.

Fri, 12th Jun 2026

UltraViolet Cyber launches Solstice AI pentesting platform
Threat intelligence

UltraViolet Cyber launches Solstice AI pentesting platform

The platform aims to speed application security reviews by about 20% while keeping expert testers in charge of final findings.

Sat, 6th Jun 2026

Token Security launches Enzo AI builder for identity teams
Mergers and Acquisitions

Token Security launches Enzo AI builder for identity teams

Security teams are getting a way to automate access reviews and remediation as AI agents and machine accounts widen identity risks.

Sat, 6th Jun 2026

Geordie appoints Courtney Broadwell as Channel Chief
Leadership

Geordie appoints Courtney Broadwell as Channel Chief

The hire bolsters Geordie's push to help enterprises govern AI agents, as it expands after a USD $30 million funding round.

Thu, 4th Jun 2026

Sonatype expands Firewall to block malicious packages
Chief Technology Officers

Sonatype expands Firewall to block malicious packages

Malicious open source packages are increasingly slipping past spelling checks, exposing developer data and build systems to supply-chain attacks.

Tue, 2nd Jun 2026

Zapier security chain exposed package publishing risk
Identity and Access Management

Zapier security chain exposed package publishing risk

A free account could have let attackers alter Zapier-maintained packages and hijack logged-in users' browser sessions, researchers said.

Fri, 29th May 2026

CodeHunter appoints Anurag Jain as Engineering Chief
Security Operations Centres

CodeHunter appoints Anurag Jain as Engineering Chief

The hire signals CodeHunter's push to scale pre-execution software security as threats mount across supply chains and development environments.

Thu, 28th May 2026

Job Moves