Fix SCA issues at scale in your terminal with Snyk Remediation Agent in the CLI
Stop security backlogs. Snyk's Remediation Agent in the CLI pairs AI reasoning with Snyk security intelligence to fix SCA issues at scale directly in your terminal.
AppSec in 2026 is supply-chain-first, identity-first, and increasingly AI-mediated. Strategic lessons on building software security that ships with the product.
Strategic perspective by Ishmael Chibvuri, CISM · updated 3d agoThe biggest shift in application security over the last few years isn't a new class of bug — it's the recognition that the codebase isn't the boundary anymore. The dependencies, the build system, the developer's IDE, the AI assistant, the artifact registry, and the runtime are all in scope. Programs that haven't moved with that shift are protecting the wrong surface.
The feed below tracks supply-chain incidents, OWASP guidance, and the AppSec research that's reshaping how we build software.
Stop security backlogs. Snyk's Remediation Agent in the CLI pairs AI reasoning with Snyk security intelligence to fix SCA issues at scale directly in your terminal.
See how Relay Network securely adopted AI coding with Snyk and GitHub Copilot, implementing "secure at inception" to reduce vulnerabilities and accelerate development.
The latest malware campaign uncovered by Sonatype researchers involved 176 malicious npm packages, many published with the exact same version number: 99.99.99.
In 2011, Marc Andreessen famously wrote that "software is eating the world." Today, software is no longer just a competitive advantage; it is the foundational infrastructure for nearly every industry. We don't merely us…
Snyk's Continuous Offensive Security unifies DAST, AI pentesting, and agent red teaming to find exploitable flaws — not just bugs — before attackers do. Here's why lineage matters.
Repositories have long served as the backbone of software infrastructure, sitting between developers, CI/CD pipelines, public registries, and production releases. Today, the most sophisticated attackers have set their s…
Hundreds of historical Laravel Lang Packagist releases were republished with malicious code, putting Composer installs at risk of credential theft and secret exfiltration.
Attackers do not need to wait for a CVE when they can publish directly into the build.
Snyk announces two new integrations with Anthropic that cover both sides of AI-assisted development. Evo by Snyk now integrates with Anthropic's Claude Enterprise, and the Snyk Security Desktop Extension is now availabl…
Application security (AppSec) tools are essential for identifying and fixing vulnerabilities throughout the software development lifecycle. As modern applications increasingly rely on open source components, choosing th…
AI is accelerating code creation. Learn how Snyk is scaling its AI Security Platform and investing in new partner programs to help enterprises govern AI-generated code at scale.
GitHub Enterprise Server customers need to take immediate action. The post Investigation update: GitHub Enterprise Server signing key rotation appeared first on The GitHub Blog.
Modern software delivery runs on open source. But as dependency graphs expand and application lifecycles stretch across years, end-of-life (EOL) components are becoming a structural security challenge.
Go behind the scenes with Lulu, a Strategy Co-Op at Snyk, and discover a day balancing high-impact AI security projects with a vibrant Boston office culture.
A day after the AntV npm supply chain attack, the same campaign appears to have struck `durabletask`, a Microsoft-associated Python package on PyPI. Snyk has coverage in the vulnerability database and package health pag…
Why bother hunting for a CVE when you can just publish malicious code straight into the software supply chain? That's the story behind the latest wave of Shai-Hulud-related npm compromises, which recently hit the Ant De…
A compromised npm maintainer account triggered an automated burst of over 300 malicious package versions across 323 packages in the AntV data visualization ecosystem, part of the ongoing Mini Shai-Hulud supply chain wor…
AI-powered development tools accelerate the production of software. But they also introduce a familiar challenge: how do you ensure that what's generated is secure, compliant, and trustworthy?
We're updating our bug bounty program standards to prioritize quality submissions, clarify shared responsibility boundaries, and evolve how we reward low-risk findings. The post Raising the bar: Quality, shared responsi…
On May 14, 2026, multiple malicious versions of the popular npm package node-ipc were published to the npm registry. Current public reporting identifies node...
In the first post in this series, we looked at why software supply chain risk has become a growing security challenge. Modern applications depend on sprawling ecosystems of open source packages, automated pipelines, clo…
Juice Shop v20.0.0 — a fresh squeeze of features, now with AI After months of work on the develop branch, OWASP Juice Shop v20.0.0 is ready to serve. This is a major version bump packed with new challenges, a redesigned…
On behalf of the entire OWASP Foundation, it is our absolute pleasure to welcome 26 new contributors to Google Summer of Code 2026. This summer, you’re not just writing code, you’re helping build a more secure world, on…
On May 11, 2026, the Mini Shai-Hulud worm compromised 84 npm package artifacts across 42 @tanstack/* packages (as well as @squawk/*, @mistralai/* packages, and others) by chaining a GitHub Actions "Pwn Request," cache p…
Open source malware is no longer just a numbers game. What was once largely a volume problem — thousands of malicious packages flooding public registries through typosquatting, brandjacking, and low-effort deception — h…
The OWASP Foundation is entering a defining moment. This strategic plan outlines how OWASP will move from being a recognized voice in security to a truly transformative force in the industry. Inside this document, you’l…
A malicious release of the lightning PyPI package ships a credential-stealing Bun payload that runs on import. Snyk has a live advisory. Here's what's in the package, what to rotate, and how the payload pattern connects…
How we validated, fixed, and investigated a critical vulnerability in under two hours, and confirmed no exploitation. The post Securing the git push pipeline: Responding to a critical remote code execution vulnerability…
New Orleans, LA — The OWASP Foundation is pleased to announce the appointment of Missie Lindsey as Director of Corporate Relations. Missie brings more than 18 years of experience in B2B marketing, corporate partnerships…
OpenEoX and CLE are two emerging standards that work together to solve a critical gap in how organizations track whether the software and hardware they depend on is still supported, and their collaboration could reshape…