Security News


IBM and Red Hat Pledge $5 Billion to Advance Open Source AI Technologies

Investment targets open-source platforms, tools and infrastructure designed to support enterprise AI adoption.

Java Maintenance Engineering Shifts Focus on Quarterly Critical Patch Stabilization

Enterprise Java development teams are shifting engineering focus toward the stabilization and regression testing of the next Critical Patch Update (CPU) cycle for long-term support runtimes, including Java 25.

Microsoft Releases Open-Source Frameworks to Bring Safety to Agent Development Workflows

New projects aim to help developers add governance and security controls into AI agent development workflows.

Oracle Java Set to Power Samsung Semiconductor Development Operations

Agreement expands use of Java technologies in Samsung Electronics’ global semiconductor software environment.

AI Security Firm Protegrity Launches Tool to Protect Corporate Agent Workflows

Protegrity, a data security company, has released software designed to help organizations secure artificial intelligence agent systems as businesses grapple with data protection concerns in AI deployments.

Qwiet AI Expands Integrations, Adds AutoFix Features to Application Security Platform

Application security provider Qwiet AI has expanded its integrations with Microsoft Azure and GitHub and introduced new AI-powered AutoFix capabilities aimed at speeding secure software delivery.

Eclipse Foundation Launches EU-Funded Project to Aid Cyber Resilience Act Compliance

The Eclipse Foundation has launched a European Commission-funded initiative to help small businesses and software developers comply with the EU's Cyber Resilience Act through free open-source tools.

Microsoft Backs Passkey Standard, Signals Developers to Build Passwordless by Default

Microsoft marked the inaugural World Passkey Day (formerly World Password Day) by reaffirming its push toward a passwordless future—signing the FIDO Alliance’s Passkey Pledge and joining other major tech players in accelerating adoption of modern, developer-friendly authentication standards. For engineers, it’s a signal that passkeys are moving from optional to inevitable—and it’s time to start building with them in mind.

Harness and Traceable Launch Unified WAAP to Tackle Modern Application Threats

Application delivery platform Harness, in collaboration with recently acquired API security company Traceable, has unveiled Traceable Cloud WAAP, a next-generation Web Application and API Protection platform. The product, launched Tuesday, aims to provide full-stack, context-aware security for cloud-native environments and microservices architectures.

Oracle Launches Jipher to Support Java Cryptography in FIPS 140-2 Regulated Environments

Oracle Corp on Tuesday announced the release of Oracle Jipher, a Java Cryptographic Service Provider designed to enable secure deployments of Java applications in U.S. government and enterprise environments that require FIPS 140-2 compliance.

Microsoft Arms Security Copilot with Autonomous AI Agents to Streamline Threat Response for Developers

Microsoft has supercharged its Security Copilot platform with 11 new autonomous AI agents designed to help developers and security teams triage phishing alerts, remediate vulnerabilities, and secure AI workloads across multi-cloud environments—marking a major step in automated cyber defense tools tailored for modern DevSecOps workflows.

Rubrik and Red Hat Team Up to Boost Cyber Resilience for Virtualized Environments

Data security firm Rubrik has announced a collaboration with open-source software maker Red Hat to integrate Red Hat OpenShift Virtualization into Rubrik Security Cloud, aiming to streamline data protection for virtualized environments and enhance cyber resilience. The solution is expected to be generally available early next year.

Stytch Unveils Advanced Authentication Tech with Enhanced Fraud and Bot Protection for Developers

Identity platform provider Stytch launches new device fingerprinting capabilities designed to provide enhanced fraud and bot protection for developers. The upgrade incorporates advanced AI functionality, offering an easy-to-integrate solution for boosting security within authentication flows, the company said. Stytch’s technology aims to provide seamless and highly accurate bot detection, reducing user friction and enhancing security without visible interventions.

JFrog Launches Runtime Security Solution to Boost Software Integrity from Code to Cloud

JFrog has introduced a new runtime security solution aimed at enhancing software integrity and streamlining collaboration between developers and security teams. The addition of JFrog Runtime to the company’s existing security tools is meant to empower enterprises to embed security at every stage of the software development process, the company said, from writing source code to deploying applications in production.

Map of United States with cybersecurity icons

CrowdStrike Apologizes, Blames Flaw in Testing Software for Faulty Update that Took Down Millions of Windows Systems

Security firm CrowdStrike has revealed that a flaw in its testing software led to a faulty update, causing more than 8.5 million Windows systems to crash last week. In a blog post published today, the Austin-based company provided more details on the incident, which resulted in flight cancellations and disruptions to public services, including 911 systems.

White House Calls for 'Attestations' of Secure Practices from Third-Party Software Providers

White House publishes guidelines requiring government agencies to obtain formal assurances from third-party software providers that they are following secure software development practices.

A Visit to the Automated Testing Zoo

Our Agile Architect wants to talk about lessons learned from his experiences with test automation. As usual, he does it in his own unique way.

Contrast Security Adds SCA in Free CodeSec Tool

App security tools provider Contrast Security adds software composition analysis capabilities to its free in CodeSec "developer-first" scanner.

Checkmarx and Seemplicity Join Forces to Simplify the Find-to-Fix Lifecycle

Application security testing company Checkmarx and cybersecurity workflow and productivity startup Seemplicity today announced a new partnership aimed at simplifying the "find-to-fix" lifecycle and accelerating the time to remediation of vulnerabilities found throughout the software development lifecycle .

Veeam Previews Major Product Updates at Annual User Conference

Veeam Software kicks off its annual user conference with a product roadmap that showcases features planned for the release of Veeam Backup & Replication v12, as well as key solution innovations for cloud-native solutions, SaaS offerings, and some deeper integrations of Kasten by Veeam K10 for Kubernetes.