# snyk

Published articles for snyk.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Old AI Security vs Evo: Watch Agentic Security Replace Weeks of Manual Work

DevFeed: [Old AI Security vs Evo: Watch Agentic Security Replace Weeks of Manual Work](<https://devfeed.tech/articles/old-ai-security-vs-evo-watch-agentic-security-replace-weeks-of-manual-work-8038.md>)

Original publisher: [Read original article](<https://snyk.io/blog/old-ai-security-vs-evo/>)

Author: Manoj Nair

Published: 2025-12-16T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Retrieval Augmented Generation (RAG)](<https://devfeed.tech/topics/retrieval-augmented-generation-rag.md>), [Machine Learning, Security Attacks](<https://devfeed.tech/topics/machine-learning-security-attacks.md>)

Tags: [agentic-security](<https://devfeed.tech/tags/agentic-security.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [developer](<https://devfeed.tech/tags/developer.md>), [orchestration](<https://devfeed.tech/tags/orchestration.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [rag](<https://devfeed.tech/tags/rag.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article argues that traditional application-security processes cannot keep pace with AI-native applications, including copilots, RAG systems, autonomous agents, and AI-powered workflows. It presents Evo by Snyk as an agentic, orchestrated approach intended to address risks such as prompt injection, data poisoning, model inversion, hallucinations, and supply-chain vulnerabilities.

### Source excerpt

The rise of GenAI brings complex, non-deterministic security risks that traditional methods can't handle. Discover Evo by Snyk, the world's first agentic security orchestration system for AI-native defense.

## Accelerating innovation with AWS: Snyk selected as an AWS Pattern Partner

DevFeed: [Accelerating innovation with AWS: Snyk selected as an AWS Pattern Partner](<https://devfeed.tech/articles/accelerating-innovation-with-aws-snyk-selected-as-an-aws-pattern-partner-8166.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-selected-as-an-aws-pattern-partner/>)

Author: Sarah Conway

Published: 2025-12-03T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-ml](<https://devfeed.tech/tags/ai-ml.md>), [amazon](<https://devfeed.tech/tags/amazon.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [aws](<https://devfeed.tech/tags/aws.md>), [blog](<https://devfeed.tech/tags/blog.md>), [co-created](<https://devfeed.tech/tags/co-created.md>), [executive](<https://devfeed.tech/tags/executive.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [partner](<https://devfeed.tech/tags/partner.md>), [responsible-ai](<https://devfeed.tech/tags/responsible-ai.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>)

### AI overview

Snyk joins AWS as a launch partner in the invite-only AWS Pattern Partners program, contributing experience with AI/ML and Generative/Agentic AI through the Snyk AI Trust platform. The program develops repeatable, scalable patterns with validated architecture, controls, and delivery practices to help enterprises modernize processes and adopt AI safely. Snyk is co-developing the Snyk Studio pattern to address disconnected data and workflows, enterprise-scale governance, AI-generated security risks, and evolving regulatory and compliance requirements.

### Source excerpt

Snyk joins the AWS Pattern Partners program, bringing its proven success with AI/ML and Generative AI. Discover how Snyk Studio accelerates innovation on AWS, embeds security at inception, and delivers measurable outcomes for enterprises modernizing critical processes and adopting AI safely.

## SHA1-Hulud, npm supply chain incident

DevFeed: [SHA1-Hulud, npm supply chain incident](<https://devfeed.tech/articles/sha1-hulud-npm-supply-chain-incident-8097.md>)

Original publisher: [Read original article](<https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/>)

Author: Brian Vermeer

Published: 2025-11-24T18:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [npm](<https://devfeed.tech/topics/npm.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Azure](<https://devfeed.tech/topics/azure.md>), [Google Cloud Platform (GCP)](<https://devfeed.tech/topics/google-cloud.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [incident](<https://devfeed.tech/tags/incident.md>), [npm](<https://devfeed.tech/tags/npm.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [sha1-hulud](<https://devfeed.tech/tags/sha1-hulud.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [trust](<https://devfeed.tech/tags/trust.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>), [worm](<https://devfeed.tech/tags/worm.md>)

### AI overview

Snyk reports SHA1-Hulud, a second-wave npm supply chain attack and worm that spreads through trojanized packages with hidden preinstall scripts. The worm can compromise GitHub Actions self-hosted runners, inject malicious workflows, execute remote commands, exfiltrate GitHub and npm secrets, and search for AWS, Azure, and GCP credentials. Snyk identified more than 600 impacted npm packages and is retesting customer assets, notifying affected customers, and updating its vulnerability databases.

### Source excerpt

Snyk identified a new supply chain attack in the npm ecosystem, referred to as SHA1-Hulud. We believe this is a second wave of the Shai-Hulud attack. Learn what this attack is and how Snyk is responding.

## Anthem Awards 2025: Snyk Learn Recognized for Commitment to Secure AI Development

DevFeed: [Anthem Awards 2025: Snyk Learn Recognized for Commitment to Secure AI Development](<https://devfeed.tech/articles/anthem-awards-2025-snyk-learn-recognized-for-commitment-to-secure-ai-development-8143.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-learn-anthem-awards-2025/>)

Author: Michael Biocchi

Published: 2025-11-19T05:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk-learn](<https://devfeed.tech/topics/snyk-learn.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Learning](<https://devfeed.tech/topics/learning.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-development](<https://devfeed.tech/tags/ai-development.md>), [awards](<https://devfeed.tech/tags/awards.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [developer](<https://devfeed.tech/tags/developer.md>), [education](<https://devfeed.tech/tags/education.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-learn](<https://devfeed.tech/tags/snyk-learn.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Snyk Learn was recognized as a Silver Winner in the Responsible Technology: Education or Literacy Platform category at the 2025 Anthem Awards. The free platform helps developers understand, identify, and fix code vulnerabilities through bite-sized lessons, interactive examples, and real-world scenarios, including guidance for secure AI development.

### Source excerpt

We are incredibly proud and excited to announce that Snyk Learn has been recognized as a Silver Winner in the Responsible Technology: Education or Literacy Platform category at the 5th annual Anthem Awards!

## Secure by Design: The Future of Threat Modeling for AI-Native Applications

DevFeed: [Secure by Design: The Future of Threat Modeling for AI-Native Applications](<https://devfeed.tech/articles/secure-by-design-the-future-of-threat-modeling-for-ai-native-applications-7936.md>)

Original publisher: [Read original article](<https://snyk.io/blog/future-threat-modeling-ai-native-apps/>)

Author: John Carione

Published: 2025-11-11T05:00:00Z

Content type: opinion

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Security for AI](<https://devfeed.tech/topics/security-for-ai.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [security-for-ai](<https://devfeed.tech/tags/security-for-ai.md>), [snyk](<https://devfeed.tech/tags/snyk.md>)

### AI overview

This Snyk article argues that traditional, manual threat modeling cannot keep pace with AI-native applications built from large language models, autonomous agents, APIs, and changing data flows. It presents continuous, automated, AI-assisted threat modeling as a way to maintain secure-by-design systems and address risks such as prompt injection, data exfiltration, data poisoning, and agentic vulnerabilities.

### Source excerpt

Explore how Snyk's Evo Threat Modeling Agent automates and contextualizes security for AI-native applications, addressing prompt injection, data exfiltration, data poisoning, and agentic vulnerabilities.

## Snyk Studio brings security scanning and automated fixes to Factory's Droids

DevFeed: [Snyk Studio brings security scanning and automated fixes to Factory's Droids](<https://devfeed.tech/articles/snyk-studio-brings-security-scanning-and-automated-fixes-to-factory-s-droids-8126.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-factory-partner-integration/>)

Author: Sarah Conway

Published: 2025-11-05T05:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [Security](<https://devfeed.tech/topics/security.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [agentic-security](<https://devfeed.tech/tags/agentic-security.md>), [ai](<https://devfeed.tech/tags/ai.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [model-context-protocol](<https://devfeed.tech/tags/model-context-protocol.md>), [partnership](<https://devfeed.tech/tags/partnership.md>), [related-content](<https://devfeed.tech/tags/related-content.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Snyk announces a partnership with Factory to bring Snyk Studio's real-time security intelligence into Factory Droid workflows through the Model Context Protocol. The integration is designed to help Droids identify and remediate vulnerabilities in newly generated code and reduce existing security debt using prioritized vulnerability data.

### Source excerpt

Snyk is thrilled to announce our partnership with Factory, which brings Snyk Studio directly into Droid workflows.

## Snyk Studio: Now for All Customers, Powering Secure AI Development at Scale

DevFeed: [Snyk Studio: Now for All Customers, Powering Secure AI Development at Scale](<https://devfeed.tech/articles/snyk-studio-now-for-all-customers-powering-secure-ai-development-at-scale-8172.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-studio-announcement/>)

Author: Daniel Berman

Published: 2025-11-04T04:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [VS Code Extension](<https://devfeed.tech/topics/vscode-extension.md>), [MCP Server](<https://devfeed.tech/topics/mcp-server.md>), [code productivity](<https://devfeed.tech/topics/code-productivity.md>), [FIRST](<https://devfeed.tech/topics/first.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [ai-development](<https://devfeed.tech/tags/ai-development.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [availability](<https://devfeed.tech/tags/availability.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code](<https://devfeed.tech/tags/code.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [development](<https://devfeed.tech/tags/development.md>), [devops](<https://devfeed.tech/tags/devops.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [extension](<https://devfeed.tech/tags/extension.md>), [guides](<https://devfeed.tech/tags/guides.md>), [integration](<https://devfeed.tech/tags/integration.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [speed](<https://devfeed.tech/tags/speed.md>), [tool](<https://devfeed.tech/tags/tool.md>), [vs-code](<https://devfeed.tech/tags/vs-code.md>)

### AI overview

Snyk Studio is now available to all customers as a product for securing the AI-driven development lifecycle. The announcement introduces streamlined setup through the official Snyk VS Code extension, enterprise-wide deployment, and general availability of the Snyk MCP Server integration engine.

### Source excerpt

Snyk Studio now offers secure AI development at scale for all customers, with streamlined setup via VS Code extension and enterprise rollout capabilities.

## DevSecCon 2025 Recap: Securing the AI Revolution Together

DevFeed: [DevSecCon 2025 Recap: Securing the AI Revolution Together](<https://devfeed.tech/articles/devseccon-2025-recap-securing-the-ai-revolution-together-7892.md>)

Original publisher: [Read original article](<https://snyk.io/blog/devseccon-2025-recap-securing-the-ai-revolution-together/>)

Author: Ben Desjardins

Published: 2025-10-22T23:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [ide](<https://devfeed.tech/topics/ide.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [snyk-code](<https://devfeed.tech/topics/snyk-code.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [ai](<https://devfeed.tech/tags/ai.md>), [also](<https://devfeed.tech/tags/also.md>), [blog](<https://devfeed.tech/tags/blog.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [ide](<https://devfeed.tech/tags/ide.md>), [interest](<https://devfeed.tech/tags/interest.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>)

### AI overview

This DevSecCon 2025 recap examines how AI is changing software development and security. It covers AI-accelerated DevSecOps, securing code from the first prompt, and managing AI-native application chaos with Evo by Snyk. The article also highlights Snyk capabilities for IDEs, pull requests, Snyk Code, and AppSec governance.

### Source excerpt

AI is changing development. Our DevSecCon 2025 recap covers the 3 critical stages: AI-Accelerated DevSecOps, securing code at the first prompt, and taming AI-native app chaos with Evo by Snyk.

## Why We Built Evo -- From My Heart

DevFeed: [Why We Built Evo -- From My Heart](<https://devfeed.tech/articles/why-we-built-evo-from-my-heart-7983.md>)

Original publisher: [Read original article](<https://snyk.io/blog/introducing-evo-by-snyk/>)

Author: Manoj Nair

Published: 2025-10-22T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [ai security](<https://devfeed.tech/topics/ai-security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [agentic-security](<https://devfeed.tech/tags/agentic-security.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [developer](<https://devfeed.tech/tags/developer.md>), [llm](<https://devfeed.tech/tags/llm.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>)

### AI overview

Snyk introduces Evo as an agentic security orchestrator for AI-native software systems. The article argues that AI security must be an autonomous, operational, continuous architecture integrated into development rather than a passive collection of scanners, policies, or dashboards.

### Source excerpt

Introducing Evo by Snyk, the world's first Agentic Security Orchestrator. Learn why Evo is changing the game in cybersecurity to make security seamless, invisible, intelligent, and unstoppable--so innovation never has to slow down again.

## Increasing Agility & Flexibility: How Mercato Solutions tackles the application security vs. flexibility conundrum with Snyk

DevFeed: [Increasing Agility & Flexibility: How Mercato Solutions tackles the application security vs. flexibility conundrum with Snyk](<https://devfeed.tech/articles/increasing-agility-flexibility-how-mercato-solutions-tackles-the-application-security-vs-flexibility-conundrum-with-snyk-7951.md>)

Original publisher: [Read original article](<https://snyk.io/blog/how-mercato-solutions-tackles-appsec-flexibility-conundrum-with-Snyk/>)

Author: Nina McClure

Published: 2025-10-16T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Low code](<https://devfeed.tech/topics/low-code.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Web](<https://devfeed.tech/topics/web.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [customer](<https://devfeed.tech/tags/customer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [low-code](<https://devfeed.tech/tags/low-code.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

This customer article explains how Mercato Solutions, a low-code enterprise application provider, works with Snyk to address application security challenges while preserving the flexibility of its cloud-first platform. The article highlights the security risks of headless infrastructure, the resulting attack surface, and Mercato's goal of maintaining strong security with a small team.

### Source excerpt

Learn how Mercato Solutions, a fast-growing low-code application provider, achieved near-zero security incidents and maintained development flexibility by partnering with Snyk API & Web.

## Snyk Named a Leader in the 2025 Gartner® Magic Quadrant™ for Application Security Testing

DevFeed: [Snyk Named a Leader in the 2025 Gartner® Magic Quadrant™ for Application Security Testing](<https://devfeed.tech/articles/snyk-named-a-leader-in-the-2025-gartner-magic-quadranttm-for-application-security-testing-8149.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-named-a-leader-in-the-2025-gartner-r-magic-quadrant-tm-for-application/>)

Author: Ben Desjardins

Published: 2025-10-14T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>), [snyk-platform](<https://devfeed.tech/topics/snyk-platform.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [build](<https://devfeed.tech/tags/build.md>), [executive](<https://devfeed.tech/tags/executive.md>), [gartner](<https://devfeed.tech/tags/gartner.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [snyk-iac](<https://devfeed.tech/tags/snyk-iac.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

Snyk announces that it was recognized as a Leader in the 2025 Gartner Magic Quadrant for Application Security Testing. The article highlights Snyk's developer-first approach, coverage across the modern SDLC, AI-powered remediation, integrations with developer workflows, and security controls for AI-related risks and untrusted LLM outputs.

### Source excerpt

Snyk is recognized as a Leader in the 2025 Gartner® Magic Quadrant™ for Application Security Testing (AST), validating our developer-first approach and comprehensive platform for securing the modern SDLC.

## Phishing Campaign Leveraging the NPM Ecosystem

DevFeed: [Phishing Campaign Leveraging the NPM Ecosystem](<https://devfeed.tech/articles/phishing-campaign-leveraging-the-npm-ecosystem-8043.md>)

Original publisher: [Read original article](<https://snyk.io/blog/phishing-campaign-leveraging-the-npm-ecosystem/>)

Author: Liran Tal

Published: 2025-10-09T23:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [browser](<https://devfeed.tech/topics/browser.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [browser](<https://devfeed.tech/tags/browser.md>), [cdn](<https://devfeed.tech/tags/cdn.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

A phishing campaign abuses the npm ecosystem and the unpkg CDN to host and deliver JavaScript through crafted HTML business documents. More than 175 disposable packages redirect victims to credential-harvesting sites when opened in a browser, targeting over 135 organizations.

### Source excerpt

A new phishing campaign weaponizes NPM and the unpkg CDN. Over 175 throwaway packages are used to host scripts that redirect users to credential-harvesting sites. The attack targets enterprise employees through the browser, not developers at install time.

## Malicious MCP Server on npm postmark-mcp Harvests Emails

DevFeed: [Malicious MCP Server on npm postmark-mcp Harvests Emails](<https://devfeed.tech/articles/malicious-mcp-server-on-npm-postmark-mcp-harvests-emails-8009.md>)

Original publisher: [Read original article](<https://snyk.io/blog/malicious-mcp-server-on-npm-postmark-mcp-harvests-emails/>)

Author: Liran Tal

Published: 2025-09-25T04:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [MCP Server](<https://devfeed.tech/topics/mcp-server.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [npm](<https://devfeed.tech/topics/npm.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Security](<https://devfeed.tech/topics/security.md>), [toolchains](<https://devfeed.tech/topics/toolchains.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [blog](<https://devfeed.tech/tags/blog.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [incident](<https://devfeed.tech/tags/incident.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [npm](<https://devfeed.tech/tags/npm.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pii](<https://devfeed.tech/tags/pii.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [tokens](<https://devfeed.tech/tags/tokens.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

This security article reports that the npm package postmark-mcp, an MCP Server for sending email through Postmark, was modified in September 2025 to secretly add a BCC forwarding emails to an external domain. It outlines the incident timeline, the email data and credentials potentially at risk, and mitigation steps including uninstalling the package, rotating credentials, reviewing email logs, and scanning with Snyk's MCP-Scan.

### Source excerpt

Urgent security alert: On September 25, 2025, the npm package 'postmark-mcp' was compromised, secretly exfiltrating email contents. Learn about the incident timeline, impact, and immediate mitigation steps, including uninstalling, rotating credentials, and scanning with Snyk's MCP-Scan.

## Snyk Named a Leader in the 2025 Forrester SAST Wave: SAST Solutions, Q3 2025

DevFeed: [Snyk Named a Leader in the 2025 Forrester SAST Wave: SAST Solutions, Q3 2025](<https://devfeed.tech/articles/snyk-named-a-leader-in-the-2025-forrester-sast-wave-sast-solutions-q3-2025-8148.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-named-a-leader-in-the-2025-forrester-sast-wave-sast-solutions-q3-2025/>)

Author: Ben Desjardins

Published: 2025-09-09T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [Developer experience](<https://devfeed.tech/topics/developer-experience.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer-experience](<https://devfeed.tech/tags/developer-experience.md>), [executive](<https://devfeed.tech/tags/executive.md>), [recognition](<https://devfeed.tech/tags/recognition.md>), [sast](<https://devfeed.tech/tags/sast.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Snyk announces that Forrester recognized it as a Leader in the 2025 Forrester Wave for Static Application Security Testing Solutions. The article attributes this position to Snyk's innovation, AI Security Platform, developer experience, enterprise analytics and visibility, broad Application Security Testing capabilities, and customer impact. It also highlights AI-powered prioritization, autonomous fixes, and the role of Snyk in shift-left security strategies.

### Source excerpt

We're excited to announce that Snyk has been recognized as a Leader in the Forrester Wave™: Static Application Security Testing (SAST) Solutions, Q3 2025.

## Prioritize with Snyk's Open Source Vulnerability Experience

DevFeed: [Prioritize with Snyk's Open Source Vulnerability Experience](<https://devfeed.tech/articles/prioritize-with-snyk-s-open-source-vulnerability-experience-8054.md>)

Original publisher: [Read original article](<https://snyk.io/blog/prioritize-with-snyks-open-source-vulnerability-experience/>)

Author: Ryan McMorrow

Published: 2025-08-20T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Library](<https://devfeed.tech/topics/library.md>), [Development](<https://devfeed.tech/topics/development.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cost](<https://devfeed.tech/tags/cost.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developers](<https://devfeed.tech/tags/developers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [open-source-vulnerabilities](<https://devfeed.tech/tags/open-source-vulnerabilities.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>)

### AI overview

Snyk introduces a new default vulnerability view that groups open source vulnerabilities by dependency and the versions that fix them. The view helps teams compare upgrades by their remediation impact and cost-benefit tradeoffs, making it easier to prioritize library updates and resolve more issues efficiently.

### Source excerpt

Discover Snyk's new default view, grouping vulnerabilities by library and fix versions to help you prioritize and remediate open source vulnerabilities more efficiently.

## Meeting the AI Mandates with Confidence: Why Federal Teams Trust Snyk

DevFeed: [Meeting the AI Mandates with Confidence: Why Federal Teams Trust Snyk](<https://devfeed.tech/articles/meeting-the-ai-mandates-with-confidence-why-federal-teams-trust-snyk-8251.md>)

Original publisher: [Read original article](<https://snyk.io/blog/why-federal-teams-trust-snyk/>)

Author: Phoebe Nerdahl

Published: 2025-08-07T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [ai security](<https://devfeed.tech/topics/ai-security.md>), [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Platform](<https://devfeed.tech/topics/ai-platform.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [agentic-ai-security](<https://devfeed.tech/tags/agentic-ai-security.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-adoption](<https://devfeed.tech/tags/ai-adoption.md>), [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [devops](<https://devfeed.tech/tags/devops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [github](<https://devfeed.tech/tags/github.md>), [government](<https://devfeed.tech/tags/government.md>), [nist](<https://devfeed.tech/tags/nist.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [terraform](<https://devfeed.tech/tags/terraform.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains how Snyk for Government helps federal agencies adopt AI securely through secure-by-design development, continuous vulnerability management, compliance support, automation, and governance. It highlights integrations across developer workflows, FedRAMP authorization, standards-aligned practices, and the Snyk AI Trust Platform.

### Source excerpt

Learn how Snyk for Government helps federal agencies meet AI mandates with confidence. Snyk's AI Trust Platform ensures secure-by-design development, compliance, and transparent AI systems.

## Snyk Supercharges API Discovery with New Akamai Integration

DevFeed: [Snyk Supercharges API Discovery with New Akamai Integration](<https://devfeed.tech/articles/snyk-supercharges-api-discovery-with-new-akamai-integration-8110.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-akamai-integration-api-discovery-testing/>)

Author: Nuno Loureiro

Published: 2025-08-06T04:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [API](<https://devfeed.tech/topics/api.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [snyk-platform](<https://devfeed.tech/topics/snyk-platform.md>), [Security](<https://devfeed.tech/topics/security.md>), [OpenAPI Specification](<https://devfeed.tech/topics/openapi.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [akamai](<https://devfeed.tech/tags/akamai.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [api](<https://devfeed.tech/tags/api.md>), [api-discovery](<https://devfeed.tech/tags/api-discovery.md>), [api-security](<https://devfeed.tech/tags/api-security.md>), [api-testing](<https://devfeed.tech/tags/api-testing.md>), [apis](<https://devfeed.tech/tags/apis.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [co-created](<https://devfeed.tech/tags/co-created.md>), [efficiency](<https://devfeed.tech/tags/efficiency.md>), [executive](<https://devfeed.tech/tags/executive.md>), [integration](<https://devfeed.tech/tags/integration.md>), [openapi](<https://devfeed.tech/tags/openapi.md>), [openapi-specification](<https://devfeed.tech/tags/openapi-specification.md>), [platform](<https://devfeed.tech/tags/platform.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [testing](<https://devfeed.tech/tags/testing.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

Snyk and Akamai announced an integration that automates API discovery and schema ingestion. Akamai API inventories and schemas are added to Snyk API & Web so teams can turn discovered APIs into scannable targets with a single click, improving API security testing coverage and efficiency.

### Source excerpt

Snyk and Akamai partner to streamline API security. This integration automates API discovery and schema ingestion from Akamai to power Snyk's DAST engine, boosting scan coverage and efficiency.

## Snyk Joins CISA's Secure by Design Pledge

DevFeed: [Snyk Joins CISA's Secure by Design Pledge](<https://devfeed.tech/articles/snyk-joins-cisa-s-secure-by-design-pledge-8141.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-joins-cisas-secure-by-design-pledge/>)

Author: Brian Campbell

Published: 2025-08-05T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [cybersecurity and infrastructure security agency](<https://devfeed.tech/topics/cybersecurity-and-infrastructure-security-agency.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [customer](<https://devfeed.tech/tags/customer.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [secure-by-design-pledge](<https://devfeed.tech/tags/secure-by-design-pledge.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [software](<https://devfeed.tech/tags/software.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Snyk's CISO describes the company's decision to join CISA's Secure by Design pledge. The article presents the pledge as a set of measurable goals for improving product security, including secure-by-default practices, MFA, eliminating default passwords, and reducing vulnerabilities before software reaches users.

### Source excerpt

Snyk's CISO explains why we've joined CISA's Secure by Design pledge. Learn about the 7 key goals for a safer digital world, including MFA, no default passwords, and vulnerability reduction.

## Secure at Inception: Introducing New Tools for Securing AI-Native Development

DevFeed: [Secure at Inception: Introducing New Tools for Securing AI-Native Development](<https://devfeed.tech/articles/secure-at-inception-introducing-new-tools-for-securing-ai-native-development-8076.md>)

Original publisher: [Read original article](<https://snyk.io/blog/secure-at-inception-black-hat-2025/>)

Author: Daniel Berman; Liran Tal

Published: 2025-08-04T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [snyk](<https://devfeed.tech/topics/snyk.md>)

Tags: [agentic-security](<https://devfeed.tech/tags/agentic-security.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [customer](<https://devfeed.tech/tags/customer.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [securing-ai](<https://devfeed.tech/tags/securing-ai.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [snyk](<https://devfeed.tech/tags/snyk.md>)

### AI overview

Snyk introduces three capabilities at Black Hat 2025 for securing AI-native development: security testing embedded in agentic workflows and tools, AI-BOM visibility and governance, and MCP-scanning capabilities. The article describes emerging risks including prompt injection, model poisoning, and MCP rug pulls.

### Source excerpt

Snyk unveils innovations at Black Hat to secure AI development. Features include MCP Server for agentic workflows, AI-BOM for visibility, and Toxic Flow Analysis for novel AI threats.

## Fixing Fix Fatigue: Building Developer Trust for Secure AI Code

DevFeed: [Fixing Fix Fatigue: Building Developer Trust for Secure AI Code](<https://devfeed.tech/articles/fixing-fix-fatigue-building-developer-trust-for-secure-ai-code-7926.md>)

Original publisher: [Read original article](<https://snyk.io/blog/fixing-fix-fatigue-building-developer-trust-for-secure-ai-code/>)

Author: Ezra Tanzer

Published: 2025-06-30T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [ai-coding](<https://devfeed.tech/topics/ai-coding.md>), [GitHub Copilot](<https://devfeed.tech/topics/github-copilot.md>), [snyk](<https://devfeed.tech/topics/snyk.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [github-copilot](<https://devfeed.tech/tags/github-copilot.md>), [interest](<https://devfeed.tech/tags/interest.md>), [productivity](<https://devfeed.tech/tags/productivity.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [snyk](<https://devfeed.tech/tags/snyk.md>)

### AI overview

This article explains how AI coding assistants increase developer productivity while introducing security risks, including vulnerabilities in AI-generated code. It argues that security tools must build developer confidence through verified fixes, real-time scanning, and workflows that reduce friction and alert fatigue.

### Source excerpt

Build developer trust in AI security tools with verified fixes, real-time scanning, and frictionless workflows powered by Snyk Agent Fix.

## Why AI Trust Will Shape Your Next Decade of Software Development

DevFeed: [Why AI Trust Will Shape Your Next Decade of Software Development](<https://devfeed.tech/articles/why-ai-trust-will-shape-your-next-decade-of-software-development-8248.md>)

Original publisher: [Read original article](<https://snyk.io/blog/why-ai-trust-will-shape-your-next-decade-of-software-development/>)

Author: Brendan Hann

Published: 2025-06-24T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Security](<https://devfeed.tech/topics/security.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>), [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-adoption](<https://devfeed.tech/tags/ai-adoption.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [ai-transparency](<https://devfeed.tech/tags/ai-transparency.md>), [automation](<https://devfeed.tech/tags/automation.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [developer](<https://devfeed.tech/tags/developer.md>), [development](<https://devfeed.tech/tags/development.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [governance](<https://devfeed.tech/tags/governance.md>), [interest](<https://devfeed.tech/tags/interest.md>), [llm](<https://devfeed.tech/tags/llm.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [speed](<https://devfeed.tech/tags/speed.md>), [trust](<https://devfeed.tech/tags/trust.md>)

### AI overview

The article argues that AI trust is foundational for safe, scalable software development as organizations adopt AI and agentic workflows. It describes AI trust as maintaining control, visibility, security, governance, and continuous risk management while benefiting from faster delivery, greater productivity, and automation. It highlights risks including insecure AI-generated code, prompt injection, data exfiltration, model manipulation, and misconfiguration, and presents Snyk's AI Security Platform as a way to embed risk management and security into the SDLC.

### Source excerpt

Discover why AI Trust is crucial for secure, scalable software development in the AI era. Learn how Snyk's AI Security Platform helps you manage risk, enforce policies, and ensure continuous compliance.

## Building AI Trust with Snyk Code and Snyk Agent Fix

DevFeed: [Building AI Trust with Snyk Code and Snyk Agent Fix](<https://devfeed.tech/articles/building-ai-trust-with-snyk-code-and-snyk-agent-fix-7853.md>)

Original publisher: [Read original article](<https://snyk.io/blog/building-ai-trust-with-snyk-code-and-snyk-agent-fix/>)

Author: Liqian Lim (林利蒨); Brendan Hann

Published: 2025-06-23T04:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [snyk-code](<https://devfeed.tech/topics/snyk-code.md>), [ai security](<https://devfeed.tech/topics/ai-security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [ai-governance](<https://devfeed.tech/topics/ai-governance.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [ide](<https://devfeed.tech/topics/ide.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [ai-governance](<https://devfeed.tech/tags/ai-governance.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [auto-remediation](<https://devfeed.tech/tags/auto-remediation.md>), [autonomous](<https://devfeed.tech/tags/autonomous.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [sast](<https://devfeed.tech/tags/sast.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>)

### AI overview

Snyk describes its AI Security Platform, Snyk Code, and Snyk Agent Fix for governing AI-assisted development. Snyk Agent Fix autonomously generates and validates code-security fixes, offering auto-remediation in IDEs and pull requests, while Snyk Code provides SAST, visibility, prioritization, and policy controls.

### Source excerpt

Secure and accelerate your adoption of AI coding with pre-screened auto-fixes and autonomous code security for modern, developer-loved SAST.

## Announcing a Dedicated Snyk API & Web Infrastructure Instance for Asia-Pacific

DevFeed: [Announcing a Dedicated Snyk API & Web Infrastructure Instance for Asia-Pacific](<https://devfeed.tech/articles/announcing-a-dedicated-snyk-api-web-infrastructure-instance-for-asia-pacific-7820.md>)

Original publisher: [Read original article](<https://snyk.io/blog/announcing-snyk-api-and-web-infrastructure-instance-for-asia-pacific/>)

Author: Snyk Team

Published: 2025-06-16T23:00:00Z

Content type: release

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [API](<https://devfeed.tech/topics/api.md>), [Web](<https://devfeed.tech/topics/web.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [Latency](<https://devfeed.tech/topics/latency.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [announce](<https://devfeed.tech/tags/announce.md>), [apac](<https://devfeed.tech/tags/apac.md>), [api](<https://devfeed.tech/tags/api.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [community](<https://devfeed.tech/tags/community.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [data-privacy](<https://devfeed.tech/tags/data-privacy.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [latency](<https://devfeed.tech/tags/latency.md>), [launch](<https://devfeed.tech/tags/launch.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

Snyk has launched a dedicated Snyk API & Web infrastructure instance hosted locally in the Asia-Pacific region. The instance supports regional data residency and compliance requirements, reduces latency, and provides DAST capabilities for identifying runtime vulnerabilities in the context of AI-driven development.

### Source excerpt

Snyk is delighted to announce a significant milestone for our customers and partners in the Asia-Pacific region: the launch of a dedicated Snyk API & Web infrastructure instance, which is now available and hosted locally within the region.

## Snyk for Government Achieves FedRAMP Moderate Authorization: A Milestone for Secure Government Software

DevFeed: [Snyk for Government Achieves FedRAMP Moderate Authorization: A Milestone for Secure Government Software](<https://devfeed.tech/articles/snyk-for-government-achieves-fedramp-moderate-authorization-a-milestone-for-secure-government-software-8133.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-for-government-achieves-fedramp-moderate-authorization/>)

Author: Danny Allan

Published: 2025-06-05T23:00:00Z

Content type: release

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [executive](<https://devfeed.tech/tags/executive.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [government](<https://devfeed.tech/tags/government.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Snyk announced that Snyk for Government has received FedRAMP Moderate authorization for U.S. public-sector use. The company says the offering supports vulnerability detection, remediation guidance, policy enforcement, developer-tool integrations, and compliance reporting.

### Source excerpt

Snyk for Government is our FedRAMP Moderate authorized solution for the public sector. This authorization underscores our unwavering commitment to providing secure development solutions that meet the rigorous standards of the Federal Risk and Authorization Management Program (FedRAMP).

[Next page](<https://devfeed.tech/tags/snyk.md?cursor=WyIyMDI1LTA2LTA1VDIzOjAwOjAwKzAwOjAwIiwgIjkwMjY5ZjlhLTI2MTQtNDg1Ny1iMjZiLWM0YmRlNDNjNjI3MCJd>)