# snyk-apprisk

Published articles for snyk-apprisk.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## The Attacker Never Sleeps, Neither Can Your Testing

DevFeed: [The Attacker Never Sleeps, Neither Can Your Testing](<https://devfeed.tech/articles/the-attacker-never-sleeps-neither-can-your-testing-7832.md>)

Original publisher: [Read original article](<https://snyk.io/blog/attacker-never-sleeps-neither-can-testing/>)

Author: Manoj Nair

Published: 2026-07-30T00:00:00Z

Content type: opinion

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [Developer Tools](<https://devfeed.tech/topics/developer-tools.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code](<https://devfeed.tech/tags/code.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [finserv](<https://devfeed.tech/tags/finserv.md>), [interest](<https://devfeed.tech/tags/interest.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [software](<https://devfeed.tech/tags/software.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [tech](<https://devfeed.tech/tags/tech.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

AI-driven code generation is expanding software attack surfaces while giving attackers machine-speed reasoning capabilities. The article argues that security teams need continuous testing, agent governance, and independent validation of findings.

### Source excerpt

AI is accelerating software development and giving attackers machine-speed capabilities. Security teams must continuously test AI-built code, govern agents, and independently validate every finding.

## So You Have an AI Security Budget. Now what?

DevFeed: [So You Have an AI Security Budget. Now what?](<https://devfeed.tech/articles/so-you-have-an-ai-security-budget-now-what-7811.md>)

Original publisher: [Read original article](<https://snyk.io/blog/ai-security-budget/>)

Author: Snyk Team

Published: 2026-06-04T00:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [ai security](<https://devfeed.tech/topics/ai-security.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [coding](<https://devfeed.tech/topics/coding.md>), [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [development](<https://devfeed.tech/tags/development.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [executive](<https://devfeed.tech/tags/executive.md>), [interest](<https://devfeed.tech/tags/interest.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [policy](<https://devfeed.tech/tags/policy.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [snyk-security-intel](<https://devfeed.tech/tags/snyk-security-intel.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [tech](<https://devfeed.tech/tags/tech.md>)

### AI overview

The article argues that AI security budgets should prioritize unified visibility, governance, policy enforcement, risk assessment, adversarial testing, runtime protection, and audit evidence across the full AI lifecycle. It distinguishes between securing agents that build software and agents operating in production applications.

### Source excerpt

An AI security budget should fund more than visibility. The real priority is unified governance and enforcement across agentic development and production apps.

## Building AI Security with Our Customers: 5 Lessons from Evo's Design Partner Program

DevFeed: [Building AI Security with Our Customers: 5 Lessons from Evo's Design Partner Program](<https://devfeed.tech/articles/building-ai-security-with-our-customers-5-lessons-from-evo-s-design-partner-program-7852.md>)

Original publisher: [Read original article](<https://snyk.io/blog/building-ai-security-with-our-customers/>)

Author: Rudy Lai

Published: 2026-04-01T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [Generative AI](<https://devfeed.tech/topics/generative-ai.md>), [shadow AI](<https://devfeed.tech/topics/shadow-ai.md>), [ai security](<https://devfeed.tech/topics/ai-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Automation](<https://devfeed.tech/topics/automation.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-adoption](<https://devfeed.tech/tags/ai-adoption.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [automation](<https://devfeed.tech/tags/automation.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [customer](<https://devfeed.tech/tags/customer.md>), [customer-featured](<https://devfeed.tech/tags/customer-featured.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [finserv](<https://devfeed.tech/tags/finserv.md>), [generative](<https://devfeed.tech/tags/generative.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [interest](<https://devfeed.tech/tags/interest.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [policy](<https://devfeed.tech/tags/policy.md>), [retail](<https://devfeed.tech/tags/retail.md>), [scale](<https://devfeed.tech/tags/scale.md>), [security](<https://devfeed.tech/tags/security.md>), [shadow-ai](<https://devfeed.tech/tags/shadow-ai.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [tech](<https://devfeed.tech/tags/tech.md>)

### AI overview

Snyk shares five lessons from its Evo design partner program for securing generative AI. The article emphasizes discovering AI sprawl and shadow AI, understanding custom AI deployments, replacing static spreadsheets, enforcing governance policies, and using actionable risk intelligence to move AI from chaos to controlled production.

### Source excerpt

Learn 5 key lessons from Snyk's Evo design partner program. Discover how AI discovery, risk intelligence, and policy automation help teams secure generative AI and govern AI sprawl at scale.

## Beyond Detection: Building a Resilient Software Supply Chain (Lessons from the Shai-Hulud Post-Mortem)

DevFeed: [Beyond Detection: Building a Resilient Software Supply Chain (Lessons from the Shai-Hulud Post-Mortem)](<https://devfeed.tech/articles/beyond-detection-building-a-resilient-software-supply-chain-lessons-from-the-shai-hulud-post-mortem-8099.md>)

Original publisher: [Read original article](<https://snyk.io/blog/shai-hulud-post-mortem/>)

Author: Liran Tal

Published: 2026-01-08T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Post Mortem](<https://devfeed.tech/topics/post-mortem.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [incident](<https://devfeed.tech/topics/incident.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Security](<https://devfeed.tech/topics/security.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [ci](<https://devfeed.tech/topics/ci.md>), [GitHub Copilot](<https://devfeed.tech/topics/github-copilot.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [americas](<https://devfeed.tech/tags/americas.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [copilot](<https://devfeed.tech/tags/copilot.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [github](<https://devfeed.tech/tags/github.md>), [github-copilot](<https://devfeed.tech/tags/github-copilot.md>), [google](<https://devfeed.tech/tags/google.md>), [incident](<https://devfeed.tech/tags/incident.md>), [interest](<https://devfeed.tech/tags/interest.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [malware](<https://devfeed.tech/tags/malware.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [post-mortem](<https://devfeed.tech/tags/post-mortem.md>), [related-content](<https://devfeed.tech/tags/related-content.md>), [security](<https://devfeed.tech/tags/security.md>), [security-labs](<https://devfeed.tech/tags/security-labs.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [snyk-security-intel](<https://devfeed.tech/tags/snyk-security-intel.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [tech](<https://devfeed.tech/tags/tech.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article examines the Shai-Hulud npm supply chain incident and argues that organizations should move beyond reactive scanning toward layered prevention, real-time intelligence, and automated action. It highlights safer dependency upgrades, a 21-day cooldown strategy, and security guardrails embedded in AI coding workflows.

### Source excerpt

The Shai-Hulud npm incident exposed the limitations of reactive security in modern software supply chains. To survive the next major attack, organizations must shift toward a multi-layered strategy of proactive prevention, real-time intelligence, and automated action.

## Snyk Security Solution Now Integrated into Google Cloud's Gemini Code Assist

DevFeed: [Snyk Security Solution Now Integrated into Google Cloud's Gemini Code Assist](<https://devfeed.tech/articles/snyk-security-solution-now-integrated-into-google-cloud-s-gemini-code-assist-8165.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-security-solution-now-integrated-into-google-clouds-gemini-code-assist/>)

Author: Liqian Lim (林利蒨)

Published: 2025-04-09T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [ide](<https://devfeed.tech/topics/ide.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [executive](<https://devfeed.tech/tags/executive.md>), [gemini](<https://devfeed.tech/tags/gemini.md>), [google](<https://devfeed.tech/tags/google.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [related-content](<https://devfeed.tech/tags/related-content.md>), [sast](<https://devfeed.tech/tags/sast.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>)

### AI overview

Snyk's security solution is integrated into Google Cloud's Gemini Code Assist, enabling developers to use Snyk security capabilities through natural-language prompts and the coding assistant's chat interface.

### Source excerpt

Secure AI coding with Snyk and Google Gemini. Learn how Snyk Code's SAST integrates with Gemini Code Assist for seamless, secure development workflows.

## AI Risk Management: Benefits, Challenges, and Best Practices

DevFeed: [AI Risk Management: Benefits, Challenges, and Best Practices](<https://devfeed.tech/articles/ai-risk-management-benefits-challenges-and-best-practices-7810.md>)

Original publisher: [Read original article](<https://snyk.io/blog/ai-risk-management-benefits-challenges-and-best-practices/>)

Author: Stephen Thoemmes

Published: 2025-03-13T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-adoption](<https://devfeed.tech/tags/ai-adoption.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-generation](<https://devfeed.tech/tags/code-generation.md>), [developer](<https://devfeed.tech/tags/developer.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [standards](<https://devfeed.tech/tags/standards.md>)

### AI overview

This article explains how organizations can manage risks introduced by AI development tools while still benefiting from faster coding and reduced manual work. It covers hidden vulnerabilities in generated code, outdated libraries, logic errors, compliance concerns, automated threat detection, and the use of NIST and ISO guidance to support secure-by-design AI adoption.

### Source excerpt

Learn how to manage AI risks effectively with best practices, frameworks, and strategies to ensure secure AI adoption while mitigating vulnerabilities.

## Snyk's risk-based approach to prioritization

DevFeed: [Snyk's risk-based approach to prioritization](<https://devfeed.tech/articles/snyk-s-risk-based-approach-to-prioritization-8185.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyks-risk-based-approach-to-prioritization/>)

Author: Daniel Berman

Published: 2024-12-11T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [developer](<https://devfeed.tech/tags/developer.md>), [development](<https://devfeed.tech/tags/development.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Snyk's risk-based prioritization approach helps application security teams evaluate vulnerabilities using factors such as severity, exploitability, and reachability instead of relying on vulnerability counts alone. The approach emphasizes visibility and context across the software development lifecycle to focus remediation on the issues posing the greatest risk and improve collaboration between security and development teams.

### Source excerpt

With Snyk's approach and Snyk AppRisk, implementing risk-based prioritization is easy. Here's how Snyk's developer-first, holistic approach works.

## Seven steps to close coverage gaps with ASPM

DevFeed: [Seven steps to close coverage gaps with ASPM](<https://devfeed.tech/articles/seven-steps-to-close-coverage-gaps-with-aspm-8096.md>)

Original publisher: [Read original article](<https://snyk.io/blog/seven-steps-to-close-coverage-gaps-with-aspm/>)

Author: Daniel Berman

Published: 2024-12-03T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [blog](<https://devfeed.tech/tags/blog.md>), [devops](<https://devfeed.tech/tags/devops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [monitor](<https://devfeed.tech/tags/monitor.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [policy](<https://devfeed.tech/tags/policy.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article outlines seven ongoing practices for closing application-security coverage gaps, presenting ASPM as a way to inventory application assets, prioritize risk, define policies, track controls, integrate security testing, and monitor improvement.

### Source excerpt

Finding and closing coverage gaps in your AppSec program is not a one-and-done process, it's an ongoing combination of efforts. See how ASPM makes it easier.

## Measuring AppSec success: Key KPIs that demonstrate value

DevFeed: [Measuring AppSec success: Key KPIs that demonstrate value](<https://devfeed.tech/articles/measuring-appsec-success-key-kpis-that-demonstrate-value-8013.md>)

Original publisher: [Read original article](<https://snyk.io/blog/measuring-appsec-success-key-kpis-demonstrate-value/>)

Author: Daniel Berman

Published: 2024-11-26T05:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [business-value](<https://devfeed.tech/tags/business-value.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [metrics](<https://devfeed.tech/tags/metrics.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

A guide to measuring application security program success through KPIs for risk reduction, team engagement, security posture, and vulnerability-management efficiency.

### Source excerpt

Learn how to measure AppSec success with key KPIs that demonstrate risk reduction, improve security posture, and showcase business value to stakeholders.

## How to prioritize vulnerabilities based on risk

DevFeed: [How to prioritize vulnerabilities based on risk](<https://devfeed.tech/articles/how-to-prioritize-vulnerabilities-based-on-risk-8053.md>)

Original publisher: [Read original article](<https://snyk.io/blog/prioritize-vulnerabilities-based-on-risk/>)

Author: Daniel Berman

Published: 2024-11-19T05:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

A guide to risk-based vulnerability prioritization for application-security teams. It recommends ranking vulnerabilities by exploitability, business impact, and data sensitivity instead of relying on vulnerability counts, helping reduce alert fatigue and focus remediation on the most harmful threats.

### Source excerpt

Learn how to use risk-based prioritization for vulnerability management. This blog will help you reduce alert fatigue and improve your security posture.

## How ASPM boosts visibility to manage application risk

DevFeed: [How ASPM boosts visibility to manage application risk](<https://devfeed.tech/articles/how-aspm-boosts-visibility-to-manage-application-risk-7829.md>)

Original publisher: [Read original article](<https://snyk.io/blog/aspm-boosts-visibility-manage-app-risk/>)

Author: Daniel Berman

Published: 2024-11-12T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article explains how application security posture management (ASPM) can improve visibility across software assets and help AppSec teams prioritize and manage application risk.

### Source excerpt

Visibility gaps are a huge limiting factor for growing AppSec programs. Let's discuss how Snyk can help you close them.

## Elevating views of risk: Holistic application risk management with Snyk

DevFeed: [Elevating views of risk: Holistic application risk management with Snyk](<https://devfeed.tech/articles/elevating-views-of-risk-holistic-application-risk-management-with-snyk-7901.md>)

Original publisher: [Read original article](<https://snyk.io/blog/elevating-views-risk-holistic-application-risk-management-with-snyk/>)

Author: Daniel Berman

Published: 2024-10-22T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>)

Tags: [app](<https://devfeed.tech/tags/app.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [devops](<https://devfeed.tech/tags/devops.md>), [management](<https://devfeed.tech/tags/management.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article presents Snyk's application-centered approach to managing application risk. It argues that teams should prioritize vulnerabilities using broader context, including how applications are built, deployed, configured, and valued by the business, while accounting for unknown or unscanned assets.

### Source excerpt

Learn how to secure applications with Snyk's holistic, app-centered approach to risk management. Try Snyk for smarter and safer risk-based prioritization.

## SnykLaunch Oct 2024: Enhanced PR experience, extended visibility, AI-powered security, holistic risk management

DevFeed: [SnykLaunch Oct 2024: Enhanced PR experience, extended visibility, AI-powered security, holistic risk management](<https://devfeed.tech/articles/snyklaunch-oct-2024-enhanced-pr-experience-extended-visibility-ai-powered-security-holistic-risk-management-7784.md>)

Original publisher: [Read original article](<https://snyk.io/blog/SnykLaunch-Oct-2024/>)

Author: Anthony Larkin

Published: 2024-10-08T12:45:00Z

Content type: release

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [releases](<https://devfeed.tech/topics/releases.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [event](<https://devfeed.tech/tags/event.md>), [features](<https://devfeed.tech/tags/features.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [releases](<https://devfeed.tech/tags/releases.md>), [scm](<https://devfeed.tech/tags/scm.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [snyk-cloud](<https://devfeed.tech/tags/snyk-cloud.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Recap of SnykLaunch updates for developer-first application security, including pull-request issue summaries, risk prioritization, visibility, and security considerations for AI-generated code.

### Source excerpt

Read a recap of our SnykLaunch event for October 2024, covering our new features that power a developer-first, risk-centric security experience.

## Zero-day RCE vulnerability found in CUPS - Common UNIX Printing System

DevFeed: [Zero-day RCE vulnerability found in CUPS - Common UNIX Printing System](<https://devfeed.tech/articles/zero-day-rce-vulnerability-found-in-cups-common-unix-printing-system-8260.md>)

Original publisher: [Read original article](<https://snyk.io/blog/zero-day-rce-in-cups-vulnerability-sept-2024/>)

Author: Jim Armstrong

Published: 2024-09-27T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Unix](<https://devfeed.tech/topics/unix.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [C](<https://devfeed.tech/topics/c.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [c](<https://devfeed.tech/tags/c.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [dns](<https://devfeed.tech/tags/dns.md>), [docker](<https://devfeed.tech/tags/docker.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [executive](<https://devfeed.tech/tags/executive.md>), [interest](<https://devfeed.tech/tags/interest.md>), [linux](<https://devfeed.tech/tags/linux.md>), [network](<https://devfeed.tech/tags/network.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [port](<https://devfeed.tech/tags/port.md>), [rce](<https://devfeed.tech/tags/rce.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [scm](<https://devfeed.tech/tags/scm.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article reports several vulnerabilities in CUPS, the Common UNIX Printing System, including unauthenticated remote code execution. It discusses four associated CVEs, a potentially high CVSS score, affected UNIX and Linux packages, exploitability conditions involving UDP port 631 or DNS-SD, and remediation assessment using Snyk Open Source and Snyk Container.

### Source excerpt

Security researcher evilsocket.net (Simone Margaritelli) published information about several vulnerabilities in CUPS that allow for remote code execution (RCE)

## Promise queues and batching concurrent tasks in Deno

DevFeed: [Promise queues and batching concurrent tasks in Deno](<https://devfeed.tech/articles/promise-queues-and-batching-concurrent-tasks-in-deno-8056.md>)

Original publisher: [Read original article](<https://snyk.io/blog/promise-queues-concurrent-tasks-deno/>)

Author: Liran Tal

Published: 2024-09-25T04:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Deno](<https://devfeed.tech/topics/deno.md>), [Promise](<https://devfeed.tech/topics/promise.md>), [Concurrency](<https://devfeed.tech/topics/concurrency.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Programming](<https://devfeed.tech/topics/programming.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [batching](<https://devfeed.tech/tags/batching.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [concurrent](<https://devfeed.tech/tags/concurrent.md>), [developer](<https://devfeed.tech/tags/developer.md>), [java](<https://devfeed.tech/tags/java.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [memory](<https://devfeed.tech/tags/memory.md>), [performance](<https://devfeed.tech/tags/performance.md>), [queue](<https://devfeed.tech/tags/queue.md>), [queuing](<https://devfeed.tech/tags/queuing.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>)

### AI overview

This tutorial explains how Promise queues and task batching can manage concurrent asynchronous tasks in Deno more efficiently. It covers JavaScript's single-threaded, event-driven model, the limitations of running many promises together, and how queuing can reduce memory pressure and prevent one failed task from causing complete failure.

### Source excerpt

Learn how to create secure applications using Deno. Explore the default security measures provided by Deno, understand potential vulnerabilities such as Server-Side Request Forgery (SSRF), and uncover the best practices for minimizing risks. Enhance your application's security by leveraging Deno's advanced features.

## 3 best practices to make the most of Snyk AppRisk Essentials

DevFeed: [3 best practices to make the most of Snyk AppRisk Essentials](<https://devfeed.tech/articles/3-best-practices-to-make-the-most-of-snyk-apprisk-essentials-7767.md>)

Original publisher: [Read original article](<https://snyk.io/blog/3-best-practices-snyk-apprisk-essentials/>)

Author: Daniel Berman

Published: 2024-09-19T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [App](<https://devfeed.tech/topics/app.md>), [snyk-iac](<https://devfeed.tech/topics/snyk-iac.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [applications](<https://devfeed.tech/tags/applications.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [blog](<https://devfeed.tech/tags/blog.md>), [convert-paid](<https://devfeed.tech/tags/convert-paid.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [executive](<https://devfeed.tech/tags/executive.md>), [management](<https://devfeed.tech/tags/management.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [snyk-iac](<https://devfeed.tech/tags/snyk-iac.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>)

### AI overview

Snyk AppRisk Essentials is being included in the Snyk Enterprise plan. The article describes application asset discovery, coverage management, ownership and criticality tracking, and policies for managing coverage.

### Source excerpt

We're excited to announce that Snyk AppRisk Essentials is rolling out for all Snyk Enterprise Plan customers.

## Meet Snyk for Government: Our developer security solution with FedRAMP ATO

DevFeed: [Meet Snyk for Government: Our developer security solution with FedRAMP ATO](<https://devfeed.tech/articles/meet-snyk-for-government-our-developer-security-solution-with-fedramp-ato-8134.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-for-government-developer-security-solution-with-fedramp-ato/>)

Author: Danny Allan

Published: 2024-09-17T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [ato](<https://devfeed.tech/tags/ato.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [executive](<https://devfeed.tech/tags/executive.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fedramp-ato](<https://devfeed.tech/tags/fedramp-ato.md>), [government](<https://devfeed.tech/tags/government.md>), [public-sector](<https://devfeed.tech/tags/public-sector.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Snyk announces that Snyk for Government has received an authorization to operate from its FedRAMP sponsor, enabling public sector teams to use the offering while formal FedRAMP authorization progresses. The article describes application security, software supply chain protection, vulnerability and compliance intelligence, inline code scanning, and SBOM creation for government agencies.

### Source excerpt

Discover how Snyk's FedRAMP-authorized platform empowers developers to build secure applications. Learn about our comprehensive solutions for vulnerability management, supply chain security, and AI code scanning.

## Announcing new Snyk AppRisk integration with Orca Security

DevFeed: [Announcing new Snyk AppRisk integration with Orca Security](<https://devfeed.tech/articles/announcing-new-snyk-apprisk-integration-with-orca-security-7822.md>)

Original publisher: [Read original article](<https://snyk.io/blog/announcing-snyk-apprisk-integration-orca/>)

Author: Daniel Berman

Published: 2024-09-11T13:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk-apprisk](<https://devfeed.tech/topics/snyk-apprisk.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security & compliance, Cloud security](<https://devfeed.tech/topics/security-compliance-cloud-security.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [integration](<https://devfeed.tech/tags/integration.md>), [orca-security](<https://devfeed.tech/tags/orca-security.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [related-content](<https://devfeed.tech/tags/related-content.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Snyk announces an integration between Snyk AppRisk and Orca Security. The integration combines application security context and vulnerability prioritization from Snyk with Orca's cloud security and runtime visibility to help development and security teams identify, prioritize, and remediate business risks.

### Source excerpt

We're excited to announce a new Snyk AppRisk integration with Orca Security that brings together application security from Snyk and leading cloud security from Orca.

## Introducing new Snyk AppRisk integrations: Enhancing application risk management with development context

DevFeed: [Introducing new Snyk AppRisk integrations: Enhancing application risk management with development context](<https://devfeed.tech/articles/introducing-new-snyk-apprisk-integrations-enhancing-application-risk-management-with-development-context-8027.md>)

Original publisher: [Read original article](<https://snyk.io/blog/new-snyk-apprisk-integrations/>)

Author: Daniel Berman

Published: 2024-08-01T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk-apprisk](<https://devfeed.tech/topics/snyk-apprisk.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Development](<https://devfeed.tech/topics/development.md>), [Microservice](<https://devfeed.tech/topics/microservice.md>), [Backstage](<https://devfeed.tech/topics/backstage.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [blog](<https://devfeed.tech/tags/blog.md>), [development](<https://devfeed.tech/tags/development.md>), [devops](<https://devfeed.tech/tags/devops.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [integrations](<https://devfeed.tech/tags/integrations.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>)

### AI overview

This article announces new Snyk AppRisk integrations with ServiceNow CMDB, Atlassian Compass, OpsLevel, Harness, and Datadog Service Catalog, extending an existing Backstage integration. It explains how Internal Developer Portals and service catalogs provide development context, asset visibility, ownership information, and dependency data to support application risk management and shift-left application security.

### Source excerpt

We are thrilled to expand Snyk AppRisk integrations with additional leading Internal Developer Portals (IDPs) and service catalogs: ServiceNow CMDB, Atlassian Compass, OpsLevel, Harness, and Datadog Service Catalog!

## Why ASPM is the future of AppSec: Key points from our newest whitepaper

DevFeed: [Why ASPM is the future of AppSec: Key points from our newest whitepaper](<https://devfeed.tech/articles/why-aspm-is-the-future-of-appsec-key-points-from-our-newest-whitepaper-8250.md>)

Original publisher: [Read original article](<https://snyk.io/blog/why-aspm-is-future-of-appsec-whitepaper/>)

Author: Sarah Conway

Published: 2024-06-18T17:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [blog](<https://devfeed.tech/tags/blog.md>), [co-created](<https://devfeed.tech/tags/co-created.md>), [devops](<https://devfeed.tech/tags/devops.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [executive](<https://devfeed.tech/tags/executive.md>), [interest](<https://devfeed.tech/tags/interest.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [related-content](<https://devfeed.tech/tags/related-content.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

An overview of a Snyk and Accenture whitepaper argues that application security posture management can improve visibility, add business context, and help AppSec teams prioritize vulnerabilities.

### Source excerpt

Read an overview of Snyk and Accenture's recent whitepaper: Why ASPM is the future of Application Security.

## Why "vulnerability management" falls short in modern application security

DevFeed: [Why "vulnerability management" falls short in modern application security](<https://devfeed.tech/articles/why-vulnerability-management-falls-short-in-modern-application-security-8252.md>)

Original publisher: [Read original article](<https://snyk.io/blog/why-vulnerability-management-falls-short-in-appsec/>)

Author: Daniel Berman

Published: 2024-06-13T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [executive](<https://devfeed.tech/tags/executive.md>), [interest](<https://devfeed.tech/tags/interest.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

This blog article explains why vulnerability-management approaches can fall short for modern application security. It describes AppSec challenges involving software complexity, cyber threats, regulatory requirements, collaboration, prioritization, and application visibility. It presents ASPM and related approaches as unified views that aggregate security issues and support automation, while highlighting concerns about insufficient application context and scalability.

### Source excerpt

In this blog post, we discuss the how "vulnerability management" tends to fall short when approaching modern application security.

## AppSec spring cleaning checklist

DevFeed: [AppSec spring cleaning checklist](<https://devfeed.tech/articles/appsec-spring-cleaning-checklist-7828.md>)

Original publisher: [Read original article](<https://snyk.io/blog/appsec-spring-cleaning-checklist/>)

Author: Mariah Gresham

Published: 2024-05-13T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [automation](<https://devfeed.tech/tags/automation.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [containers](<https://devfeed.tech/tags/containers.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developers](<https://devfeed.tech/tags/developers.md>), [devops](<https://devfeed.tech/tags/devops.md>), [interest](<https://devfeed.tech/tags/interest.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

A checklist for tidying an application security program by organizing application assets, prioritizing security alerts by business risk, and improving policies and controls.

### Source excerpt

Dive into three tips for spring cleaning your AppSec program: organizing assets, decluttering alerts, and sprucing up policies/controls.

## More accurate than GPT-4: How Snyk's CodeReduce improved the performance of other LLMs

DevFeed: [More accurate than GPT-4: How Snyk's CodeReduce improved the performance of other LLMs](<https://devfeed.tech/articles/more-accurate-than-gpt-4-how-snyk-s-codereduce-improved-the-performance-of-other-llms-7883.md>)

Original publisher: [Read original article](<https://snyk.io/blog/deepcode-ai-vulnerability-autofixing/>)

Author: Eric Fernandez

Published: 2024-05-07T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [AI Chat](<https://devfeed.tech/topics/ai-chat.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [ai](<https://devfeed.tech/tags/ai.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code](<https://devfeed.tech/tags/code.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [convert-paid](<https://devfeed.tech/tags/convert-paid.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [devops](<https://devfeed.tech/tags/devops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [gpt](<https://devfeed.tech/tags/gpt.md>), [interest](<https://devfeed.tech/tags/interest.md>), [llms](<https://devfeed.tech/tags/llms.md>), [performance](<https://devfeed.tech/tags/performance.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Snyk describes CodeReduce and a curated security-fix dataset as components of Snyk Agent Fix, a beta capability for automatically fixing security issues identified by Snyk Code. The article frames these techniques as ways to improve LLM-based security remediation.

### Source excerpt

Fixing security issues is complex, so to learn more about how we do this, we will deep-dive into the research paper that explains the star ingredients behind Snyk Agent Fix - CodeReduce technology and our curated security fix dataset.

## Snyk AppRisk Pro: A holistic approach to application risk management

DevFeed: [Snyk AppRisk Pro: A holistic approach to application risk management](<https://devfeed.tech/articles/snyk-apprisk-pro-a-holistic-approach-to-application-risk-management-7903.md>)

Original publisher: [Read original article](<https://snyk.io/blog/empower-application-risk-management-with-snyk-apprisk/>)

Author: Daniel Berman

Published: 2024-05-01T12:55:00Z

Content type: release

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [snyk-apprisk](<https://devfeed.tech/topics/snyk-apprisk.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [data analytics](<https://devfeed.tech/topics/data-analytics.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [developer-productivity](<https://devfeed.tech/topics/developer-productivity.md>), [Development](<https://devfeed.tech/topics/development.md>), [dynatrace](<https://devfeed.tech/topics/dynatrace.md>), [Backstage](<https://devfeed.tech/topics/backstage.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [analytics](<https://devfeed.tech/tags/analytics.md>), [api](<https://devfeed.tech/tags/api.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [backstage](<https://devfeed.tech/tags/backstage.md>), [blog](<https://devfeed.tech/tags/blog.md>), [convert-paid](<https://devfeed.tech/tags/convert-paid.md>), [developer-productivity](<https://devfeed.tech/tags/developer-productivity.md>), [development](<https://devfeed.tech/tags/development.md>), [devops](<https://devfeed.tech/tags/devops.md>), [dynatrace](<https://devfeed.tech/tags/dynatrace.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [executive](<https://devfeed.tech/tags/executive.md>), [gitguardian](<https://devfeed.tech/tags/gitguardian.md>), [measurement](<https://devfeed.tech/tags/measurement.md>), [observability](<https://devfeed.tech/tags/observability.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [reporting](<https://devfeed.tech/tags/reporting.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>)

### AI overview

Snyk announces Snyk AppRisk Pro, an application security posture management offering for managing and scaling application security programs. It combines application visibility and discovery, security coverage management, and risk-based prioritization with runtime intelligence, developer-context integrations, extended security coverage, and application analytics for tracking program performance and risk.

### Source excerpt

Find out how Snyk AppRisk Pro, our application security posture management (ASPM) solution, is designed to empower your application risk management programs.

[Next page](<https://devfeed.tech/tags/snyk-apprisk.md?cursor=WyIyMDI0LTA1LTAxVDEyOjU1OjAwKzAwOjAwIiwgImI5MDk5YzI5LWM5MjUtNGVhNC05NTY0LWFjMjk4YTE2ZWQ0MyJd>)