# snyk

Snyk is an AI security company providing developer-first tooling and a security platform that finds and fixes issues across code, dependencies, containers, and cloud infrastructure.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## SHA1-Hulud, npm supply chain incident

DevFeed: [SHA1-Hulud, npm supply chain incident](<https://devfeed.tech/articles/sha1-hulud-npm-supply-chain-incident-8097.md>)

Original publisher: [Read original article](<https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/>)

Author: Brian Vermeer

Published: 2025-11-24T18:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [npm](<https://devfeed.tech/topics/npm.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Azure](<https://devfeed.tech/topics/azure.md>), [Google Cloud Platform (GCP)](<https://devfeed.tech/topics/google-cloud.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [incident](<https://devfeed.tech/tags/incident.md>), [npm](<https://devfeed.tech/tags/npm.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [sha1-hulud](<https://devfeed.tech/tags/sha1-hulud.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [trust](<https://devfeed.tech/tags/trust.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>), [worm](<https://devfeed.tech/tags/worm.md>)

### AI overview

Snyk reports SHA1-Hulud, a second-wave npm supply chain attack and worm that spreads through trojanized packages with hidden preinstall scripts. The worm can compromise GitHub Actions self-hosted runners, inject malicious workflows, execute remote commands, exfiltrate GitHub and npm secrets, and search for AWS, Azure, and GCP credentials. Snyk identified more than 600 impacted npm packages and is retesting customer assets, notifying affected customers, and updating its vulnerability databases.

### Source excerpt

Snyk identified a new supply chain attack in the npm ecosystem, referred to as SHA1-Hulud. We believe this is a second wave of the Shai-Hulud attack. Learn what this attack is and how Snyk is responding.

## Anthem Awards 2025: Snyk Learn Recognized for Commitment to Secure AI Development

DevFeed: [Anthem Awards 2025: Snyk Learn Recognized for Commitment to Secure AI Development](<https://devfeed.tech/articles/anthem-awards-2025-snyk-learn-recognized-for-commitment-to-secure-ai-development-8143.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-learn-anthem-awards-2025/>)

Author: Michael Biocchi

Published: 2025-11-19T05:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk-learn](<https://devfeed.tech/topics/snyk-learn.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Learning](<https://devfeed.tech/topics/learning.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-development](<https://devfeed.tech/tags/ai-development.md>), [awards](<https://devfeed.tech/tags/awards.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [developer](<https://devfeed.tech/tags/developer.md>), [education](<https://devfeed.tech/tags/education.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-learn](<https://devfeed.tech/tags/snyk-learn.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Snyk Learn was recognized as a Silver Winner in the Responsible Technology: Education or Literacy Platform category at the 2025 Anthem Awards. The free platform helps developers understand, identify, and fix code vulnerabilities through bite-sized lessons, interactive examples, and real-world scenarios, including guidance for secure AI development.

### Source excerpt

We are incredibly proud and excited to announce that Snyk Learn has been recognized as a Silver Winner in the Responsible Technology: Education or Literacy Platform category at the 5th annual Anthem Awards!

## Secure by Design: The Future of Threat Modeling for AI-Native Applications

DevFeed: [Secure by Design: The Future of Threat Modeling for AI-Native Applications](<https://devfeed.tech/articles/secure-by-design-the-future-of-threat-modeling-for-ai-native-applications-7936.md>)

Original publisher: [Read original article](<https://snyk.io/blog/future-threat-modeling-ai-native-apps/>)

Author: John Carione

Published: 2025-11-11T05:00:00Z

Content type: opinion

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Security for AI](<https://devfeed.tech/topics/security-for-ai.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [security-for-ai](<https://devfeed.tech/tags/security-for-ai.md>), [snyk](<https://devfeed.tech/tags/snyk.md>)

### AI overview

This Snyk article argues that traditional, manual threat modeling cannot keep pace with AI-native applications built from large language models, autonomous agents, APIs, and changing data flows. It presents continuous, automated, AI-assisted threat modeling as a way to maintain secure-by-design systems and address risks such as prompt injection, data exfiltration, data poisoning, and agentic vulnerabilities.

### Source excerpt

Explore how Snyk's Evo Threat Modeling Agent automates and contextualizes security for AI-native applications, addressing prompt injection, data exfiltration, data poisoning, and agentic vulnerabilities.

## Snyk Studio brings security scanning and automated fixes to Factory's Droids

DevFeed: [Snyk Studio brings security scanning and automated fixes to Factory's Droids](<https://devfeed.tech/articles/snyk-studio-brings-security-scanning-and-automated-fixes-to-factory-s-droids-8126.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-factory-partner-integration/>)

Author: Sarah Conway

Published: 2025-11-05T05:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [Security](<https://devfeed.tech/topics/security.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Model Context Protocol](<https://devfeed.tech/topics/model-context-protocol.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [agentic-security](<https://devfeed.tech/tags/agentic-security.md>), [ai](<https://devfeed.tech/tags/ai.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [model-context-protocol](<https://devfeed.tech/tags/model-context-protocol.md>), [partnership](<https://devfeed.tech/tags/partnership.md>), [related-content](<https://devfeed.tech/tags/related-content.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Snyk announces a partnership with Factory to bring Snyk Studio's real-time security intelligence into Factory Droid workflows through the Model Context Protocol. The integration is designed to help Droids identify and remediate vulnerabilities in newly generated code and reduce existing security debt using prioritized vulnerability data.

### Source excerpt

Snyk is thrilled to announce our partnership with Factory, which brings Snyk Studio directly into Droid workflows.

## DevSecCon 2025 Recap: Securing the AI Revolution Together

DevFeed: [DevSecCon 2025 Recap: Securing the AI Revolution Together](<https://devfeed.tech/articles/devseccon-2025-recap-securing-the-ai-revolution-together-7892.md>)

Original publisher: [Read original article](<https://snyk.io/blog/devseccon-2025-recap-securing-the-ai-revolution-together/>)

Author: Ben Desjardins

Published: 2025-10-22T23:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [ide](<https://devfeed.tech/topics/ide.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [snyk-code](<https://devfeed.tech/topics/snyk-code.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [ai](<https://devfeed.tech/tags/ai.md>), [also](<https://devfeed.tech/tags/also.md>), [blog](<https://devfeed.tech/tags/blog.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [ide](<https://devfeed.tech/tags/ide.md>), [interest](<https://devfeed.tech/tags/interest.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>)

### AI overview

This DevSecCon 2025 recap examines how AI is changing software development and security. It covers AI-accelerated DevSecOps, securing code from the first prompt, and managing AI-native application chaos with Evo by Snyk. The article also highlights Snyk capabilities for IDEs, pull requests, Snyk Code, and AppSec governance.

### Source excerpt

AI is changing development. Our DevSecCon 2025 recap covers the 3 critical stages: AI-Accelerated DevSecOps, securing code at the first prompt, and taming AI-native app chaos with Evo by Snyk.

## Why We Built Evo -- From My Heart

DevFeed: [Why We Built Evo -- From My Heart](<https://devfeed.tech/articles/why-we-built-evo-from-my-heart-7983.md>)

Original publisher: [Read original article](<https://snyk.io/blog/introducing-evo-by-snyk/>)

Author: Manoj Nair

Published: 2025-10-22T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [ai security](<https://devfeed.tech/topics/ai-security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [agentic-security](<https://devfeed.tech/tags/agentic-security.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [developer](<https://devfeed.tech/tags/developer.md>), [llm](<https://devfeed.tech/tags/llm.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>)

### AI overview

Snyk introduces Evo as an agentic security orchestrator for AI-native software systems. The article argues that AI security must be an autonomous, operational, continuous architecture integrated into development rather than a passive collection of scanners, policies, or dashboards.

### Source excerpt

Introducing Evo by Snyk, the world's first Agentic Security Orchestrator. Learn why Evo is changing the game in cybersecurity to make security seamless, invisible, intelligent, and unstoppable--so innovation never has to slow down again.

## Increasing Agility & Flexibility: How Mercato Solutions tackles the application security vs. flexibility conundrum with Snyk

DevFeed: [Increasing Agility & Flexibility: How Mercato Solutions tackles the application security vs. flexibility conundrum with Snyk](<https://devfeed.tech/articles/increasing-agility-flexibility-how-mercato-solutions-tackles-the-application-security-vs-flexibility-conundrum-with-snyk-7951.md>)

Original publisher: [Read original article](<https://snyk.io/blog/how-mercato-solutions-tackles-appsec-flexibility-conundrum-with-Snyk/>)

Author: Nina McClure

Published: 2025-10-16T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Low code](<https://devfeed.tech/topics/low-code.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Web](<https://devfeed.tech/topics/web.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [customer](<https://devfeed.tech/tags/customer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [low-code](<https://devfeed.tech/tags/low-code.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

This customer article explains how Mercato Solutions, a low-code enterprise application provider, works with Snyk to address application security challenges while preserving the flexibility of its cloud-first platform. The article highlights the security risks of headless infrastructure, the resulting attack surface, and Mercato's goal of maintaining strong security with a small team.

### Source excerpt

Learn how Mercato Solutions, a fast-growing low-code application provider, achieved near-zero security incidents and maintained development flexibility by partnering with Snyk API & Web.

## Snyk Named a Leader in the 2025 Forrester SAST Wave: SAST Solutions, Q3 2025

DevFeed: [Snyk Named a Leader in the 2025 Forrester SAST Wave: SAST Solutions, Q3 2025](<https://devfeed.tech/articles/snyk-named-a-leader-in-the-2025-forrester-sast-wave-sast-solutions-q3-2025-8148.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-named-a-leader-in-the-2025-forrester-sast-wave-sast-solutions-q3-2025/>)

Author: Ben Desjardins

Published: 2025-09-09T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [Developer experience](<https://devfeed.tech/topics/developer-experience.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer-experience](<https://devfeed.tech/tags/developer-experience.md>), [executive](<https://devfeed.tech/tags/executive.md>), [recognition](<https://devfeed.tech/tags/recognition.md>), [sast](<https://devfeed.tech/tags/sast.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Snyk announces that Forrester recognized it as a Leader in the 2025 Forrester Wave for Static Application Security Testing Solutions. The article attributes this position to Snyk's innovation, AI Security Platform, developer experience, enterprise analytics and visibility, broad Application Security Testing capabilities, and customer impact. It also highlights AI-powered prioritization, autonomous fixes, and the role of Snyk in shift-left security strategies.

### Source excerpt

We're excited to announce that Snyk has been recognized as a Leader in the Forrester Wave™: Static Application Security Testing (SAST) Solutions, Q3 2025.

## Meeting the AI Mandates with Confidence: Why Federal Teams Trust Snyk

DevFeed: [Meeting the AI Mandates with Confidence: Why Federal Teams Trust Snyk](<https://devfeed.tech/articles/meeting-the-ai-mandates-with-confidence-why-federal-teams-trust-snyk-8251.md>)

Original publisher: [Read original article](<https://snyk.io/blog/why-federal-teams-trust-snyk/>)

Author: Phoebe Nerdahl

Published: 2025-08-07T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [ai security](<https://devfeed.tech/topics/ai-security.md>), [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Platform](<https://devfeed.tech/topics/ai-platform.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [agentic-ai-security](<https://devfeed.tech/tags/agentic-ai-security.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-adoption](<https://devfeed.tech/tags/ai-adoption.md>), [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [devops](<https://devfeed.tech/tags/devops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [github](<https://devfeed.tech/tags/github.md>), [government](<https://devfeed.tech/tags/government.md>), [nist](<https://devfeed.tech/tags/nist.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [terraform](<https://devfeed.tech/tags/terraform.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains how Snyk for Government helps federal agencies adopt AI securely through secure-by-design development, continuous vulnerability management, compliance support, automation, and governance. It highlights integrations across developer workflows, FedRAMP authorization, standards-aligned practices, and the Snyk AI Trust Platform.

### Source excerpt

Learn how Snyk for Government helps federal agencies meet AI mandates with confidence. Snyk's AI Trust Platform ensures secure-by-design development, compliance, and transparent AI systems.

## Fixing Fix Fatigue: Building Developer Trust for Secure AI Code

DevFeed: [Fixing Fix Fatigue: Building Developer Trust for Secure AI Code](<https://devfeed.tech/articles/fixing-fix-fatigue-building-developer-trust-for-secure-ai-code-7926.md>)

Original publisher: [Read original article](<https://snyk.io/blog/fixing-fix-fatigue-building-developer-trust-for-secure-ai-code/>)

Author: Ezra Tanzer

Published: 2025-06-30T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [ai-coding](<https://devfeed.tech/topics/ai-coding.md>), [GitHub Copilot](<https://devfeed.tech/topics/github-copilot.md>), [snyk](<https://devfeed.tech/topics/snyk.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [github-copilot](<https://devfeed.tech/tags/github-copilot.md>), [interest](<https://devfeed.tech/tags/interest.md>), [productivity](<https://devfeed.tech/tags/productivity.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [snyk](<https://devfeed.tech/tags/snyk.md>)

### AI overview

This article explains how AI coding assistants increase developer productivity while introducing security risks, including vulnerabilities in AI-generated code. It argues that security tools must build developer confidence through verified fixes, real-time scanning, and workflows that reduce friction and alert fatigue.

### Source excerpt

Build developer trust in AI security tools with verified fixes, real-time scanning, and frictionless workflows powered by Snyk Agent Fix.

## Why AI Trust Will Shape Your Next Decade of Software Development

DevFeed: [Why AI Trust Will Shape Your Next Decade of Software Development](<https://devfeed.tech/articles/why-ai-trust-will-shape-your-next-decade-of-software-development-8248.md>)

Original publisher: [Read original article](<https://snyk.io/blog/why-ai-trust-will-shape-your-next-decade-of-software-development/>)

Author: Brendan Hann

Published: 2025-06-24T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Security](<https://devfeed.tech/topics/security.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>), [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-adoption](<https://devfeed.tech/tags/ai-adoption.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [ai-transparency](<https://devfeed.tech/tags/ai-transparency.md>), [automation](<https://devfeed.tech/tags/automation.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [developer](<https://devfeed.tech/tags/developer.md>), [development](<https://devfeed.tech/tags/development.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [governance](<https://devfeed.tech/tags/governance.md>), [interest](<https://devfeed.tech/tags/interest.md>), [llm](<https://devfeed.tech/tags/llm.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [speed](<https://devfeed.tech/tags/speed.md>), [trust](<https://devfeed.tech/tags/trust.md>)

### AI overview

The article argues that AI trust is foundational for safe, scalable software development as organizations adopt AI and agentic workflows. It describes AI trust as maintaining control, visibility, security, governance, and continuous risk management while benefiting from faster delivery, greater productivity, and automation. It highlights risks including insecure AI-generated code, prompt injection, data exfiltration, model manipulation, and misconfiguration, and presents Snyk's AI Security Platform as a way to embed risk management and security into the SDLC.

### Source excerpt

Discover why AI Trust is crucial for secure, scalable software development in the AI era. Learn how Snyk's AI Security Platform helps you manage risk, enforce policies, and ensure continuous compliance.

## Building AI Trust with Snyk Code and Snyk Agent Fix

DevFeed: [Building AI Trust with Snyk Code and Snyk Agent Fix](<https://devfeed.tech/articles/building-ai-trust-with-snyk-code-and-snyk-agent-fix-7853.md>)

Original publisher: [Read original article](<https://snyk.io/blog/building-ai-trust-with-snyk-code-and-snyk-agent-fix/>)

Author: Liqian Lim (林利蒨); Brendan Hann

Published: 2025-06-23T04:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [snyk-code](<https://devfeed.tech/topics/snyk-code.md>), [ai security](<https://devfeed.tech/topics/ai-security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [ai-governance](<https://devfeed.tech/topics/ai-governance.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [ide](<https://devfeed.tech/topics/ide.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [ai-governance](<https://devfeed.tech/tags/ai-governance.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [auto-remediation](<https://devfeed.tech/tags/auto-remediation.md>), [autonomous](<https://devfeed.tech/tags/autonomous.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [sast](<https://devfeed.tech/tags/sast.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>)

### AI overview

Snyk describes its AI Security Platform, Snyk Code, and Snyk Agent Fix for governing AI-assisted development. Snyk Agent Fix autonomously generates and validates code-security fixes, offering auto-remediation in IDEs and pull requests, while Snyk Code provides SAST, visibility, prioritization, and policy controls.

### Source excerpt

Secure and accelerate your adoption of AI coding with pre-screened auto-fixes and autonomous code security for modern, developer-loved SAST.

## Announcing a Dedicated Snyk API & Web Infrastructure Instance for Asia-Pacific

DevFeed: [Announcing a Dedicated Snyk API & Web Infrastructure Instance for Asia-Pacific](<https://devfeed.tech/articles/announcing-a-dedicated-snyk-api-web-infrastructure-instance-for-asia-pacific-7820.md>)

Original publisher: [Read original article](<https://snyk.io/blog/announcing-snyk-api-and-web-infrastructure-instance-for-asia-pacific/>)

Author: Snyk Team

Published: 2025-06-16T23:00:00Z

Content type: release

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [API](<https://devfeed.tech/topics/api.md>), [Web](<https://devfeed.tech/topics/web.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [Latency](<https://devfeed.tech/topics/latency.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [announce](<https://devfeed.tech/tags/announce.md>), [apac](<https://devfeed.tech/tags/apac.md>), [api](<https://devfeed.tech/tags/api.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [community](<https://devfeed.tech/tags/community.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [data-privacy](<https://devfeed.tech/tags/data-privacy.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [latency](<https://devfeed.tech/tags/latency.md>), [launch](<https://devfeed.tech/tags/launch.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

Snyk has launched a dedicated Snyk API & Web infrastructure instance hosted locally in the Asia-Pacific region. The instance supports regional data residency and compliance requirements, reduces latency, and provides DAST capabilities for identifying runtime vulnerabilities in the context of AI-driven development.

### Source excerpt

Snyk is delighted to announce a significant milestone for our customers and partners in the Asia-Pacific region: the launch of a dedicated Snyk API & Web infrastructure instance, which is now available and hosted locally within the region.

## Snyk for Government Achieves FedRAMP Moderate Authorization: A Milestone for Secure Government Software

DevFeed: [Snyk for Government Achieves FedRAMP Moderate Authorization: A Milestone for Secure Government Software](<https://devfeed.tech/articles/snyk-for-government-achieves-fedramp-moderate-authorization-a-milestone-for-secure-government-software-8133.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-for-government-achieves-fedramp-moderate-authorization/>)

Author: Danny Allan

Published: 2025-06-05T23:00:00Z

Content type: release

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [executive](<https://devfeed.tech/tags/executive.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [government](<https://devfeed.tech/tags/government.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Snyk announced that Snyk for Government has received FedRAMP Moderate authorization for U.S. public-sector use. The company says the offering supports vulnerability detection, remediation guidance, policy enforcement, developer-tool integrations, and compliance reporting.

### Source excerpt

Snyk for Government is our FedRAMP Moderate authorized solution for the public sector. This authorization underscores our unwavering commitment to providing secure development solutions that meet the rigorous standards of the Federal Risk and Authorization Management Program (FedRAMP).

## Welcome to Snyk Labs: Charting the Course for AI-Native Security

DevFeed: [Welcome to Snyk Labs: Charting the Course for AI-Native Security](<https://devfeed.tech/articles/welcome-to-snyk-labs-charting-the-course-for-ai-native-security-8235.md>)

Original publisher: [Read original article](<https://snyk.io/blog/welcome-to-snyk-labs-charting-the-course-for-ai-native-security/>)

Author: Manoj Nair

Published: 2025-05-28T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [ai security](<https://devfeed.tech/topics/ai-security.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [LLM security](<https://devfeed.tech/topics/llm-security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-development](<https://devfeed.tech/tags/ai-development.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cosai](<https://devfeed.tech/tags/cosai.md>), [developer](<https://devfeed.tech/tags/developer.md>), [large-language-models-llms](<https://devfeed.tech/tags/large-language-models-llms.md>), [llm-security](<https://devfeed.tech/tags/llm-security.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [security](<https://devfeed.tech/tags/security.md>), [security-labs](<https://devfeed.tech/tags/security-labs.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Snyk introduces Snyk Labs, an innovation and research arm focused on helping developers and security leaders address emerging risks in AI-native applications. The hub will publish technical demos, prototypes, research, analysis of AI threats and standards, and experiments. Its work includes AI Security Posture Management, an AI Bill of Materials, a GenAI Model Risk Registry, vulnerability research, continuous monitoring of AI behavior, and contributions to LLM security standards with OWASP and CoSAI.

### Source excerpt

Discover Snyk Labs, Snyk's AI security resource hub for the latest technical demos, sharing emerging threats and standards, & early insights into the AI security landscape.

## Driving AI Security Innovation: Snyk Enhances Global Channel & GSI Partner Program

DevFeed: [Driving AI Security Innovation: Snyk Enhances Global Channel & GSI Partner Program](<https://devfeed.tech/articles/driving-ai-security-innovation-snyk-enhances-global-channel-gsi-partner-program-7898.md>)

Original publisher: [Read original article](<https://snyk.io/blog/driving-ai-security-innovation-snyk-enhances-global-channel-and-gsi-partner/>)

Author: Cyndi Doyle

Published: 2025-05-08T04:00:00Z

Content type: release

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [ai security](<https://devfeed.tech/topics/ai-security.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [Generative AI](<https://devfeed.tech/topics/generative-ai.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [partners](<https://devfeed.tech/tags/partners.md>), [partnerships](<https://devfeed.tech/tags/partnerships.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [updates](<https://devfeed.tech/tags/updates.md>)

### AI overview

Snyk describes updates to its Global Channel & GSI Partner Program, including formalized go-to-market programs, revised resale discounts, marketing development funds, co-marketing planning, and enhanced partner enablement. The changes emphasize strategic collaboration and AI Security opportunities.

### Source excerpt

Discover Snyk's enhanced Partner Program for AI Security. Drive growth with optimized discounts, MDF, new GTM programs & dedicated support for mutual success.

## Secure AI-Generated Code at Speed with Snyk and ServiceNow

DevFeed: [Secure AI-Generated Code at Speed with Snyk and ServiceNow](<https://devfeed.tech/articles/secure-ai-generated-code-at-speed-with-snyk-and-servicenow-8075.md>)

Original publisher: [Read original article](<https://snyk.io/blog/secure-ai-generated-code-at-speed-with-snyk-and-servicenow/>)

Author: Sarah Conway

Published: 2025-05-01T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-assisted-coding](<https://devfeed.tech/tags/ai-assisted-coding.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [automated](<https://devfeed.tech/tags/automated.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code](<https://devfeed.tech/tags/code.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [development](<https://devfeed.tech/tags/development.md>), [executive](<https://devfeed.tech/tags/executive.md>), [interest](<https://devfeed.tech/tags/interest.md>), [related-content](<https://devfeed.tech/tags/related-content.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

The article examines the security risks of AI-generated code and presents the Snyk and ServiceNow partnership as a way to combine AI-powered developer security with enterprise workflow automation. It emphasizes real-time feedback, vulnerability prioritization, remediation tracking, and automated fixes to help application security teams manage the scale and speed of AI-assisted coding.

### Source excerpt

Explore the security risks of AI-generated code and how Snyk & ServiceNow offer AI-powered developer security integrated with enterprise workflows for effective remediation.

## Snyk launches Snyk API & Web, a dynamic application security testing solution

DevFeed: [Snyk launches Snyk API & Web, a dynamic application security testing solution](<https://devfeed.tech/articles/snyk-ushers-in-the-future-of-dast-ai-driven-security-for-the-age-of-ai-driven-development-8113.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-announces-the-future-of-dast-ai-driven-security-for-the-age-of-ai/>)

Author: Manoj Nair

Published: 2025-04-22T12:00:00Z

Content type: release

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [API](<https://devfeed.tech/topics/api.md>), [Development](<https://devfeed.tech/topics/development.md>), [Web](<https://devfeed.tech/topics/web.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Generative AI](<https://devfeed.tech/topics/generative-ai.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-development](<https://devfeed.tech/tags/ai-development.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [api](<https://devfeed.tech/tags/api.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [customer-featured](<https://devfeed.tech/tags/customer-featured.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

Snyk announces Snyk API & Web, a dynamic application security testing solution integrated with its Developer Security Platform. The article says it combines Probely's DAST technology with Snyk's SAST, SCA, container, and infrastructure-as-code security engines to address security challenges in modern applications, including APIs connecting applications and large language models.

### Source excerpt

Snyk launches Snyk API & Web, an AI-driven DAST engine that helps organizations automatically find and expose vulnerabilities at scale. Deeply integrated in Snyk's Developer Security Platform, Snyk API & Web is the company's answer to securing the complex, AI-powered applications developers are building today.

## Snyk Partners with Nova8 to Empower Secure Development Across Latin America

DevFeed: [Snyk Partners with Nova8 to Empower Secure Development Across Latin America](<https://devfeed.tech/articles/snyk-partners-with-nova8-to-empower-secure-development-across-latin-america-8152.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-partners-with-nova8-to-empower-secure-development-across-latin-america/>)

Author: Michael Daniels

Published: 2025-04-15T04:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [Development](<https://devfeed.tech/topics/development.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developer-security-platform](<https://devfeed.tech/tags/developer-security-platform.md>), [developers](<https://devfeed.tech/tags/developers.md>), [devops](<https://devfeed.tech/tags/devops.md>), [external](<https://devfeed.tech/tags/external.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [partners](<https://devfeed.tech/tags/partners.md>), [partnership](<https://devfeed.tech/tags/partnership.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [snyk-iac](<https://devfeed.tech/tags/snyk-iac.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Snyk announces a strategic partnership with Nova8 to expand developer security adoption across Latin America. The partnership combines Snyk's developer security platform with Nova8's regional distribution, implementation, training, customization, and channel-partner expertise to help organizations identify and fix application vulnerabilities earlier.

### Source excerpt

Snyk joins forces with cybersecurity distributor Nova8 to accelerate developer security adoption in Latin America. See how the partnership helps reduce risk.

## Snyk Security Solution Now Integrated into Google Cloud's Gemini Code Assist

DevFeed: [Snyk Security Solution Now Integrated into Google Cloud's Gemini Code Assist](<https://devfeed.tech/articles/snyk-security-solution-now-integrated-into-google-cloud-s-gemini-code-assist-8165.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-security-solution-now-integrated-into-google-clouds-gemini-code-assist/>)

Author: Liqian Lim (林利蒨)

Published: 2025-04-09T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [ide](<https://devfeed.tech/topics/ide.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [executive](<https://devfeed.tech/tags/executive.md>), [gemini](<https://devfeed.tech/tags/gemini.md>), [google](<https://devfeed.tech/tags/google.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [related-content](<https://devfeed.tech/tags/related-content.md>), [sast](<https://devfeed.tech/tags/sast.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>)

### AI overview

Snyk's security solution is integrated into Google Cloud's Gemini Code Assist, enabling developers to use Snyk security capabilities through natural-language prompts and the coding assistant's chat interface.

### Source excerpt

Secure AI coding with Snyk and Google Gemini. Learn how Snyk Code's SAST integrates with Gemini Code Assist for seamless, secure development workflows.

## Q&A Session with Snyk & John Hammond: Your Fetch the Flag Questions, Answered

DevFeed: [Q&A Session with Snyk & John Hammond: Your Fetch the Flag Questions, Answered](<https://devfeed.tech/articles/q-a-session-with-snyk-john-hammond-your-fetch-the-flag-questions-answered-8259.md>)

Original publisher: [Read original article](<https://snyk.io/blog/your-fetch-the-flag-questions-answered-with-snyk-and-john-hammond/>)

Author: Taylor Macomber; Gina Fitzpatrick

Published: 2025-04-01T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [ctf](<https://devfeed.tech/topics/ctf.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [math](<https://devfeed.tech/topics/math.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [community](<https://devfeed.tech/tags/community.md>), [ctf](<https://devfeed.tech/tags/ctf.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [developer](<https://devfeed.tech/tags/developer.md>), [event](<https://devfeed.tech/tags/event.md>), [interest](<https://devfeed.tech/tags/interest.md>), [python](<https://devfeed.tech/tags/python.md>), [q-a](<https://devfeed.tech/tags/q-a.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-learn](<https://devfeed.tech/tags/snyk-learn.md>)

### AI overview

This article presents a live Q&A following Snyk's Fetch the Flag CTF event. Cybersecurity educator John Hammond, challenge designer Matt Kiely, and developer advocates answer questions about getting started with CTFs, collaborating with the security community, using Netcat and pwntools, and automating challenge interactions with Python socket tools. It also introduces a challenge involving JavaScript's Math.random() and discusses securely using generative AI coding tools.

### Source excerpt

Here are five standout questions and answers from Snyk's Fetch the Flag CTF event on February 27 and 28. Sit down with cybersecurity educator and developer influencer John Hammond--along with challenge designer Matt Kiely (aka huskyhacks), and developer advocates Micah Silverman, Sonya Moisset, Vandana Verma, and Elliot Ward--for a live Q&A session.

## Lottie Player npm package compromised for crypto wallet theft

DevFeed: [Lottie Player npm package compromised for crypto wallet theft](<https://devfeed.tech/articles/lottie-player-npm-package-compromised-for-crypto-wallet-theft-8007.md>)

Original publisher: [Read original article](<https://snyk.io/blog/lottie-player-npm-package-compromised-crypto-wallet-theft/>)

Author: Liran Tal

Published: 2024-10-31T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cli](<https://devfeed.tech/tags/cli.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [crypto](<https://devfeed.tech/tags/crypto.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [incident](<https://devfeed.tech/tags/incident.md>), [npm](<https://devfeed.tech/tags/npm.md>), [package-compromise](<https://devfeed.tech/tags/package-compromise.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The @lottiefiles/lottie-player npm package was compromised after an npm registry publishing token was exposed. Malicious code in versions 2.0.5, 2.0.6, and 2.0.7 attempted to prompt users to connect cryptocurrency wallets. Those versions were removed, and version 2.0.8 restored the safe project code. The article explains how to use Snyk Dependency Reports and the Snyk CLI to identify affected projects and vulnerable dependencies.

### Source excerpt

On October 31st, 2024, another package compromise and cryptocurrency hijack story unfolded for a popular npm package. Scan open source dependencies and container images in the CLI or your SCM with Snyk to determine if you're using one of the vulnerable versions of lottie-player, and potentially uncover any other security vulnerabilities you may have in your projects.

## Best practices for continuous vulnerability management

DevFeed: [Best practices for continuous vulnerability management](<https://devfeed.tech/articles/best-practices-for-continuous-vulnerability-management-7842.md>)

Original publisher: [Read original article](<https://snyk.io/blog/best-practices-continuous-vulnerability-management/>)

Author: Liran Tal

Published: 2024-10-29T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [developer tooling](<https://devfeed.tech/topics/developer-tooling.md>), [npm](<https://devfeed.tech/topics/npm.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [blog](<https://devfeed.tech/tags/blog.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [llm](<https://devfeed.tech/tags/llm.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pycharm](<https://devfeed.tech/tags/pycharm.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [snyk-learn](<https://devfeed.tech/tags/snyk-learn.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [visual-studio-code](<https://devfeed.tech/tags/visual-studio-code.md>), [vs-code](<https://devfeed.tech/tags/vs-code.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This article presents continuous vulnerability management as essential for addressing risks from open-source dependencies, supply chain incidents, AI-generated code, and emerging cybersecurity threats. It recommends building a proactive security culture, integrating security throughout the software development lifecycle, providing ongoing training and awareness, and automating security workflows across DevOps and DevSecOps teams. It also advocates shift-left security through tools such as Snyk Code in IDEs including Visual Studio Code and Pycharm.

### Source excerpt

By integrating security practices into the development lifecycle, providing continuous education and training, and automating security workflows, organizations can effectively mitigate risks from open-source supply chain incidents, AI-generated code, and emerging threats. Snyk provides the tools and resources to establish a proactive security culture and ensure application security.

## Snyk announces commitment to Service for America, bringing security education access to all

DevFeed: [Snyk announces commitment to Service for America, bringing security education access to all](<https://devfeed.tech/articles/snyk-announces-commitment-to-service-for-america-bringing-security-education-access-to-all-8112.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-announces-commitment-to-service-for-america-bringing-security-education-access-to-all/>)

Author: Michael Biocchi

Published: 2024-10-17T05:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [snyk-learn](<https://devfeed.tech/topics/snyk-learn.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Learning](<https://devfeed.tech/topics/learning.md>), [AdventureX 2026](<https://devfeed.tech/topics/adventurex2026.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [capture](<https://devfeed.tech/tags/capture.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [ctf](<https://devfeed.tech/tags/ctf.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [education](<https://devfeed.tech/tags/education.md>), [executive](<https://devfeed.tech/tags/executive.md>), [free](<https://devfeed.tech/tags/free.md>), [government](<https://devfeed.tech/tags/government.md>), [learn](<https://devfeed.tech/tags/learn.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-learn](<https://devfeed.tech/tags/snyk-learn.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [teams](<https://devfeed.tech/tags/teams.md>), [training](<https://devfeed.tech/tags/training.md>), [workshops](<https://devfeed.tech/tags/workshops.md>)

### AI overview

Snyk announces its commitment to the Service for America Initiative by providing free cybersecurity education through Snyk Learn. The platform offers interactive lessons, learning paths, resources, and a Capture the Flag 101 workshop for students to help developers, security teams, and aspiring professionals build practical skills for secure software development.

### Source excerpt

Snyk partners with the Service for America Initiative to offer free cybersecurity education through Snyk Learn. Discover Snyk Learn's free, hands-on training and workshops designed to equip developers and security teams with the skills to build secure applications. From coding security to Capture the Flag events, Snyk helps prepare students and professionals for the ever-evolving cyber landscape.

[Next page](<https://devfeed.tech/topics/snyk.md?cursor=WyIyMDI0LTEwLTE3VDA1OjAwOjAwKzAwOjAwIiwgImZjZGM2NmQyLWVhMWUtNGU5Ny05MDVmLTJiZmUxYWUyNTdkOCJd>)