Please turn JavaScript on

Cycode

Subscribe to Cycode’s news feed.

Click on “Follow” and decide if you want to get news from Cycode via RSS, as email newsletter, via mobile or on your personal news page.

Subscription to Cycode comes without risk as you can unsubscribe instantly at any time.

You can also filter the feed to your needs via topics and keywords so that you only receive the news from Cycode which you are really interested in. Click on the blue “Filter” button below to get started.

Website title: Cycode | AI Native Application Security Platform

Is this your feed? Claim it!

Publisher:  Unclaimed!
Message frequency:  0.43 / day

Message History

Much of the debate about agentic code scanning revolves around three core questions: Do more capable models find more vulnerabilities? Where does deterministic, rules-based SAST still fit? What does the cost and performance balance look like?

We ran two benchmarks to ans...


Read full story

Your backlog is full of low- and medium-severity vulnerabilities nobody is planning to fix. A profile page leaking information. A reset endpoint with no rate limit. A form missing a CSRF check. These are all medium-severity issues which are reasonable to defer in isolation. However, together they add up to a critical exploit. The leak reveals how reset tokens are built, the m...


Read full story

TL;DR: Agentic Code Scanning is the fourth dimension of Cycode’s code scanning spectrum, not a separate product bolted on. Deterministic SAST, AI SAST, SAST + AI Exploitability, and Agentic Code Scanning run as one single system that decides what runs where, so you stop trading precision vs. cost vs. model. It caught both authorization CVEs in our benchmark that no rul...


Read full story
AI Security Maturity Models Keep Grading the Wrong Thing

In the span of ten months, the security industry produced more AI maturity models than most teams will ever read. SANS shipped one in May 2026, and the Cloud Security Alliance published a different one a week later.

OWASP added a second model of its own in June. Accenture and Carnegie Mellon’s Software Engineerin...


Read full story

A web GUI used to drive spacecraft and instrument commanding shipped a server that listens on every network interface, asks nobody for a password, and can be steered by any web page an operator happens to open. Here is how a stack of small, ordinary web mistakes adds up to unauthenticated command execution against hardware that is very much not ordinary, and what to do about ...


Read full story