The Ultimate Guide to Application Security
A curated Canadian edition of IndustrialDay news, analysis, interviews, reviews, job moves, and related resources for Application Security.
What to know about Application Security
Application Security focuses on protecting software applications from vulnerabilities and cyber threats throughout their development and operational life cycles. This critical field addresses challenges such as runtime protection, secure coding practices, DevSecOps integration, API security, cloud-native environments, and mitigating attacks like DDoS, supply chain risks, and malicious bot traffic.
Exploring the latest stories in Application Security reveals how advancements like AI and automation are enhancing threat detection, vulnerability management, and developer workflows, while highlighting ongoing risks found in mobile apps, open source components, and cloud deployments. Readers can gain insights into best practices, emerging technologies, and strategies to safeguard applications against evolving cyber threats.
Whether you’re a developer, security professional, or business leader, staying informed about Application Security developments helps in building resilient software, maintaining compliance, and protecting user data in an increasingly complex digital landscape.
Canadian Application Security News
Regional stories with direct local relevance
ServiceNow unveils six autonomous security products
Rising AI-driven threats are pushing firms to consolidate security operations, as ServiceNow adds automation across exposure, identity and incident response.
Alberta uses Claude to scan 466 million lines of code
The province found hidden security flaws in public sector systems in hours, a task officials say could have taken a manual review 6.5 years.
eSentire launches Atlas Preempt for continuous testing
Continuous attack testing aims to help customers spot exploitable gaps before criminals do, including misconfigurations hiding outside core systems.
World Backup Day 2026: In the age of AI, what are you really backing up?
AI disruptions and cyberattacks are forcing organisations to back up models, prompts and knowledge bases, not just files.
Check Point launches Canada-only data region for WAF
Check Point debuts Canada-only WAF data region, promising full data residency, lower latency and AI-driven protection for local organisations.
Bell Cyber & Radware launch AI-driven cloud security
Bell Cyber and Radware have unveiled an AI-driven, fully managed cloud security service to shield apps, APIs and sites from automated attacks.
Analyst Insights
Research and market analysis connected to Application Security
RevEng.AI launches binary analysis models for code
Survey finds AI access controls lag behind confidence
Broadcom launches TrueSource for secure open source
Netscout adds CDN-bypassing DDoS protection features
Gartner sees securing AI market hit USD $4.8bn in 2027
Expert Columns
AI closes vulnerability window as zero-day exploits surge
When AI memory, simulation and provenance collide
Supercharged security: Cyber risk in the age of frontier AI
A strategic blueprint for governing AI-enabled software development
Why ERP is not just another platform you can rebuild with AI code
As agentic development accelerates, workflow auditability becomes a bottleneck
World Backup Day 2026: In the age of AI, what are you really backing up?
The evolving role of the CSO: From technical guardian to business strategist
Secure by default: Moving beyond secure by design
Why the next endpoint and SASE disruption will not come from a security vendor
Interviews
Interviews and video coverage from the networkRecent Application Security News
Delinea joins Anthropic project to test identity security
It could expose faults in software that governs access to sensitive systems, with no customer data included in the AI-led testing.
Mandiant warns of AI agents fuelling new attack risks
Autonomous systems are now creating fresh avenues for code theft, remote execution and runaway cloud spending, Mandiant says.
Tanium tests Anthropic AI for code vulnerabilities
By probing its own production code, Tanium is aiming to catch flaws before attackers can exploit software used by thousands of organisations.
CrowdStrike links PhantomRaven malware to bug bounty hunter
The stealer's use of typosquatted npm packages has raised fears that bug bounty channels are being abused to monetise stolen developer data.
Secure Code Warrior launches Citizen AI training programme
With most firms using AI in daily work but few staff ready for it, the programme targets non-developers handling sensitive data and automations.
Rubrik launches Code Guardian & expands Anthropic ties
The private previews aim to help security teams spot exploitable code chains and connect AI agents to Rubrik's governance tools more safely.
AWS adds OpenAI's GPT-6 Astra to Bedrock for business
Businesses can now run OpenAI's latest frontier model on AWS without managing infrastructure, as Bedrock gains access to GPT-6 Astra.
F5 launches AI security to monitor worker tool use
As staff hand more tasks to AI agents, firms need audit trails and policy controls to stop unauthorised access and risky data moves.
Google warns cyber attackers are moving to agentic AI
Attackers are compressing intrusions into hours, leaving defenders less time to spot and stop credential-harvesting campaigns.
Checkmarx joins Anthropic's Project Glasswing on defence
The collaboration could help security teams spot flaws before attackers exploit them, as exploitations increasingly happen on or before disclosure.
HP patches three high-severity flaws in Easy Start
Mac users face a higher risk of tampered printer installs after HP fixed three bugs in Easy Start, including a root-level file flaw.
A-LIGN buys Pathfynder in cyber services expansion
The deal gives A-LIGN customers direct access to penetration testing and red teaming as firms seek fewer vendors for cyber compliance and defence.
Reco launches Browser Guard to curb shadow AI risks
Security teams can now block employees' unsanctioned AI use in browsers before prompts or agent actions expose sensitive data.
F5 integrates AI Guardrails into MuleSoft Agent Fabric
Businesses using AI agents can now inspect prompts and responses inline, as F5's guardrails plug into MuleSoft's Agent Fabric.
Cycode launches agentic code scanning & attack chaining
Security teams could see fewer false positives and faster fixes as Cycode's new system blends rule-based checks with AI to trace attack paths.
JFrog launches AI-era security tools for software supply
As AI coding agents speed up development, JFrog is adding controls meant to keep governance, compliance and patching from lagging.
Reco launches Browser Guard for enterprise AI security
Security teams now have to police shadow AI in browsers, where Reco says Browser Guard can block prompts, data leaks and rogue actions.
AI-generated cyber attacks to hit firms soon, warn experts
Many firms lack the capacity to fix existing flaws fast enough, leaving them exposed as AI-generated attacks scale up, experts warn.
Kobalt.io signs security partnerships across North America
Enterprise buyers and defence contractors will get a clearer route to certification as Kobalt.io broadens its North American security network.
Cloudflare launches Adaptive Intelligence for bot attacks
Businesses facing a surge in automated abuse could see faster bot blocking as Cloudflare says its system learns from live traffic and updates continuously.