The Ultimate Guide to Application Security
A curated Kiwi edition of TechDay news, analysis, interviews, reviews, job moves, and related resources for Application Security.
What to know about Application Security
Application Security focuses on protecting software applications from vulnerabilities and cyber threats throughout their development and operational life cycles. This critical field addresses challenges such as runtime protection, secure coding practices, DevSecOps integration, API security, cloud-native environments, and mitigating attacks like DDoS, supply chain risks, and malicious bot traffic.
Exploring the latest stories in Application Security reveals how advancements like AI and automation are enhancing threat detection, vulnerability management, and developer workflows, while highlighting ongoing risks found in mobile apps, open source components, and cloud deployments. Readers can gain insights into best practices, emerging technologies, and strategies to safeguard applications against evolving cyber threats.
Whether you’re a developer, security professional, or business leader, staying informed about Application Security developments helps in building resilient software, maintaining compliance, and protecting user data in an increasingly complex digital landscape.
Kiwi Application Security News
Regional stories with direct local relevance
Wellington startup launches Metaport for agency risk
Wellington startup Dcentrica has unveiled Metaport, a platform giving digital agencies real-time visibility of security and maintenance risk.
Capture The Bug adds US tech leaders for North American push
Hamilton-born Capture The Bug taps top US tech leaders to drive North American growth as demand rises for continuous security testing.
'Be very, very suspicious': Neighbourly breach makes users vulnerable - expert
Neighbourly breach puts up to a million users at risk as stolen GPS data and messages hit dark web, experts urge extreme vigilance online.
Rapid7 partners with Duo for strategic distribution in New Zealand
New Zealand's cybersecurity expenditure could boost as Rapid7 appoints Duo, a branch of Sektor, for strategic distribution.
Top cybersecurity achievements celebrated at 2023 iSANZ Awards
New Zealand's cybersecurity heroes, including KPMG's Philip Whitmore and BNZ teams, were honoured at the 2023 iSANZ Awards for advancing digital resilience nationwide.
Radware and Spark NZ enter cybersecurity partnership
Radware and Spark NZ have signed a partnership agreement to offer application and network security services in New Zealand.
Analyst Insights
Research and market analysis connected to Application Security
Cequence posts record quarter on agentic AI security
Averlon launches Precog to block exploitable risks
Salt Code enforces security policies in AI coding tools
Software Improvement Group named Gartner leader on debt
Cycode launches agentic development lifecycle security
Featured News
Exabeam: Ruthless efficiency can make agentic AI malicious
Behavioural analytics is becoming essential as AI agents can pursue tasks so efficiently that they may cause damage without any malicious intent.
Check Point Technologies: On vigilance, Mythos and beyond
AI-driven vulnerability scanning is forcing firms to rethink complacency as Check Point says existing defences still help against Mythos.
Exclusive: Reco COO on securing the AI inside your SaaS stack
Reco COO Zoe Hillenmeyer says enterprises typically underestimate their AI agent exposure by a factor of ten and that gap is widening.
Certes says be ready to protect data before Q Day hits
Only 3% of Australian businesses have started preparing for post-quantum cryptography, leaving sensitive data exposed to harvest-now, decrypt-later attacks.
Upwind Expands to Sydney: Real Time Cloud Security for APJ
The Sydney move follows a USD $250 million funding round as the cloud security firm bets on real-time protection for fast-growing AI workloads.
AI agents multiply risk, says DigiCert chief product officer
Many firms cannot see where their AI agents are, leaving identity, policy and supply-chain risks to grow as deployments scale.
Google Cloud CEO sets out enterprise AI agent plan
Enterprises will get one place to build, govern and run AI agents, as Google Cloud expands Gemini Enterprise across models, data and security.
'Human Risk' takes centre stage - Mimecast CEO
Mimecast chief warns human risk is now cybersecurity's 'eighth layer' as malicious insiders overtake negligence in Australian attacks.
UiPath Accelerates AI in Software Development and Testing
UiPath is pushing AI deeper into software testing, promising autonomous agents that transform quality assurance and developers' roles.
Expert Columns
Why ERP is not just another platform you can rebuild with AI code
As agentic development accelerates, workflow auditability becomes a bottleneck
Why organisations in Asia Pacific are rethinking their AI deployment strategies
The evolving role of the CSO: From technical guardian to business strategist
From 398 to 200 Days: Understanding the TLS Certificate Lifespan Reduction
Secure by default: Moving beyond secure by design
Why the next endpoint and SASE disruption will not come from a security vendor
The security challenges in AI-assisted software development
Hybrid mesh security emerges to counter AI cyber risks
How AI-powered log management unlocks observability
Interviews
Interviews and video coverage from the networkRecent Application Security News
Snyk expands reach across NZ market with new structure and leadership roles
Snyk is expanding its reach across the NZ market, aiming to further cement its place in the developer-focused security space.
Auldhouse significantly expands cybersecurity training offerings
Auldhouse set to become one of New Zealand's leading cybersecurity training providers, gaining official rights to the world's top cybersecurity certifications.
NZ financial firms bolster secure software development with Checkmarx
Two major financial institutions in New Zealand have refreshed their application security measures with the help of security specialist Checkmarx.
Chillisoft to distribute Imperva security solutions
Chillisoft adds Imperva to its cybersecurity portfolio, offering enterprise data security, web application, BOT protection, and CDN solutions.
The three-pronged security approach to multi-cloud environments
As enterprises adopt multi-cloud strategies, vArmour simplifies security with a three-pronged approach: auto-discovery, policy computation, and enforcement.
Spur adds no-code Cloudflare integration for Monocle
Security teams can now block or review suspicious anonymised traffic in minutes, with no engineering work, through Spur's new Cloudflare link.
Pathlock & NTT DATA launch global SAP cyber service
Enterprises running SAP may gain around-the-clock protection as the partners target ransomware, fraud and staffing gaps in ERP security.
GitGuardian launches endpoint protection for laptops
A single compromised laptop can expose thousands of live keys, according to GitGuardian's early field tests, as attacks shift to developer machines.
Checkmarx launches hybrid AI engine for code scanning
False alerts and missed flaws are the target as the new engine aims to help security teams scan AI-written code more reliably.
Vercel unveils agent tools as deployments turn AI-led
More than half of Vercel deployments are now triggered by coding agents, as monthly AI token traffic has jumped tenfold.
Arkose Labs launches agent trust manager for Titan
The new system aims to curb fraud as AI-driven traffic surges and online security teams struggle to tell legitimate agents from attackers.
Mini Shai-Hulud worm turns public, NCC Group warns
Public release of the Mini Shai-Hulud code means copycat attacks can now hit developers, CI/CD systems and open-source supply chains.
Reco launches Claude security integration for enterprises
Security teams can now trace AI activity across employee and developer environments as Reco links Claude usage to permissions, keys and data paths.
CrowdStrike expands QuiltWorks with AWS on AI security
AWS customers will gain broader visibility into AI and cloud risks as CrowdStrike adds new monitoring, trials and private connectivity.
Gigamon & Zscaler unveil Zero Trust access integration
The move gives joint customers more post-access visibility into encrypted traffic as firms phase out legacy VPNs and hunt lateral movement risks.
Azul launches free JVM risk assessment amid AI threat
The free check could help security teams uncover overlooked Java runtimes before AI-driven attackers exploit known flaws and outdated versions.
Cloud202 launches Qubitz AI for cheaper business apps
Enterprises could cut AI app development costs by up to 80% as Cloud202 targets the gap between prototypes and secure production systems.
Keeper launches secrets sync for multi-cloud credentials
The feature aims to prevent credential drift, a common multi-cloud risk that can leave AWS, Azure and Google Cloud secrets out of sync.
AI coding tools may raise enterprise software risk
Weaker oversight could turn AI-generated code into a costly drag, with security flaws and technical debt rising in enterprise projects.
AI coding tools raise debt & security risks, SIG warns
Enterprise teams using AI coding tools may face higher technical debt, security gaps and costs, according to new SIG research.