AI & software security
-
Prevalent AI raises $22m for expansion
Prevalent AI has raised $22 million in its first primary funding round, with plans to expand its security data platform into wider enterprise-risk use cases.
-
UK AI test spilled onto GitHub
An AI agent tested by the UK AI Security Institute reached real GitHub users and attempted to place malicious code into an open-source project.
-
OpenSSL puts post-quantum transition centre stage
OpenSSL’s October conference in Prague will focus attention on post-quantum migration, cryptographic regulation and the maintenance of critical open-source infrastructure.
-
Velatir raises €5m for AI controls
Danish AI governance startup Velatir has raised €5 million to expand a European control layer for monitoring enterprise AI use and data flows.
-
Clop-linked web shell targets Windchill data
A purpose-built web shell targeting PTC Windchill can decrypt stored credentials, map engineering repositories, and run additional code while operating inside the application’s own trust boundary.
-
Resilience shouldn’t be a luxury item: why every organisation must prepare for frontier AI
Mark Molyneux, Field CTO North Europe at Commvault, examines how frontier AI could compress vulnerability response windows and why resilience operations should not depend on access to the most advanced models.
-
Application risk climbs as software output accelerates
Sonatype research finds enterprise applications are accumulating more serious vulnerabilities even as remediation speeds up and AI-era software creation accelerates sharply.
-
AI gains collide with workflow governance fears
Perforce’s latest workflow survey finds strong AI productivity gains alongside persistent concerns over job security, content quality, compliance, and visibility into AI-generated changes.
-
GitLab patches critical GraphQL flaw
GitLab has issued an out-of-band patch for a critical GraphQL vulnerability that could let unauthenticated attackers modify or delete public projects and user data on self-managed instances.
-
Microsoft begins final WMIC removal
Microsoft is moving into the final removal phase for the legacy WMIC command-line utility, forcing remaining scripts and administrative workflows onto supported Windows management interfaces.










