Why the future of application security isn’t AI or SAST—it’s both

AI code scanning and SAST aren't competing tools—they're complementary ones. Discover why the strongest application security programs use a hybrid model that pairs SAST as the foundation with AI where semantic reasoning ...

Why LLM API keys should be treated like tier‑zero secrets

LLM API keys for OpenAI, Anthropic, Perplexity, and Gemini are now business-critical secrets. Learn how hardcoded AI credentials leak, the risks they create, and how to detect them before attackers do.The post ...

What Anthropic’s Project Glasswing means for software builders

Anthropic released Glasswing and Mythos AI models that can find software vulnerabilities. Here's what it means for application security teams.The post What Anthropic’s Project Glasswing means for software builders appeared first on ...
The third wave of application security: How AI is reshaping AppSec at scale

The third wave of application security: How AI is reshaping AppSec at scale

Black Duck CEO Jason Schmitt on how AI transforms AppSec: 10-20x more code, autonomous security workflows, and why AI enhances rather than disrupts AppSec.The post The third wave of application security: How ...

Black Duck Signal: Security that moves at the speed of AI

Signal operates differently than traditional AST tools or single-model AI solutions. Where other solutions stop at identifying potential issues, Signal reasons about them with the depth and nuance of experienced security professionals ...

AI is rewriting the rules of application security—and most organizations aren’t ready

AI is rewriting application security rules. BSIMM16 reveals how leading organizations are adapting their AppSec programs for AI-generated code, automation, and new threats.The post AI is rewriting the rules of application security—and ...

Accenture offers True Scale Application Security to clients worldwide

Accenture expands its Black Duck partnership to deliver comprehensive AST solutions with the Polaris platform for flexible, scalable security. The post Accenture offers True Scale Application Security to clients worldwide appeared first ...
Navigating the AI frontier: Risks, benefits, and uncharted territory in code development

Navigating the AI frontier: Risks, benefits, and uncharted territory in code development

85% of organizations use AI coding assistants, but are you managing the security risks and IP concerns? Learn how to balance AI benefits with robust DevSecOps practices. Part 2 of our 2025 ...

Navigating the AI security era: Key trends for software leaders in 2026

Features Black Duck’s Chief Product and Technology Officer Dipto Chakravarty on key topics like AI agents and quantum computing.The post Navigating the AI security era: Key trends for software leaders in 2026 ...

Vibe coding and its implications

Explore the concept of vibe coding, its benefits, risks, and best practices. Learn how to harness AI-assisted development while maintaining software security and integrity. The post Vibe coding and its implications appeared ...