The Ultimate Guide to Application Security
A curated Canadian edition of TechDay news, analysis, interviews, reviews, job moves, and related resources for Application Security.
What to know about Application Security
Application Security focuses on protecting software applications from vulnerabilities and cyber threats throughout their development and operational life cycles. This critical field addresses challenges such as runtime protection, secure coding practices, DevSecOps integration, API security, cloud-native environments, and mitigating attacks like DDoS, supply chain risks, and malicious bot traffic.
Exploring the latest stories in Application Security reveals how advancements like AI and automation are enhancing threat detection, vulnerability management, and developer workflows, while highlighting ongoing risks found in mobile apps, open source components, and cloud deployments. Readers can gain insights into best practices, emerging technologies, and strategies to safeguard applications against evolving cyber threats.
Whether you’re a developer, security professional, or business leader, staying informed about Application Security developments helps in building resilient software, maintaining compliance, and protecting user data in an increasingly complex digital landscape.
Canadian Application Security News
Regional stories with direct local relevance
Alberta uses Claude to scan 466 million lines of code
The province found hidden security flaws in public sector systems in hours, a task officials say could have taken a manual review 6.5 years.
eSentire launches Atlas Preempt for continuous testing
Continuous attack testing aims to help customers spot exploitable gaps before criminals do, including misconfigurations hiding outside core systems.
World Backup Day 2026: In the age of AI, what are you really backing up?
AI disruptions and cyberattacks are forcing organisations to back up models, prompts and knowledge bases, not just files.
Check Point launches Canada-only data region for WAF
Check Point debuts Canada-only WAF data region, promising full data residency, lower latency and AI-driven protection for local organisations.
Bell Cyber & Radware launch AI-driven cloud security
Bell Cyber and Radware have unveiled an AI-driven, fully managed cloud security service to shield apps, APIs and sites from automated attacks.
Analyst Insights
Research and market analysis connected to Application Security
Cloudbrink launches AI security platform for enterprise
Citrix adds MCP Gateway to NetScaler for AI traffic
Data Theorem launches AI security platform for apps
Gartner names Tenable leader in AI exposure assessment
Secure Code Warrior launches AI adoption model for CISOs
Featured News
Humanoid robots, 0-day defence among Info-Tech trends for '27
Agentic AI, zero-day surge, sovereign cloud, and humanoid robots will define IT strategy in 2027, Info-Tech Research Group warns.
Exabeam: Ruthless efficiency can make agentic AI malicious
Behavioural analytics is becoming essential as AI agents can pursue tasks so efficiently that they may cause damage without any malicious intent.
Check Point Technologies: On vigilance, Mythos and beyond
AI-driven vulnerability scanning is forcing firms to rethink complacency as Check Point says existing defences still help against Mythos.
Exclusive: Reco COO on securing the AI inside your SaaS stack
Reco COO Zoe Hillenmeyer says enterprises typically underestimate their AI agent exposure by a factor of ten and that gap is widening.
Google Cloud CEO sets out enterprise AI agent plan
Enterprises will get one place to build, govern and run AI agents, as Google Cloud expands Gemini Enterprise across models, data and security.
Expert Columns
A strategic blueprint for governing AI-enabled software development
Why ERP is not just another platform you can rebuild with AI code
As agentic development accelerates, workflow auditability becomes a bottleneck
World Backup Day 2026: In the age of AI, what are you really backing up?
The evolving role of the CSO: From technical guardian to business strategist
Secure by default: Moving beyond secure by design
Why the next endpoint and SASE disruption will not come from a security vendor
The security challenges in AI-assisted software development
AI surge exposes cloud security gaps, report warns
Agentic AI double agents expose dangerous security gaps
Interviews
Interviews and video coverage from the networkRecent Application Security News
SafeLogic launches platform for post-quantum migration
Businesses face a growing compliance burden as regulators push post-quantum upgrades, and SafeLogic is aiming to ease the search for hidden cryptography.
Ossprey raises USD $2.65 million for supply chain security
The round will fund hiring, product work and overseas growth as investors back tools to counter AI-driven software supply chain risks.
Azul to launch monthly Java security patch updates
Organisations running Java in production will get faster fixes for serious flaws as Azul moves to monthly security-only updates from August 2026.
Google makes CodeMender available in its Gemini security models
Developers may get patched code faster as Google's preview agent scans repositories, tests exploits and drafts fixes for review.
Cisco launches Antares AI models for code flaw pinpointing
Security teams could cut hours from patching work as open-weight Antares models narrow flaws to the relevant code segment.
CrowdStrike warns of malware targeting AI coding tools
Developers using AI assistants could face stolen credentials and poisoned repositories as the worm hides inside normal coding workflows.
Qualys joins Chainguard's Athena security coalition
The coalition has now processed more than 40,000 findings, underscoring how quickly open source flaws can spread across corporate systems.
Lineaje launches AI vulnerability elimination factory
The tool aims to help developers cut vulnerability backlogs and reach no exploitable flaws within 90 days as AI coding expands risk.
F5 adds fleet management tools for BIG-IP environments
Security teams under pressure to patch faster can now track and stage BIG-IP updates across fleets without losing audit control.
FIS joins Anthropic cyber security project with Mythos 5
For thousands of banks and payments firms, the trial could help spot software flaws before they disrupt critical financial systems.
Google Cloud unveils AI security blueprint for GKE
The framework targets CISOs and platform teams as they move AI systems into production, amid rising risks from prompts, models and outputs.
Google Cloud issues guardrails for AI vulnerability agents
Security teams are being warned to keep humans and strict controls in place as AI agents can miss context and leak sensitive code.
Google Cloud sets out AI security plan with Gemini & Wiz
Defenders could gain a faster edge against AI-driven attacks as Google Cloud ties Gemini, Wiz, CodeMender and Mandiant into one platform.
GitLab 19.2 adds AI tools for security & workflows
The update aims to cut review bottlenecks by auto-fixing vulnerable dependencies and surfacing code flaws scanners often miss.
SecurityBridge launches SAPMAP to map attack paths
Security teams can now trace how one SAP flaw could spread across finance, payroll and supply chains, with access tightly restricted.
CleanStart launches Clean Libraries to secure AI code
Developers face earlier checks on risky open-source dependencies as AI coding tools speed up software assembly and raise supply chain concerns.
Targeted open source malware attacks on developers soar
Malicious package advisories jumped from 21 in 2023 to 1,576 in 2025, as attackers increasingly target developers before code reaches production.
AI coding models make working code, not secure code
Working output from the latest AI coding tools was secure barely a third of the time, exposing a widening risk for software teams.
Akamai joins WWT AI security model for NVIDIA systems
The tie-up gives enterprises a layered way to secure AI systems without sacrificing performance, as demand for larger workloads grows.
Mandiant warns on exposed Cloud Run serverless apps
Exposed serverless apps can let attackers steal tokens, read secrets and take over cloud projects if weak code is left unpatched.