Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Securing autonomous AI agents: regulatory risk and governance for modern AppSec

Autonomous AI agents writing and executing code at machine speed present an urgent compliance challenge for modern software organizations. As global regulations tighten, engineering leaders must establish clear governance layers over agentic workflows, external tool calls, and Model Context Protocol integrations to ensure full accountability. In this session, Mend.io experts Asaf Saar and Ben Goldberg unpack the intersection of AI compliance, software supply chain security, and enterprise risk management. Learn how to bridge the accountability gap without sacrificing development velocity.

Why Traditional SAST Fails on AI-Generated Code

AI didn't just speed up software development, it changed what application security programs must defend. As AI coding assistants generate code at machine speed and developers integrate AI agents, models, and RAG pipelines into production, traditional scanners generate endless backlogs of unprioritized alerts.

AppSec: When Bandwidth Isn't the Bottleneck

AppSec teams are frequently told that a lack of bandwidth is why vulnerability backlogs keep growing. In reality, the bottleneck is not team size, it is the lack of contextual prioritization and agentic triage. When traditional scanners hand security teams thousands of findings without reachability context, developer velocity stalls. In this webinar, Mend.io security experts unpack why bandwidth is not the real bottleneck in modern software security and show you how to streamline triage, automate remediation, and secure code at AI speed.

Why Project Glasswing Changes the Rules of AppSec

The old application security playbook is broken. With Anthropic’s Claude Mythos and the release of Project Glasswing, AI agents can now autonomously chain low-severity bugs into working zero-day exploits, collapsing the time between vulnerability discovery and active exploitation. In this video, Mend.io's Saoirse Hinksmon (Head of Product Marketing) and Daniel Wyrzykowski (Product Manager) break down the structural shifts in the threat landscape and what security teams must do to keep pace.

Hacking LLMs using LinkedIn #aisecurity #ai #llm

Mend.io, formerly known as Whitesource, has over a decade of experience helping global organizations build world-class AppSec programs that reduce risk and accelerate development -– using tools built into the technologies that software and security teams already love. Our automated technology protects organizations from supply chain and malicious package attacks, vulnerabilities in open source and custom code, and open-source license risks.

AI Sales Avatar Hijacked by Prompt Injection on Livestream #promptinjection #hacked #hacker

Mend.io, formerly known as Whitesource, has over a decade of experience helping global organizations build world-class AppSec programs that reduce risk and accelerate development -– using tools built into the technologies that software and security teams already love. Our automated technology protects organizations from supply chain and malicious package attacks, vulnerabilities in open source and custom code, and open-source license risks.

Treat AI Like an Employee #ai #aisecurity

Mend.io, formerly known as Whitesource, has over a decade of experience helping global organizations build world-class AppSec programs that reduce risk and accelerate development -– using tools built into the technologies that software and security teams already love. Our automated technology protects organizations from supply chain and malicious package attacks, vulnerabilities in open source and custom code, and open-source license risks.

AI Without Guardrails Is Like an Employee Without Training #ai #aisecurity #github

Mend.io, formerly known as Whitesource, has over a decade of experience helping global organizations build world-class AppSec programs that reduce risk and accelerate development -– using tools built into the technologies that software and security teams already love. Our automated technology protects organizations from supply chain and malicious package attacks, vulnerabilities in open source and custom code, and open-source license risks.

How to Map AI Risk to Existing Compliance Frameworks

Mend.io, formerly known as Whitesource, has over a decade of experience helping global organizations build world-class AppSec programs that reduce risk and accelerate development -– using tools built into the technologies that software and security teams already love. Our automated technology protects organizations from supply chain and malicious package attacks, vulnerabilities in open source and custom code, and open-source license risks.