Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

CISO Risk Intel Brief: Tokens, Policy, and the Edge Under Siege

The week’s material risk is not a single CVE. It is the identity and policy control plane. In seven days, CISA confirmed active exploitation against Cisco Identity Services Engine, Check Point VPN and management servers, F5 BIG-IP Access Policy Manager when used as an OAuth authorization server, and Arista’s on-prem VeloCloud Orchestrator. These products issue tokens, enforce network policy, or orchestrate SD-WAN.

Aligning Application Security Software with Business Growth Objectives

AppSec teams know application risk is growing, but budget conversations are often won and lost outside the security team, in rooms full of executives who speak the language of revenue and delivery velocity, not CVSS scores. The core argument: application security software is easier to fund when it is tied to growth, resilience, compliance, and delivery outcomes… not just technical findings.

The 3 Layers of a Mature Software Supply Chain Security Program

There are lots of terms used to generalize what a mature application security program looks like. Find & Fix. Continuous Remediation. Code to Cloud, Unified Risk. The underlying message in these buzzwords is the same: security needs to be systemic. Defense in Depth is preached as a security best practice by leading cybersecurity agencies like NIST and CISA, and these principles are especially relevant to the metastasizing software supply chain risk seen across enterprises.

The EU Cyber Resilience Act Has Global Implications - Who Needs to Prepare and How?

The European Union has made great strides to enhance cybersecurity over the past few years, with a comprehensive framework of core legislative acts designed to protect critical infrastructure. The EU Cyber Resilience Act, originally published as Regulation (EU) 2024/2847 on 20 November 2024, and entered into force on 10 December 2024, shifts the burden of proof so that manufacturers must now show their software is secure, not just claim it.

Scaling DevSecOps: The Role of a Comprehensive Application Security Platform

Exploitation of software vulnerabilities is now the number one cause of breaches, according to the 2026 Verizon DBIR Report. At the same time, release velocity keeps climbing and AI coding tools are now authoring roughly half of all committed code in organizations that use them. For application security and engineering teams, the math is unforgiving: more code, faster delivery, and a growing attack surface.

CISO Risk Intel Brief: Exploited Control Planes, Not Patch Volume, Define Residual Risk

This executive intelligence briefing covers from the past week (2–9 September 2026) and the past month (approximately 10 August – 9 September 2026). CISOs, start here: do not open a 974-row spreadsheet. That queue is the failure mode. This week’s material risk sits in four places you can name before noon.

Evaluating Risk Remediation Software for Enterprise Scalability

Enterprise software delivery is accelerating with more applications, more teams, more pipelines, more third-party code shipping faster than ever. And you can add the compounding risks of AI onto all of that. At the same time, compliance pressure is rising across development, security, and audit teams.

Securing Public Sector Software in 2026: Security Debt Demands Action

Public sector software, from defense platforms to K-12 student information systems, is accumulating a dangerous backlog of unresolved vulnerabilities. That’s the headline finding from Veracode’s 2026 State of Software Security report, and the data behind it is unambiguous: the pace of vulnerability discovery has structurally outrun the capacity to fix them.

CISO Risk Intel Brief: Edge Zero-Days, Artifact-Repository Takeover, and Identity-Pivoted Extortion

This CISO application risk intelligence briefing covers two distinct horizons: the past seven days (Wednesday, 26 August 2026 through Wednesday, 2 September 2026) and the preceding thirty days (Sunday, 3 August 2026 through Wednesday, 2 September 2026). It is written for board risk committees and operating CISOs.

GPT-5.6 Sol Shows Why a Better Model Isn't a Uniformly Safer Model

Veracode Research’s latest secure-coding test finds GPT-5.6 Sol with a 15-point Python gain beneath modest aggregate movement, evidence that cyber capability and secure-code generation do not move in lockstep. OpenAI calls GPT-5.6 Sol its “strongest cybersecurity model yet.” Veracode’s extension test finds it scoring only two percentage points higher overall on secure-code generation than GPT-5.5, but it scores 15 points higher in Python.