惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
D
Docker
腾讯CDC
J
Java Code Geeks
大猫的无限游戏
大猫的无限游戏
The Cloudflare Blog
Martin Fowler
Martin Fowler
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
博客园 - 三生石上(FineUI控件)
Recent Announcements
Recent Announcements
F
Fortinet All Blogs
IT之家
IT之家
WordPress大学
WordPress大学
M
MIT News - Artificial intelligence
爱范儿
爱范儿
Microsoft Azure Blog
Microsoft Azure Blog
Vercel News
Vercel News
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
小众软件
小众软件
N
Netflix TechBlog - Medium
T
Tailwind CSS Blog
Engineering at Meta
Engineering at Meta
博客园 - 【当耐特】

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY
AI-written software creates hassles for wary security teams
Eric Geller · 2026-04-23 · via Cybersecurity Dive - Latest News

An article from site logo

Dive Brief

A new report explains what cybersecurity practitioners need to see before they trust AI coding tools.

Published April 23, 2026

Image of a green computer screen with COBOL coding on it.

Getty Images

Dive Brief:

  • Companies using AI to write code are creating serious security risks that not all organizations feel prepared to handle, according to a report released Wednesday by the security testing firm ProjectDiscovery. 
  • Security personnel want audit trails and access limitations before they integrate AI into their processes, ProjectDiscovery found. “They are not opposed to the technology, but they need it to earn its place.”
  • The report highlights one of the most fraught aspects of the AI revolution in the corporate world: the tension between AI-assisted coders and the people responsible for protecting their work.

Dive Insight:

“A deluge of AI-generated code is hitting security teams, and the wave is building faster than most organizations can absorb it,” ProjectDiscovery said in its report. “Engineering teams are shipping at an unprecedented speed, and security teams are standing in the path of that rising tide.”

Only 38% of cybersecurity practitioners said they are keeping up well with the increasing volume of code they have to review because of AI, and nearly 60% said the task is getting harder, the report found. Security personnel at mid-sized companies felt this pressure more than their counterparts at large firms, perhaps reflecting the amount of resources larger companies have to devote to the work.

The report is based on a survey of 200 cybersecurity professionals at mid-size to large enterprises in North America and Western Europe. Nearly half of respondents work in security architecture, ProjectDiscovery said, and more than half play a role in “selecting or approving security products.”

Defenders are concerned about several risks stemming from the use of AI to write code, including the exposure of corporate secrets (78% of respondents cited this as a top concern), supply-chain risks from unreliable dependencies (73%) and “business logic vulnerabilities,” application design flaws that could let a hacker abuse legitimate functions (72%).

In its discussion of secrets leakage, ProjectDiscovery cited a 2025 National Cybersecurity Alliance report that found that 43% of employees admitted to entering sensitive company data into AI tools.

European respondents were more likely than their American counterparts to cite secrets leakage as a major concern (87% versus 72%), perhaps reflecting the strict privacy requirements of the European Union’s General Data Protection Regulation (GDPR).