惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
V
Visual Studio Blog
有赞技术团队
有赞技术团队
T
Tailwind CSS Blog
B
Blog
I
InfoQ
博客园 - 三生石上(FineUI控件)
阮一峰的网络日志
阮一峰的网络日志
F
Fortinet All Blogs
H
Help Net Security
博客园 - Franky
宝玉的分享
宝玉的分享
博客园 - 司徒正美
C
Check Point Blog
G
Google Developers Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Jina AI
Jina AI
T
The Blog of Author Tim Ferriss
MongoDB | Blog
MongoDB | Blog
云风的 BLOG
云风的 BLOG
A
About on SuperTechFans
罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
IT之家
IT之家

Help Net Security

Police arrest 10 suspected members of Black Axe cybercrime gang ShinyHunters claims it stole 1.4 million records from Udemy Sevii unveils Cyber Swarm Defense Mode to stop AI-driven attacks at scale Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research Cequence Agent Personas bring granular control and governance to enterprise AI agents NowSecure MARI gives enterprises evidence-based visibility into third-party mobile app risk The metrics killing your SOC, and what to use instead US state privacy fines reached $3.425 billion in 2025 Canada’s first SMS blaster case leads to three arrests Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startup TLS Connect gives SMBs a right-sized automated tool to manage TLS certificates Aptori expands its platform with autonomous offensive testing to reduce security bottlenecks Your IAM was built for humans, AI agents don’t care The AI criminal mastermind is already hiring on gig platforms 25 open-source cybersecurity tools that don’t care about your budget Product showcase: LuLu reveals unauthorized outbound connections from Mac apps Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach Users advised to drop passwords and make room for passkeys - Help Net Security Indirect prompt injection is taking hold in the wild - Help Net Security Compromised everyday devices power Chinese cyber espionage operations - Help Net Security New Cisco firewall malware can only be killed by pulling the plug - Help Net Security Meta is overhauling how you sign in, manage settings, and protect your accounts - Help Net Security Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm servers - Help Net Security OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards - Help Net Security AI is speeding up nation-state cyber programs - Help Net Security A study of 1,000 Android apps finds a privacy policy logging gap - Help Net Security IT spending to hit $6.31 trillion record, thanks to AI - Help Net Security Where AI in CI/CD is working for engineering teams - Help Net Security With AI's help, North Korean hackers stumbled into a near-undetectable attack - Help Net Security Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security
New 42Crunch plugin helps developers find and fix API vul...
Industry News · 2026-06-18 · via Help Net Security

42Crunch has announced the availability of the 42Crunch API Security Testing Plugin for GitHub Copilot. This latest advance enables developers to continuously audit, test, remediate and validate API security vulnerabilities directly within AI-assisted development workflows.

Organizations are struggling to secure their growing API landscape in the face of increasing attacks, with AI’s heavy reliance on APIs compounding this problem. Consequently, one of the key areas of attention for security and engineering teams is the security testing of these APIs.

According to William Dupre, VP Analyst with Gartner, “building on the testing capabilities in the managing stage, organizations that optimize their API testing capabilities will utilize specifications to further automate API testing. Various API testing tools can use specifications to run functional and security-focused tests against APIs. These efforts will be automated in the build pipeline to provide immediate feedback to development teams on security vulnerabilities in APIs.”

“As agentic workflows become the norm, repository creation, pull request activity, and API usage are all accelerating with no evidence of slowing down. On GitHub alone, commits nearly doubled year over year, crossing 1.4 billion per month, plus over 2 billion GitHub Actions minutes a week,” said GitHub CPO Mario Rodriguez.

“To meet this demand and continue to be the home for all developers (and now their agents), our focus is scaling our underlying systems and improving resilience, security and stability across all of our services, at every layer of the stack,” Rodriguez added.

As reported last year by Veracode, almost half (45%) of AI-generated code contains known OWASP Top 10 vulnerabilities and a survey by security consultancy Upguard revealed that 88% of security leaders admit incorporating unauthorized AI into their daily workflows.

For APIs, the challenge is particularly acute. APIs have become the operational backbone of modern applications, AI agents, and enterprise systems. As developers increasingly rely on AI coding assistants to generate API specifications, integrations, and application logic, manual security reviews risk becoming the very bottleneck that slows enterprise AI adoption.

“The future of software development isn’t simply AI generating more code. It’s AI generating more code that organizations can trust,” said Jacques Declas, CEO of 42Crunch.

“GitHub Copilot and other AI coding assistants are dramatically increasing development velocity, but they are also exposing a fundamental challenge: human security review cannot scale linearly with AI-generated output. Organizations need deterministic security guardrails that can validate, govern, and remediate API security issues at the same speed AI generates them. The 42Crunch API security testing GitHub Copilot plugin delivers exactly that capability,” continued Declas.

The 42Crunch API Security Testing Plugin for GitHub Copilot addresses this challenge by embedding deterministic API security guardrails directly into the development workflow.

The plugin continuously:

  • Audits OpenAPI specifications when new APIs are defined
  • Detects API security vulnerabilities and governance violations
  • Identifies OWASP API Security Top 10 risks
  • Provides AI-assisted remediation guidance
  • Validates fixes through automated testing
  • Enforces organizational API security standards and policies

By automating API security validation, organizations can ensure that security scales alongside AI-assisted development rather than becoming a downstream review process.