惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 聂微东
Y
Y Combinator Blog
WordPress大学
WordPress大学
L
LangChain Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
A
About on SuperTechFans
小众软件
小众软件
有赞技术团队
有赞技术团队
S
SegmentFault 最新的问题
宝玉的分享
宝玉的分享
Recent Announcements
Recent Announcements
GbyAI
GbyAI
I
InfoQ
The GitHub Blog
The GitHub Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
酷 壳 – CoolShell
酷 壳 – CoolShell
罗磊的独立博客
C
Check Point Blog
V
V2EX
Apple Machine Learning Research
Apple Machine Learning Research
月光博客
月光博客
量子位
雷峰网
雷峰网
Hugging Face - Blog
Hugging Face - Blog

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security
New 42Crunch plugin helps developers find and fix API vul...
Industry News · 2026-06-18 · via Help Net Security

42Crunch has announced the availability of the 42Crunch API Security Testing Plugin for GitHub Copilot. This latest advance enables developers to continuously audit, test, remediate and validate API security vulnerabilities directly within AI-assisted development workflows.

Organizations are struggling to secure their growing API landscape in the face of increasing attacks, with AI’s heavy reliance on APIs compounding this problem. Consequently, one of the key areas of attention for security and engineering teams is the security testing of these APIs.

According to William Dupre, VP Analyst with Gartner, “building on the testing capabilities in the managing stage, organizations that optimize their API testing capabilities will utilize specifications to further automate API testing. Various API testing tools can use specifications to run functional and security-focused tests against APIs. These efforts will be automated in the build pipeline to provide immediate feedback to development teams on security vulnerabilities in APIs.”

“As agentic workflows become the norm, repository creation, pull request activity, and API usage are all accelerating with no evidence of slowing down. On GitHub alone, commits nearly doubled year over year, crossing 1.4 billion per month, plus over 2 billion GitHub Actions minutes a week,” said GitHub CPO Mario Rodriguez.

“To meet this demand and continue to be the home for all developers (and now their agents), our focus is scaling our underlying systems and improving resilience, security and stability across all of our services, at every layer of the stack,” Rodriguez added.

As reported last year by Veracode, almost half (45%) of AI-generated code contains known OWASP Top 10 vulnerabilities and a survey by security consultancy Upguard revealed that 88% of security leaders admit incorporating unauthorized AI into their daily workflows.

For APIs, the challenge is particularly acute. APIs have become the operational backbone of modern applications, AI agents, and enterprise systems. As developers increasingly rely on AI coding assistants to generate API specifications, integrations, and application logic, manual security reviews risk becoming the very bottleneck that slows enterprise AI adoption.

“The future of software development isn’t simply AI generating more code. It’s AI generating more code that organizations can trust,” said Jacques Declas, CEO of 42Crunch.

“GitHub Copilot and other AI coding assistants are dramatically increasing development velocity, but they are also exposing a fundamental challenge: human security review cannot scale linearly with AI-generated output. Organizations need deterministic security guardrails that can validate, govern, and remediate API security issues at the same speed AI generates them. The 42Crunch API security testing GitHub Copilot plugin delivers exactly that capability,” continued Declas.

The 42Crunch API Security Testing Plugin for GitHub Copilot addresses this challenge by embedding deterministic API security guardrails directly into the development workflow.

The plugin continuously:

  • Audits OpenAPI specifications when new APIs are defined
  • Detects API security vulnerabilities and governance violations
  • Identifies OWASP API Security Top 10 risks
  • Provides AI-assisted remediation guidance
  • Validates fixes through automated testing
  • Enforces organizational API security standards and policies

By automating API security validation, organizations can ensure that security scales alongside AI-assisted development rather than becoming a downstream review process.