April 2025 Summaries
7 posts from Snyk
Filter
Month:
Year:
Post Summaries
Back to Blog
Black Hat Asia 2025 was a transformative conference that not only provided deep technical insights but also inspiring conversations, serendipitous reunions with admired individuals, and a renewed sense of purpose in cybersecurity. The conference featured a variety of sessions, including "Cloud Security: Building Connections in the Cloud," which brought together professionals to discuss challenges and innovative solutions, as well as "Hacking the Status Quo: Tales from Leading Women in Cybersecurity," a panel that celebrated women leaders in the field and shared their personal stories. Additionally, the conference included coaching opportunities for young speakers and sessions on AI's role in cybersecurity. The event concluded with a Locknote session summarizing key takeaways and reflecting on the critical issues facing the security world today. Throughout the week, attendees had the chance to reconnect with mentors, meet new friends, and find allies from around the world, making Black Hat Asia 2025 a truly unforgettable experience.
Apr 28, 2025
938 words in the original blog post.
Snyk has launched its next-generation dynamic application security testing (DAST) solution, Snyk API & Web, which is designed to secure complex, AI-powered applications. The solution integrates DAST with SAST, SCA, and other tools to provide a holistic risk view, developer-first security context, and synergistic detection capabilities. With the launch, Snyk aims to redefine DAST for the AI era, addressing the increasing demand for secure, AI-powered solutions. The company has seen overwhelming interest in its DAST capabilities, with 245% quarter-over-quarter ARR growth, and is investing heavily to enhance its AI-driven testing, expand API coverage, and provide richer context for faster remediation.
Apr 22, 2025
880 words in the original blog post.
The cybersecurity community has been watching closely as the future of the MITRE-run CVE (Common Vulnerabilities and Exposures) program, which could abruptly end due to federal funding uncertainty. However, a last-minute extension has been granted, providing temporary relief. The CVE system has become crucial to modern cybersecurity, highlighting the need for resilience and redundancy across the vulnerability disclosure ecosystem. Snyk, a company that maintains its own triaged vulnerability database, is committed to supporting a transparent and open vulnerability disclosure process and remains ready to collaborate with industry peers to ensure continued support if federal funding were to be discontinued. The situation serves as a reminder of the importance of proactive monitoring, investment in open security data, and delivering comprehensive vulnerability intelligence to developers and security teams.
Apr 16, 2025
362 words in the original blog post.
Snyk, a developer security platform, has partnered with Nova8, a leading value-added distributor of cybersecurity solutions in Latin America, to empower developers and security teams across the region to build secure applications faster. The partnership aims to address the growing need for developer security in Latin America, where organizations are increasingly adopting DevOps practices, cloud-native architectures, and open-source technologies. Snyk's platform integrates security seamlessly into the development workflow, enabling early detection and remediation of vulnerabilities, which can lead to increased vulnerabilities, development delays, and higher remediation costs if left unchecked. The partnership will provide benefits such as empowered developers, accelerated and secure development, reduced risk, and streamlined compliance and reporting. With Nova8's deep expertise in the Latin American market and extensive network of channel partners, Snyk is expanding its reach to more organizations across the region, giving security teams the visibility, control, and confidence they need to scale application security without slowing development.
Apr 15, 2025
735 words in the original blog post.
Snyk has integrated its security solution into Google Cloud's Gemini Code Assist tools, empowering developers to access Snyk's powerful functionalities with natural language prompts and enabling teams to securely adopt and leverage AI at scale. This integration bridges the gap between innovation and security, solving challenges modern AppSec teams face, and enables developers to use AI coding tools without sacrificing speed, productivity, or security. The collaboration allows developers to interact with Gemini Code Assist as they normally would while having the reassurance that their code is being secured by an analyst-approved AI security assistant trusted by 1 in 3 Fortune 50 companies. Existing Snyk customers will have the added benefit of accessing their security policy configurations and other configurations from their Snyk platform, meaning that they can continue to leverage customized features like ignoring issues at scale. The integration enables long-term, consistent adoption, providing developers with a leading, analyst-approved SAST and pioneering AI security agent — DeepCode AI Fix — that automatically scans code to find and fix security issues and vulnerabilities as early as possible.
Apr 09, 2025
1,426 words in the original blog post.
Greybeard is a new CLI tool that wraps Snyk's security scanning capabilities in the personality of a grumpy, seasoned security engineer. It provides no-nonsense feedback, contextual wisdom, and motivational insults to motivate developers to fix vulnerabilities. Greybeard uses AI to enhance the original Snyk output with its greybeard personality, making security feedback more engaging and memorable. The tool is built in Go, is fully open source, and runs on multiple platforms. It aims to bridge the gap between security findings and developer action by adding a touch of humor and personality to security messages, potentially making it more accessible and less intimidating for developers.
Apr 01, 2025
816 words in the original blog post.
The Snyk team conducted a live Q&A session with John Hammond, a cybersecurity educator and developer influencer, along with Matt Kiely, challenge designer, Micah Silverman, Sonya Moisset, Vandana Verma, and Elliot Ward, developer advocates. The session covered various topics such as beginner advice to deep-dive tooling tips for CTFs (Capture The Flag) and cybersecurity. Key takeaways from the session included the importance of community, focusing on challenges that genuinely interest you, reading write-ups and watching walkthroughs, thinking like an attacker, using tools like PortSwigger Academy and PentesterLab to build foundational skills, and exploiting Math.random() by predicting future OTPs. The team also recommended various tools for CTF beginners, including Python, Google, Burp Suite, Metasploit, nmap, Kali Linux, Telnet, and ChatGPT.
Apr 01, 2025
733 words in the original blog post.