Home / Companies / Snyk / Blog / May 2025

May 2025 Summaries

12 posts from Snyk

Filter
Month: Year:
Post Summaries Back to Blog
The Snyk AI Trust Platform is designed to help organizations achieve "AI Trust" by providing advanced tooling and empowering developers. The new Learn Add-on, part of the platform, aims to educate developers on secure development practices in the AI era through education and AI-powered assistance. This add-on reduces application risk, accelerates secure development, and helps meet industry standards such as PCI-DSS, SOX, SOC 2, and ISO 27001. The Snyk Learning Management Add-on enables security leaders to assign lessons and track progress, while also providing an AI learning assistant called Snyk Assist that offers real-time support to developers. This tool is designed to address the need for fast and secure development in a fully AI-enabled reality.
May 29, 2025 596 words in the original blog post.
The software development industry is undergoing a significant shift driven by artificial intelligence, with AI-powered coding tools rapidly integrating into developer workflows. This shift brings opportunities for innovation but also introduces new types of risk, including security flaws in AI-generated code and dynamic systems that are harder to secure with traditional tools. To address these challenges, organizations need an AI TrustOps readiness model to build and secure software in the age of AI. This approach recognizes that developers are collaborating with AI assistants, integrating models, and deploying agents that make decisions on their own, and offers a structured, practical way to think ahead and build security and trust into AI-driven development without slowing innovation down. The framework identifies five key areas of focus, including governance, secure design, risk assurance, and culture, and explains why mature DevSecOps practices are essential before starting.
May 29, 2025 906 words in the original blog post.
The development landscape is shifting as artificial intelligence (AI) becomes increasingly prevalent, with enterprise teams adopting real-world AI use cases at scale. By 2028, it's expected that 75% of software engineers will be using AI-assisted coding tools, and by 2030, 95% of code could be generated by AI. While these tools have accelerated development, they also increase the risk of security breaches due to flawed training data, reliance on open-source code, and package hallucination attacks. To address this, developers are shifting towards guiding AI agents through high-level instructions that generate entire features, and a new platform called AI Trust is being built to provide developer-first security solutions across the software development lifecycle.
May 29, 2025 478 words in the original blog post.
Snyk Labs is a new innovation and research arm dedicated to tackling the challenges of AI-native security, which is transforming the software development landscape with rapid advancements in Artificial Intelligence. The lab aims to provide a resource hub for understanding and navigating the future of AI security, showcasing technical demos, prototypes, and breakthrough research from Snyk's team and partners. Securing the new AI development lifecycle requires a fresh perspective and continuous innovation, and Snyk Labs is focusing on developing an AI Bill of Materials (AI BoM) to provide clear visibility into AI model usage within software. The lab is also pioneering the GenAI Model Risk Registry to understand and mitigate risks associated with different AI models, fostering a community and building coalitions to advance AI security.
May 28, 2025 415 words in the original blog post.
The Snyk AI Trust Platform is a purpose-built platform designed to help organizations secure their future in the age of AI, where increased acceleration introduces new risks if not managed effectively. The platform delivers comprehensive visibility across AI-driven applications, intelligent prioritization to focus on what matters most, and scalable policy enforcement and governance. It provides features such as Snyk Assist, an AI-powered security expert who sits alongside developers in their training workflow; Snyk Agent Fix, which autonomously generates and validates fixes for identified issues; and Snyk Studio, which enables teams to integrate Snyk's security scanning capabilities into their coding assistants and AI-assisted workflows. The platform is built on Snyk's foundation of strong AppSec and governance, leveraging industry-leading engines, enterprise readiness, and powerful platform features to provide a unified security solution for organizations.
May 28, 2025 1,700 words in the original blog post.
The author attended HackSpaceCon 2025 in Cape Canaveral, where they spoke about bridging the knowledge gap between academia and industry regarding security education. The conference highlighted the significant work required to secure space applications, which is crucial for preventing critical errors that can halt an application or take down a rocket. The author emphasized the need to integrate security into computer science curricula as a core requirement, starting from the ground up, and providing practical, hands-on security education that mirrors real-world scenarios. A platform like Snyk Learn offers free, interactive security training that bridges this gap, focusing on real-world application security and shifting the approach from fixing problems after deployment to building security into the development process from the beginning. This is essential as we expand human presence beyond Earth and commercial space ventures proliferate, making security errors increasingly critical.
May 23, 2025 693 words in the original blog post.
Snyk recently conducted a survey of 101 US-based CISOs, finding that 88% are concerned about the current state of US cyber readiness, with AI being a major impetus for this unease. Almost all (96%) worry about AI-generated code introducing hidden vulnerabilities, while nearly three-fourths (70%) have faced an AI-related attack in 2025 alone. Despite concerns, most CISOs remain confident in their ability to maintain a sufficient security posture for their own organizations, with almost all (94%) sharing confidence in their organization's ability to stay secure and regulatory compliant for the next few years. The survey also found that CISOs are keeping an eye on new AI-related legislation and regulations, and many believe that policies are keeping pace with AI advancements. To mitigate potential cybersecurity pitfalls, CISOs suggested implementing generative AI security defense systems, continuous security validation and breach testing, real-time vulnerability management platforms, DevSecOps fully integrated with AI development, and security built into software supply chains by design. While AI-generated code is seen as a future wave of innovation, 96% of CISOs expressed concern about its potential to introduce hidden vulnerabilities, citing factors such as the rapid evolution of AI outpacing security controls, developer teams' lack of skills, and lack of clear security standards for AI-generated software.
May 22, 2025 873 words in the original blog post.
When developing a web application, dev teams can choose between Single-Page Applications (SPAs) or traditional Multi-Page Applications (MPAs), with SPAs providing a smoother user experience and better adoption. SPAs have several benefits, including faster performance due to reduced page reloads and improved load times through enhanced caching mechanisms. They also offload rendering and processing to the client-side, reducing server load and bandwidth usage. This makes them suitable for organizations creating web apps with large user bases and high traffic volume. However, SPAs present security challenges, particularly in testing dynamic content changes using traditional security testing methods. To address this, Snyk API & Web provides comprehensive scans of both APIs and web applications, including seamless integration with popular JavaScript frameworks like AngularJS, ReactJS, and Vue.js.
May 21, 2025 995 words in the original blog post.
At RSAC 2025, Snyk focused on the future of cybersecurity, particularly the impact of generative AI on software security. The company highlighted its commitment to integrating AI into its solutions and showcased cutting-edge demonstrations that drew significant attention from attendees and industry experts alike. Snyk's presence at the conference featured a range of activities, including networking events, panel discussions, and product showcases, which demonstrated the company's comprehensive approach to securing APIs and web applications. The company also emphasized its commitment to fostering a more diverse and inclusive environment, particularly through initiatives such as the "Women Leading Security" panel and luncheon. With Snyk Launch 2025 on the horizon, the company is poised to address the challenges of generative AI and related technologies in application development and maintenance, providing a strong foundation for secure development and operations.
May 12, 2025 686 words in the original blog post.
Snyk is evolving its Global Channel & GSI Partner Program to foster deeper, more impactful relationships with partners in the rapidly evolving world of AI Security. The company aims to empower partners with resources and opportunities to build thriving businesses alongside Snyk. A shift from transactional to strategic collaborations will be made, focusing on formalized business practices and concentrated resources on key partnerships. Key enhancements include formalized go-to-market programs, optimized resale discounts, revitalized marketing development funds, strategic GTM and co-marketing planning, enhanced enablement & activation programs, exclusive benefits for Platinum and Gold partners, priority access to strategic engagements, dedicated regional partner management, and targeted marketing campaigns for platinum partners. By strengthening its partnership ecosystem, Snyk is equipping its ecosystem with the tools, resources, and support necessary to thrive in the evolving AI Security landscape, ultimately shaping a more secure digital future together.
May 08, 2025 606 words in the original blog post.
Snyk Learn, a developer security education platform, has introduced a new learning path focused on open source software security risks. The OWASP Top 10 learning path provides guidance on the most critical vulnerabilities unique to open source projects and how to mitigate them effectively. This course is designed to help developers and security professionals navigate the challenges of open source security, including evaluating open source packages, contributing securely, and protecting applications from supply chain threats. With real-world examples and a certificate of completion, Snyk Learn aims to empower developers to find and fix vulnerabilities throughout their software development lifecycle.
May 05, 2025 327 words in the original blog post.
Snyk and ServiceNow are partnering to provide a solution to secure AI-generated code, which is becoming increasingly mainstream in software development. While GenAI tools increase productivity, they also create more work for application security teams. To address this challenge, Snyk's AI-powered developer security platform combines with ServiceNow Application Vulnerability Response to protect software supply chains and secure custom code, open source dependencies, and cloud infrastructure. The integration provides broad visibility into risk posture, prioritization, and automated fixes, reducing remediation time and increasing collaboration between developers and security teams. With Snyk's DeepCode AI, vulnerabilities in AI-generated code are quickly identified and automatically fixed with a single click, dramatically reducing mean time to remediate (MTTR) and saving thousands of developer hours. The partnership aims to future-proof AppSec strategies as AI-generated code becomes the norm.
May 01, 2025 707 words in the original blog post.