Home / Companies / Snyk / Blog / October 2025

October 2025 Summaries

7 posts from Snyk

Filter
Month: Year:
Post Summaries Back to Blog
DevSecCon 2025 was a vibrant conference focusing on the intersection of AI and security, emphasizing the rapid pace of AI's evolution and its projected $22 trillion impact on the global economy by 2030. The event highlighted the necessity for secure AI-accelerated DevSecOps practices, showcasing Snyk's new capabilities designed to integrate security seamlessly into modern development workflows. These include improvements to developer tools and AppSec team functionalities, advanced analytics, and a groundbreaking partnership with Cognition to embed security intelligence directly into AI workflows. The conference also addressed the challenges of securing AI-native applications with the introduction of Evo by Snyk, an agentic security orchestration system. Beyond the conference, DevSecCon has fostered a global community dedicated to AI security, promoting collaboration and providing open-source security solutions to maintainers. The event encouraged participants to take actionable steps towards securing AI initiatives and offered opportunities for organizations to engage further with Snyk's evolving security platforms.
Oct 23, 2025 1,627 words in the original blog post.
The rapid evolution of AI technology has created a significant challenge for cybersecurity, as traditional methods struggle to keep pace with the real-time adaptability and autonomous capabilities of AI systems. This shift has necessitated the emergence of a new role, the AI Security Engineer, who must navigate the complexities of securing AI-native systems without full visibility or adequate tools. Snyk's Evo, described as the world's first Agentic Security Orchestrator, aims to address this gap by providing proactive, continuous, and integrated security measures that empower these engineers. Evo operates through natural language prompts and specialized AI security agents, offering a seamless, intelligent approach to safeguarding AI applications. The initiative underscores the need for security to be an inherent part of the development process rather than an afterthought, advocating for a model that ensures innovation and security can coexist without compromising speed or effectiveness.
Oct 22, 2025 725 words in the original blog post.
Mercato Solutions, one of EMEA's fastest-growing low-code enterprise application providers, aids global clients in transforming business processes through bespoke software platforms and applications, emphasizing efficiency and cost-effectiveness. Neil Tonkin, the company's CTO, has played a crucial role in developing Mercato's intellectual property and maintaining its niche as a valued software provider. Mercato's reliance on a cloud-first low-code platform allows citizen developers to create applications without needing coding knowledge, serving satisfied customers in over 150 countries. The company faces a challenge in balancing security with flexibility, relying on Snyk to bolster their security posture while maintaining core functionality. Snyk's integration into Mercato's DevOps pipeline has helped reduce security incidents significantly, and the partnership has enhanced their ability to deliver secure, flexible applications efficiently. This collaboration has been pivotal in Mercato's success, leading to nearly zero security incidents and making them one of the few companies to achieve CESG security status in the UK.
Oct 16, 2025 910 words in the original blog post.
Snyk has partnered with Cognition to integrate Snyk's security intelligence into Cognition's AI-native developer tools, Devin and Windsurf, as part of their "Secure at Inception" model. This collaboration addresses the challenge of maintaining security in an era where AI tools significantly accelerate development speed, creating a bottleneck for manual security reviews. By embedding Snyk's capabilities directly into these workflows, developers can benefit from real-time code analysis and automated security scanning, enabling them to identify and fix vulnerabilities as they write code. This integration facilitates more efficient resource allocation by allowing AI agents to handle routine security tasks, thus freeing up human teams for more complex security challenges. The new implementations, Snyk for Devin and Snyk for Windsurf, aim to improve continuous security posture and governance at scale, ensuring compliant development processes without compromising on innovation velocity.
Oct 15, 2025 466 words in the original blog post.
AI is transforming software development, introducing new security challenges that development and security leaders must navigate, emphasizing the need for comprehensive visibility in the development lifecycle. DevSecCon, scheduled for October 22, 2025, offers a platform for leaders to discuss and strategize on secure development practices in this AI-driven era. The conference will address key themes such as elevating application security teams from task management to strategic governance, empowering developers with seamless security integration, measuring the success of security programs, and embedding security into AI workflows to handle vulnerabilities inherent in AI-generated code. Sessions will focus on innovative approaches, such as using the Snyk platform for effective prioritization and automated remediation, and the need for new security strategies to manage risks posed by AI-powered applications, aiming to build security programs that serve as strategic enablers for businesses.
Oct 15, 2025 972 words in the original blog post.
Snyk has been recognized as a Leader in the 2025 Gartner® Magic Quadrant™ for Application Security Testing (AST) due to its compelling vision and execution capabilities, which align with its mission to empower developers with secure building practices while offering security teams comprehensive visibility and control. As software development accelerates with cloud, microservices, and AI advancements, Snyk's developer-centric security approach, including its complete platform offerings like Snyk Code (SAST), Snyk Open Source (SCA), Snyk Container, Snyk Infrastructure as Code, and Snyk API & Web, has positioned the company at the forefront of the market. This recognition is further supported by Snyk's innovations in AI and developer enablement, with features such as AI-powered remediation and risk detection, and the seamless integration of security measures into existing workflows like IDEs, SCMs, and CI/CD pipelines. The company's recent acquisitions of Invariant Labs and Probely have bolstered its AI and machine learning capabilities, enhancing its ability to deliver automated, AI-driven security at scale, as Snyk continues to advance towards a more secure future for software development.
Oct 14, 2025 468 words in the original blog post.
In October 2025, researchers identified a sophisticated phishing operation exploiting the npm ecosystem not by infecting developers during the package installation but by using the trusted unpkg.com CDN to host and deliver phishing scripts. The attackers created over 175 disposable npm packages to host JavaScript that redirects users to credential-harvesting sites when opened from specially crafted HTML documents. The campaign targeted over 135 organizations across industrial, tech, and energy sectors, primarily in Europe. Following the disclosure by Socket, Snyk mapped additional packages with a different naming scheme, suggesting possible copycat actions or related infrastructure. This operation demonstrates a shift from traditional package-based exploits to leveraging legitimate open-source hosting for phishing attacks, signaling an evolving threat landscape in the open-source ecosystem. The attack uses HTML lure files to trigger scripts from unpkg.com, which redirect victims to phishing pages, capturing credentials through pre-filled forms, thus bypassing traditional supply chain compromises and employing new methods to exploit open-source components.
Oct 10, 2025 1,766 words in the original blog post.