Definition
Application security (AppSec) covers practices and tools that find and fix vulnerabilities in application code — injection, XSS, insecure data handling, path traversal, weak crypto — across SDLC stages.
Key Points
-
2026-07-29: cve-2026-66066 Rails Active Storage / libvips CVSS 9.5 arbitrary file read (2026-08-01-rails-ghsa-xr9x-r78c-5hrm)
-
2026-07-22/23: claude-security-plugin beta — multi-agent in-session AppSec for claude-code; complements sast (2026-07-24-anthropic-claude-security-docs)
-
2026-07: cisco-antares for vuln localization; github bounty restructure (2026-07-23-cisco-antares-open-weight-vuln-localization, 2026-07-23-github-bug-bounty-restructure-vip)
-
2026-07-17: capital-one open-sources vulnhunter — attacker-first + falsification AppSec agent (2026-07-18-capital-one-vulnhunter-official)
-
GitHub Copilot app
/security-review(July 2026 public preview) brings AI vulnerability scanning into desktop workflow -
Complements Code Scanning, Dependabot, and secret scanning — not a replacement