AI coding agents are reshaping software development—but they’re also expanding the attack surface. Researchers uncovered a now-patched vulnerability in Anthropic’s Claude Code GitHub Action that could have enabled prompt injection attacks to expose CI/CD secrets, API keys, and credentials. As AI agents gain autonomy in development workflows, organizations must treat untrusted inputs as hostile and rethink CI/CD security models. Natural language is becoming executable code—and attackers know it.
Top 10 Common Software Vulnerabilities
An essential part of an effective software security process is being familiar with software vulnerabilities, which are flaws or weaknesses in your code. Often, testing and manual code reviews are […]
What is SAST? Overview + SAST Tools
Static Application Security Testing Overview With the growing number of cybersecurity threats, you must ensure that your software is protected against potential vulnerabilities and threats. One of the most beneficial […]
What Is PA-DSS?
If you develop payment application software, you must ensure that it is secure and compliant with PA DSS. Read on to learn more about the payment application security standard. What […]
Best Practices for a Secure Software Development Project
The beginning of any new software development project can be daunting, as there are many decisions that need to be made and considerations that must be thought through. Often this […]
5 Ways to Accelerate Standards Compliance With Static Code Analysis
In mission- and safety-critical industries, static code analysis is essential to facilitating the development of robust and reliable software. However, according to VDC Research, a B2B technology market intelligence and […]
Top 10 Embedded Security Vulnerabilities
Nearly all of detected security vulnerabilities can be attributed to just 10 types. Here, we discuss the most common cybersecurity vulnerabilities and offer guidance on how to mitigate their risk. […]
What Is ISO 21434? Compliance Tips for Automotive Software Developers
What Is ISO 21434? Compliance Tips for Automotive Software Developers To read more, please visit: https://www.perforce.com/blog/qac/ISO-21434-Compliance
What is the NIST Cybersecurity Framework?
Cybersecurity threats are easier to handle when you have a framework to build off of. That’s why NIST developed the Cybersecurity Framework. Learn more. What You Need to Know About […]
What Is OWASP?
With cybersecurity attacks rising, it is important for you to enforce secure software best practices, like OWASP and the OWASP Top 10. OWASP helps you to safeguard your code against […]











