<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Application Security</title><description>Cybersecurity articles tagged #Application Security on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>AI Vulnerability Surge: Enterprise Security Strategies</title><link>https://runtimerebel.com/blog/ai-vulnerability-surge-enterprise-security-strategies</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-vulnerability-surge-enterprise-security-strategies</guid><description>New research suggests the anticipated increase in AI vulnerabilities can be managed by enterprise security teams with effective strategies.</description><pubDate>Thu, 03 Sep 2026 02:06:02 GMT</pubDate><category>AI</category><category>Machine Learning</category><category>Application Security</category><category>Vulnerability Management</category><category>Enterprise Security</category></item><item><title>OWASP Releases Top 10 Security List and Universal Skill Format for AI</title><link>https://runtimerebel.com/blog/owasp-releases-top-10-security-list-and-universal-skill-format-for-ai</link><guid isPermaLink="true">https://runtimerebel.com/blog/owasp-releases-top-10-security-list-and-universal-skill-format-for-ai</guid><description>OWASP debuts a top 10 security list and Universal Skill Format to secure AI add-ons, addressing modern artificial intelligence risks.</description><pubDate>Sat, 22 Aug 2026 00:41:22 GMT</pubDate><category>OWASP</category><category>Artificial Intelligence</category><category>Application Security</category><category>Zero-Day</category></item><item><title>AI Browser Prompt Injection Flaws Defeat Vendor Guardrails</title><link>https://runtimerebel.com/blog/ai-browser-prompt-injection-flaws-defeat-vendor-guardrails</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-browser-prompt-injection-flaws-defeat-vendor-guardrails</guid><description>New security research reveals that AI-powered web browsers remain susceptible to persistent prompt injection flaws despite guardrails.</description><pubDate>Sun, 09 Aug 2026 16:25:35 GMT</pubDate><category>Artificial Intelligence</category><category>Browser Security</category><category>Zero-Day</category><category>Application Security</category></item><item><title>AI-Generated Patches: High Failure Rate &amp; New Vulnerabilities</title><link>https://runtimerebel.com/blog/ai-generated-patches-high-failure-rate-new-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-generated-patches-high-failure-rate-new-vulnerabilities</guid><description>A recent study reveals that AI-generated software patches fail in approximately half of all cases, often introducing new bugs or bypass vulnerabilities.</description><pubDate>Sat, 08 Aug 2026 00:55:21 GMT</pubDate><category>AI</category><category>Software Patching</category><category>Application Security</category><category>Vulnerability Management</category><category>Secure Development</category></item><item><title>AI Agent Sandbox Escape: Applying Traditional Security to Novel Threats</title><link>https://runtimerebel.com/blog/ai-agent-sandbox-escape-applying-traditional-security-to-novel-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agent-sandbox-escape-applying-traditional-security-to-novel-threats</guid><description>OpenAI&apos;s AI agent sandbox escape highlights critical security gaps. Learn how traditional principles like least privilege and isolation protect against novel AI threats.</description><pubDate>Tue, 28 Jul 2026 21:10:49 GMT</pubDate><category>AI Agents</category><category>Sandbox Escape</category><category>Application Security</category><category>OpenAI</category><category>Least Privilege</category><category>Isolation</category><category>Threat Intelligence</category></item><item><title>Palo Alto Networks Acquires Embrace: Security Observability Implications</title><link>https://runtimerebel.com/blog/palo-alto-networks-acquires-embrace-security-observability-implications</link><guid isPermaLink="true">https://runtimerebel.com/blog/palo-alto-networks-acquires-embrace-security-observability-implications</guid><description>Palo Alto Networks acquires Embrace, deepening its cloud security capabilities by integrating observability for enhanced application protection and threat detection.</description><pubDate>Wed, 22 Jul 2026 17:22:46 GMT</pubDate><category>Palo Alto Networks</category><category>Embrace</category><category>Observability</category><category>Cloud Security</category><category>Acquisition</category><category>Application Security</category></item><item><title>AI-Generated Code Vulnerabilities: Framework Pairing is Key to Risk</title><link>https://runtimerebel.com/blog/ai-generated-code-vulnerabilities-framework-pairing-is-key-to-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-generated-code-vulnerabilities-framework-pairing-is-key-to-risk</guid><description>AI-generated code introduces an average of 15 vulnerabilities per codebase. This analysis explores how framework choices significantly influence the actual security risk.</description><pubDate>Tue, 21 Jul 2026 13:56:54 GMT</pubDate><category>AI Generated Code</category><category>Code Security</category><category>Application Security</category><category>Vulnerabilities</category><category>Developer Security</category><category>Secure Development</category></item><item><title>2-Click Cursor Exploit: Dev Environment Takeover Risks &amp; Mitigations</title><link>https://runtimerebel.com/blog/2-click-cursor-exploit-dev-environment-takeover-risks-mitigations</link><guid isPermaLink="true">https://runtimerebel.com/blog/2-click-cursor-exploit-dev-environment-takeover-risks-mitigations</guid><description>Analyze the &apos;2-click cursor exploit&apos; leveraging &apos;age-old bugs&apos; to compromise developer environments, risking source code and IP theft.</description><pubDate>Wed, 15 Jul 2026 13:49:23 GMT</pubDate><category>Developer Environments</category><category>Supply Chain Security</category><category>Application Security</category><category>Exploitation</category><category>Source Code Theft</category></item><item><title>AI Code Generation Security Risks: Managing Vibe Coding Governance</title><link>https://runtimerebel.com/blog/ai-code-generation-security-risks-managing-vibe-coding-governance</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-code-generation-security-risks-managing-vibe-coding-governance</guid><description>Learn how to manage AI code generation security risks and implement governance for vibe coding practices in the software development lifecycle.</description><pubDate>Mon, 08 Jun 2026 17:13:52 GMT</pubDate><category>Vibe Coding</category><category>AI Security</category><category>LLM Governance</category><category>Shadow AI</category><category>Application Security</category></item><item><title>Securing Agentic AI Deployments: Mitigating Overlap Risks</title><link>https://runtimerebel.com/blog/securing-agentic-ai-deployments-mitigating-overlap-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-agentic-ai-deployments-mitigating-overlap-risks</guid><description>Understanding the security risks in agentic AI deployments is crucial. This article outlines how AI agents&apos; interaction with software tools creates vulnerabilities and…</description><pubDate>Thu, 28 May 2026 17:25:59 GMT</pubDate><category>Agentic AI</category><category>AI Security</category><category>Application Security</category><category>Responsible AI</category><category>Secure Deployment</category></item><item><title>npm Staged Publishing: New 2FA Controls Prevent Supply Chain Attacks</title><link>https://runtimerebel.com/blog/npm-staged-publishing-new-2fa-controls-prevent-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/npm-staged-publishing-new-2fa-controls-prevent-supply-chain-attacks</guid><description>GitHub introduces staged publishing for npm, requiring manual 2FA approval for package releases to mitigate malicious automated updates and account takeovers.</description><pubDate>Sat, 23 May 2026 20:21:54 GMT</pubDate><category>NPM</category><category>GitHub</category><category>Supply Chain Security</category><category>Two Factor Authentication</category><category>Staged Publishing</category><category>Application Security</category></item><item><title>Software Supply Chain Security: Addressing Visibility Gaps</title><link>https://runtimerebel.com/blog/software-supply-chain-security-addressing-visibility-gaps</link><guid isPermaLink="true">https://runtimerebel.com/blog/software-supply-chain-security-addressing-visibility-gaps</guid><description>An analysis of the growing software supply chain crisis, focusing on the acceleration of vulnerability exploitation and the lack of systemic visibility.</description><pubDate>Thu, 21 May 2026 09:16:05 GMT</pubDate><category>Software Supply Chain</category><category>Vulnerability Management</category><category>SBOM</category><category>Application Security</category></item><item><title>OpenClaw &apos;Claw Chain&apos; Vulnerabilities: Credential Theft, Persistence</title><link>https://runtimerebel.com/blog/openclaw-claw-chain-vulnerabilities-credential-theft-persistence</link><guid isPermaLink="true">https://runtimerebel.com/blog/openclaw-claw-chain-vulnerabilities-credential-theft-persistence</guid><description>Analysis of &apos;Claw Chain&apos; vulnerabilities in OpenClaw, an AI agent framework, detailing credential theft, privilege escalation, and persistence risks.</description><pubDate>Tue, 19 May 2026 00:58:13 GMT</pubDate><category>OpenClaw</category><category>AI Agent Framework</category><category>Claw Chain</category><category>Credential Theft</category><category>Privilege Escalation</category><category>Persistence</category><category>Application Security</category></item><item><title>GitHub High-Severity Bug Discovered via AI Reverse Engineering</title><link>https://runtimerebel.com/blog/github-high-severity-bug-discovered-via-ai-reverse-engineering</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-high-severity-bug-discovered-via-ai-reverse-engineering</guid><description>Wiz utilized AI reverse-engineering to uncover a high-severity vulnerability within GitHub, demonstrating advanced discovery methods for complex bugs.</description><pubDate>Wed, 29 Apr 2026 20:32:08 GMT</pubDate><category>GitHub</category><category>Application Security</category><category>AI in Security</category><category>Vulnerability Discovery</category><category>Reverse Engineering</category><category>Wiz</category></item><item><title>GlassWorm Campaign Leverages Malicious VS Code Extensions</title><link>https://runtimerebel.com/blog/glassworm-campaign-leverages-malicious-vs-code-extensions</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-campaign-leverages-malicious-vs-code-extensions</guid><description>Runtime Rebel details the GlassWorm campaign, which infects developers via malicious Visual Studio Code extensions on Open VSX, facilitating a supply chain attack.</description><pubDate>Tue, 28 Apr 2026 16:45:38 GMT</pubDate><category>GlassWorm</category><category>VS Code</category><category>Open VSX</category><category>Supply Chain Attack</category><category>Malware</category><category>Developer Tools</category><category>Application Security</category></item><item><title>AI Coding Tools: New Challenges for Endpoint Security Defenses</title><link>https://runtimerebel.com/blog/ai-coding-tools-new-challenges-for-endpoint-security-defenses</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-coding-tools-new-challenges-for-endpoint-security-defenses</guid><description>A security researcher demonstrates how AI coding tools can bypass traditional endpoint security measures, prompting a reevaluation of defense strategies.</description><pubDate>Wed, 25 Mar 2026 00:37:30 GMT</pubDate><category>AI Coding Tools</category><category>Endpoint Security</category><category>Application Security</category><category>Threat Research</category></item><item><title>Raven Emerges From Stealth with $20M for Runtime Security</title><link>https://runtimerebel.com/blog/raven-emerges-from-stealth-with-20m-for-runtime-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/raven-emerges-from-stealth-with-20m-for-runtime-security</guid><description>Raven secures $20M in funding to launch a runtime application security platform designed to detect anomalous behavior and block sophisticated cyberattacks.</description><pubDate>Thu, 19 Mar 2026 12:19:58 GMT</pubDate><category>Raven</category><category>Runtime Security</category><category>Application Security</category><category>Cloud Native</category><category>Behavioral Analysis</category></item><item><title>Critical OpenClaw Flaw in AI Agents: Risks and Remediation Guide</title><link>https://runtimerebel.com/blog/critical-openclaw-flaw-in-ai-agents-risks-and-remediation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-openclaw-flaw-in-ai-agents-risks-and-remediation-guide</guid><description>A critical OpenClaw vulnerability in widely adopted AI agents could lead to severe security risks. Understand the impact and crucial remediation steps.</description><pubDate>Tue, 03 Mar 2026 00:36:48 GMT</pubDate><category>OpenClaw</category><category>AI Agents</category><category>Vulnerability</category><category>Application Security</category><category>Patching</category></item></channel></rss>