CMOtech Canada - Technology news for CMOs & marketing decision-makers
Canada
Canadian Edition · 2026

The Ultimate Guide to Application Security

A curated Canadian edition of TechDay news, analysis, interviews, reviews, job moves, and related resources for Application Security.

What to know about Application Security

Application Security focuses on protecting software applications from vulnerabilities and cyber threats throughout their development and operational life cycles. This critical field addresses challenges such as runtime protection, secure coding practices, DevSecOps integration, API security, cloud-native environments, and mitigating attacks like DDoS, supply chain risks, and malicious bot traffic.

Exploring the latest stories in Application Security reveals how advancements like AI and automation are enhancing threat detection, vulnerability management, and developer workflows, while highlighting ongoing risks found in mobile apps, open source components, and cloud deployments. Readers can gain insights into best practices, emerging technologies, and strategies to safeguard applications against evolving cyber threats.

Whether you’re a developer, security professional, or business leader, staying informed about Application Security developments helps in building resilient software, maintaining compliance, and protecting user data in an increasingly complex digital landscape.

Canadian Application Security News

Regional stories with direct local relevance

Analyst Insights

Research and market analysis connected to Application Security

Expert Columns

Interviews

Interviews and video coverage from the network

Recent Application Security News

Canada ahead of global average on password security
Data Protection

Canada ahead of global average on password security

Canada slightly outperforms the global average on password security, but Zoho warns identity gaps, third-party access and legacy systems still loom large.

Yesterday

Vega spots Weaver E-cology attacks within days of patch
Threat intelligence

Vega spots Weaver E-cology attacks within days of patch

Vega says attackers began exploiting a critical Weaver E-cology remote code execution flaw within five days of the vendor patch, with no lasting foothold.

2 days ago

Saiga phishing kit returns to bypass multifactor auth
QR code

Saiga phishing kit returns to bypass multifactor auth

Barracuda spots Saiga 2FA phishing kit revival as attackers use dynamic pages and cookie theft to sidestep multifactor authentication.

2 days ago

Kamiwaza launches AI platform for regulated sectors
Government

Kamiwaza launches AI platform for regulated sectors

Kamiwaza AI debuts version 1.0 platform for healthcare, banking and government users, promising governed access and hardened infrastructure.

3 days ago

Chainguard launches compliant EKS add-ons in AWS Marketplace
Public Sector

Chainguard launches compliant EKS add-ons in AWS Marketplace

Chainguard brings compliant EKS add-ons to AWS Marketplace, giving regulated organisations FIPS 140-3 validated Kubernetes components with zero known CVEs.

3 days ago

Tenable finds GitHub workflow flaw in Microsoft repo
DevOps

Tenable finds GitHub workflow flaw in Microsoft repo

Tenable flags GitHub workflow flaw in Microsoft's Windows-driver-samples repo that could let attackers run code and reach secrets.

3 days ago

Cloudflare warns of AI code review prompt injection
Virtual Private Networks

Cloudflare warns of AI code review prompt injection

Cloudflare says indirect prompt injection can fool AI code reviewers, with malicious scripts slipping past models when buried in large files and comment noise.

3 days ago

Qilin drives 43% rise in ransomware attacks
Email Security

Qilin drives 43% rise in ransomware attacks

Qilin-linked ransomware attacks jumped 43% in March, NCC Group says, as AI-fuelled deception and software flaws widen the threat picture.

Last week

OpenObserve raises USD $10 million for Observability 3.0
Network Infrastructure

OpenObserve raises USD $10 million for Observability 3.0

OpenObserve wins USD $10 million backing to expand its Observability 3.0 platform, adding AI SRE and LLM monitoring for enterprise customers.

Last week

Intruder launches AI pentesting for faster validation
DevOps

Intruder launches AI pentesting for faster validation

Intruder's new AI Pentesting tool aims to validate scanner findings in minutes, easing pressure on security teams facing faster-moving threats.

Last week

Keeper Security launches Agent Kit for AI coding agents
Virtualisation

Keeper Security launches Agent Kit for AI coding agents

Keeper Security launches Agent Kit to let AI coding assistants handle secrets and admin tasks without exposing credentials in chat logs.

Last week

Intruder launches AI pentesting to cut vulnerability triage
Cloud Services

Intruder launches AI pentesting to cut vulnerability triage

Intruder launches AI Pentesting to help security teams validate scanner findings faster as pressure mounts over shrinking exploit windows.

Last week

Virtana adds AWS Bedrock Guardrails support to AI Factory
Government

Virtana adds AWS Bedrock Guardrails support to AI Factory

Virtana expands AI Factory Observability with AWS Bedrock Guardrails support, giving security teams deeper insight into enterprise LLM behaviour and anomalies.

Last week

AI is biggest cyber threat to CISOs, NCC Group warns
Disaster Recovery

AI is biggest cyber threat to CISOs, NCC Group warns

Artificial intelligence heightens cyber risk for chief information security officers as ransomware attacks rise 22% in March, NCC Group says.

Last week

Bots make up 53% of web traffic, Thales report says
Threat intelligence

Bots make up 53% of web traffic, Thales report says

Thales says AI-driven bots now account for 53% of web traffic, as malicious automation surges and API attacks intensify across finance.

Last week

Qualys warns cloud risk now stems from identity design
Data breach

Qualys warns cloud risk now stems from identity design

Qualys report says cloud breaches are increasingly driven by identity design, delegated trust and slow remediation as AI widens exposure.

Last week

GitLab deepens Anthropic Claude integration for governance
Data Protection

GitLab deepens Anthropic Claude integration for governance

GitLab adds Anthropic's latest Claude models to Duo Agent Platform, giving enterprises cloud-based access with governance, compliance and audit controls.

Last week

Oracle NetSuite launches AI coding skills for developers
IT Industry

Oracle NetSuite launches AI coding skills for developers

Oracle NetSuite rolls out AI coding skills for developers, aiming to speed custom app building and reduce errors across 25 platforms.

Last week

API attacks surge as AI exposure raises cyber risk
Data Protection

API attacks surge as AI exposure raises cyber risk

Akamai survey finds APIs are now cybercriminals' main target, with AI-linked interfaces under attack and incidents costing organisations more than USD $700,000.

Last week

MathWorks adds AI copilot tools to MATLAB & Simulink
EdTech

MathWorks adds AI copilot tools to MATLAB & Simulink

MathWorks adds Simulink Copilot and Polyspace Copilot in R2026a, bringing generative AI tools to embedded design, code analysis and verification.

Last week