eCommerceNews Canada - Technology news for digital commerce decision-makers
Canada
Canadian Edition · 2026

The Ultimate Guide to Application Security

A curated Canadian edition of TechDay news, analysis, interviews, reviews, job moves, and related resources for Application Security.

What to know about Application Security

Application Security focuses on protecting software applications from vulnerabilities and cyber threats throughout their development and operational life cycles. This critical field addresses challenges such as runtime protection, secure coding practices, DevSecOps integration, API security, cloud-native environments, and mitigating attacks like DDoS, supply chain risks, and malicious bot traffic.

Exploring the latest stories in Application Security reveals how advancements like AI and automation are enhancing threat detection, vulnerability management, and developer workflows, while highlighting ongoing risks found in mobile apps, open source components, and cloud deployments. Readers can gain insights into best practices, emerging technologies, and strategies to safeguard applications against evolving cyber threats.

Whether you’re a developer, security professional, or business leader, staying informed about Application Security developments helps in building resilient software, maintaining compliance, and protecting user data in an increasingly complex digital landscape.

Canadian Application Security News

Regional stories with direct local relevance

Analyst Insights

Research and market analysis connected to Application Security

Expert Columns

Interviews

Interviews and video coverage from the network

Recent Application Security News

Google brings quantum-safe signatures to Cloud KMS
Security Operations Centres

Google brings quantum-safe signatures to Cloud KMS

Enterprises can now deploy quantum-safe signing in production as Cloud KMS adds post-quantum algorithms for sensitive records and transactions.

Today

Saviynt launches Zuma as AI identity security platform
Digital Transformation

Saviynt launches Zuma as AI identity security platform

Rising demand for AI security helped Saviynt top USD $300 million in annual recurring revenue as enterprises seek control over non-human identities.

Today

Microsoft launches Project Perception & AI-Cyber-1-Flash
Digital Transformation

Microsoft launches Project Perception & AI-Cyber-1-Flash

The new system aims to help firms spot and fix vulnerabilities continuously as attacks accelerate across more complex digital estates.

Yesterday

SafeLogic launches platform for post-quantum migration
Risk & Compliance

SafeLogic launches platform for post-quantum migration

Businesses face a growing compliance burden as regulators push post-quantum upgrades, and SafeLogic is aiming to ease the search for hidden cryptography.

Last week

Ossprey raises USD $2.65 million for supply chain security
Cyber attacks

Ossprey raises USD $2.65 million for supply chain security

The round will fund hiring, product work and overseas growth as investors back tools to counter AI-driven software supply chain risks.

Last week

Azul to launch monthly Java security patch updates
Chief Information Security Officer

Azul to launch monthly Java security patch updates

Organisations running Java in production will get faster fixes for serious flaws as Azul moves to monthly security-only updates from August 2026.

Last week

Google makes CodeMender available in its Gemini security models
Digital Transformation

Google makes CodeMender available in its Gemini security models

Developers may get patched code faster as Google's preview agent scans repositories, tests exploits and drafts fixes for review.

Last week

Cisco launches Antares AI models for code flaw pinpointing
IT Department

Cisco launches Antares AI models for code flaw pinpointing

Security teams could cut hours from patching work as open-weight Antares models narrow flaws to the relevant code segment.

Last week

CrowdStrike warns of malware targeting AI coding tools
Threat intelligence

CrowdStrike warns of malware targeting AI coding tools

Developers using AI assistants could face stolen credentials and poisoned repositories as the worm hides inside normal coding workflows.

Last week

Qualys joins Chainguard's Athena security coalition
Threat intelligence

Qualys joins Chainguard's Athena security coalition

The coalition has now processed more than 40,000 findings, underscoring how quickly open source flaws can spread across corporate systems.

Last week

Lineaje launches AI vulnerability elimination factory
Security Operations Centres

Lineaje launches AI vulnerability elimination factory

The tool aims to help developers cut vulnerability backlogs and reach no exploitable flaws within 90 days as AI coding expands risk.

Last week

F5 adds fleet management tools for BIG-IP environments
Software Updates

F5 adds fleet management tools for BIG-IP environments

Security teams under pressure to patch faster can now track and stage BIG-IP updates across fleets without losing audit control.

This month

FIS joins Anthropic cyber security project with Mythos 5
Supply Chain

FIS joins Anthropic cyber security project with Mythos 5

For thousands of banks and payments firms, the trial could help spot software flaws before they disrupt critical financial systems.

This month

Google Cloud unveils AI security blueprint for GKE
Managed Services

Google Cloud unveils AI security blueprint for GKE

The framework targets CISOs and platform teams as they move AI systems into production, amid rising risks from prompts, models and outputs.

This month

Google Cloud issues guardrails for AI vulnerability agents
Threat intelligence

Google Cloud issues guardrails for AI vulnerability agents

Security teams are being warned to keep humans and strict controls in place as AI agents can miss context and leak sensitive code.

This month

Google Cloud sets out AI security plan with Gemini & Wiz
Threat intelligence

Google Cloud sets out AI security plan with Gemini & Wiz

Defenders could gain a faster edge against AI-driven attacks as Google Cloud ties Gemini, Wiz, CodeMender and Mandiant into one platform.

This month

GitLab 19.2 adds AI tools for security & workflows
Identity and Access Management

GitLab 19.2 adds AI tools for security & workflows

The update aims to cut review bottlenecks by auto-fixing vulnerable dependencies and surfacing code flaws scanners often miss.

This month

SecurityBridge launches SAPMAP to map attack paths
Digital Transformation

SecurityBridge launches SAPMAP to map attack paths

Security teams can now trace how one SAP flaw could spread across finance, payroll and supply chains, with access tightly restricted.

This month

CleanStart launches Clean Libraries to secure AI code
Chief Technology Officers

CleanStart launches Clean Libraries to secure AI code

Developers face earlier checks on risky open-source dependencies as AI coding tools speed up software assembly and raise supply chain concerns.

This month

Targeted open source malware attacks on developers soar
Threat intelligence

Targeted open source malware attacks on developers soar

Malicious package advisories jumped from 21 in 2023 to 1,576 in 2025, as attackers increasingly target developers before code reaches production.

This month