Qwiet AI Honored as Winner of Best Application Security Solution at the 2025 SC Awards
Key Takeaways Agentic AI is purpose-built for specific tasks, not general interaction. It doesn’t respond to prompts like a chatbot—it operates automatically based on system-level inputs. By limiting the scope of agentic AI, we enhance its precision and reliability. This approach removes variability and user-driven input, making the model easier to train, test, and trust […]
READ MOREToday is the day that all of us at ShiftLeft have been waiting for, the opportunity to share our value, vision and strategy to the world. The company has been reducing the noise that plagues the AppSec industry for some of the world’s largest companies through dramatic innovation like our code property graph and reachability […]
New Name, New Logo Shows Focus on “Preventing the Unpreventable” in the future of AppSec Disruptive startup led by cybersecurity AI pioneer Stuart McClure relaunches to reflect radical impact their platform is having on the world of AppSec and DevSecOps San Jose, CA. February 15, 2023—ShiftLeft, the first in the AppSec industry to provide AI-powered […]
Walk, Talk and Act like your internal customers: Product Engineering In my previous role at Nielsen, Clay Carter and Sam Neely did a phenomenal job of organizing the Product Security function into what closely resembles an engineering function. Product Managers oversaw services built internally and off the shelf. These services go through release planning, sprints […]
The Background Cybercriminals are currently exploiting a vulnerability in the popular server administration tool Control Web Panel (CWP). This vulnerability allows for a fairly trivial remote code execution (RCE), requiring no authentication. A recent Shodan search shows over 426,000 servers currently running CWP (down from around 435,000 servers a couple days ago) around the globe. […]
I have been fortunate enough to lead both engineering teams and security teams. I have felt the pain on both sides. On the engineering side, I felt the pressure of delivering for my product leaders and client services teams. On the Security side, I pressed hard to achieve acceptable risk levels and to remove vulnerabilities […]
CircleCI is currently investigating a security incident. We reached out to our customers using CircleCI as their development platform, but thought it important to share this information with the wider community. Their official announcement can be read here, but the key takeaways are: While CircleCI is sharing information on the key compromise, it’s important to […]
When I got the call to consider picking up the golden baton at the next-gen application security company (ShiftLeft) the thought hadn’t even crossed my mind. After all, I had committed to building another company (NumberOne AI), one that would build multiple companies and all of them on the foundations of predictive AI/ML to solve […]
This time of year offers everyone in Infosec the opportunity to set operational and strategic goals for the coming year. With the normal software cycle paused and developers on holiday, we can get the kind of serious work done that is only possible when everyone else isn’t around. Our team is no exception. Like anyone […]
SecOps and DevOps. They’re two sides of the same coin. But more often than not a divide exists between them that seems to always be growing . To an extent that makes sense in that SecOps is the gatekeeper, always thinking four steps ahead, the worrier, always considering what’s lurking in their environment that could […]