#Cycode
BREAKING TODAY! Cycode Extends its ADLC Security Capabilities to Developers’ Workstations, Stopping Software Supply Chain Attacks Before They Start -- radicaldatascience.wpcomstaging.com/2026/09/23/c...

#AI #Security #workstation #ADLC #SupplyChain
Cycode Extends its ADLC Security Capabilities to Developers’ Workstations, Stopping Software Supply Chain Attacks Before They Start
Workstation protection builds on the AI visibility, governance, and guardrails of the Cycode platform, blocking malicious packages in real time for customers Cycode, the leader in Agentic Developme…
radicaldatascience.wpcomstaging.com
September 23, 2026 at 9:53 PM
Cycode adds Workstation Protection to its ADLC Protection platform to block malicious or suspicious software packages before they reach developer workstations.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 23, 2026 at 1:36 PM
Cycode adds Workstation Protection to its ADLC Protection platform to block malicious or suspicious software packages before they reach developer workstations.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 23, 2026 at 1:36 PM
Cycode adds Workstation Protection to its ADLC Protection platform to block malicious or suspicious software packages before they reach developer workstations.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 23, 2026 at 1:36 PM
We're excited to welcome Cycode, a leader in software supply chain security and application security posture management. Their commitment to helping organizations build and deliver secure software aligns perfectly with the security-first mindset of our community.

🔗 Learn more:
Cycode | Agentic Development Security Platform
Cycode’s Agentic Development Security Platform unites security and development teams with actionable, code-to-runtime context to identify, prioritize, and fix the software risk that matters.
cycode.com
September 16, 2026 at 7:30 PM
🌟 Sponsor Spotlight: Cycode

Community-driven events like BSides Vancouver Island wouldn't be possible without the support of organizations that are passionate about advancing cybersecurity.

#BSidesVI2026 #CyberSecurity #InfoSec #AppSec #Cycode
September 16, 2026 at 7:30 PM
𝗖𝘆𝗰𝗼𝗱𝗲 𝗮𝗱𝗱𝘀 𝗔𝗴𝗲𝗻𝘁𝗶𝗰 𝗖𝗼𝗱𝗲 𝗦𝗰𝗮𝗻𝗻𝗶𝗻𝗴 𝘁𝗼 𝗰𝗼𝗻𝘁𝗿𝗼𝗹 𝗔𝗜 𝗺𝗼𝗱𝗲𝗹 𝘀𝗽𝗲𝗻𝗱
Cycode has launched Agentic Code Scanning, a system that decides which ...
https://www.developer-tech.com/news/cycode-adds-agentic-code-scanning-control-ai-model-spend/
via RSS App
September 7, 2026 at 7:49 PM
Cycode has added Agentic Code Scanning to its application-security platform, DeveloperTech reported, using AI routing and attack-path analysis to decide when code review needs a reasoning model instead of a cheaper rule-based scan.

#Cybersecurity
Cycode Adds Agentic Code Scanning to Control AI Review Costs
Cycode’s Agentic Code Scanning routes code review between AI and rule-based engines, with benchmark claims covering six CVEs, authorization flaws and MLflow detection volume.
stechtimes.com
September 7, 2026 at 7:00 AM
Cycode launches scanner for AI-speed code - x.com/ddgutierrez7...

#AI #AgenticAI #Security
September 4, 2026 at 4:55 PM
Cycode has added Agentic Code Scanning to decide which AI or rule-based engine checks which code and at what cost.

Is pointing a frontier LLM at every code commit creating unsustainable API bills for your team?

#cycode #appsec #devsecops #ai #technology
Cycode adds Agentic Code Scanning to control AI model spend
Cycode has launched Agentic Code Scanning, a system that decides which AI or rule-based engine reviews code and at what cost.
www.developer-tech.com
September 2, 2026 at 4:47 PM
#Cycode claims its AI scanner catches authorization bugs rule engines structurally can't see. We pushed on the benchmark. The CTO's follow-up had more detail than the press release — and a few numbers that didn't match it.
coderlegion.com/26085/cycode... #AgenticAI #AppSec #InfoSec #DevSecOps
Cycode's AI Scanner Found 38 Bugs in MLflow. The Press Release Only Mentioned One.
Every AI security vendor ships a benchmark chart these days. Most of them don't survive a second phone call. On September 1, Cycode launched Agentic Code Scanning, a fourth layer that sits on top of i...
coderlegion.com
September 2, 2026 at 2:42 PM
BREAKING TODAY! Cycode Releases Agentic Code Scanning and Attack Chaining, Post-Mythos Era’s Answer to Cost vs. Precision Tradeoff -- radicaldatascience.wordpress.com/2026/09/01/c...

#AI #GenAI #AgenticAI #Coding #Mythos
Cycode Releases Agentic Code Scanning and Attack Chaining, Post-Mythos Era’s Answer to Cost vs. Precision Tradeoff
Agentic Code Scanning in the Cycode platform caught both authorization CVEs in benchmark testing that no rule engine could express. New Attack Chaining capabilities links related findings into the …
radicaldatascience.wordpress.com
September 1, 2026 at 10:48 PM
Critical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command Execution

A critical flaw (CVSS 9.4) in NASA/JPL’s AIT-GUI let anyone send unauthenticated commands to spacecraft instruments. Cycode researchers found that AIT-GUI, the browser-base…
#hackernews #news
Critical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command Execution
A critical flaw (CVSS 9.4) in NASA/JPL’s AIT-GUI let anyone send unauthenticated commands to spacecraft instruments. Cycode researchers found that AIT-GUI, the browser-based operator console in NASA/JPL open-source AMMOS Instrument Toolkit, shipped with no authentication, no session checks, and no CSRF protection on any of its state-changing endpoints. “AIT-GUI, the web front end of NASA/JPL’s […]
securityaffairs.com
August 23, 2026 at 2:09 PM
NASA/JPL's open-source AIT-GUI, the console operators use to send spacecraft commands, ships with no login and binds to every interface.

Cycode found a page an operator visits can issue commands (CVSS 9.4).

The 2.5.2 fix still adds no auth.
NASA AIT-GUI console has no login (CVSS 9.4), and the 2.5.2 patch still adds no authentication
AIT-GUI, NASA/JPL open-source operator console, binds to every interface with no login (CVSS 9.4). A browser can send commands, and the 2.5.2 fix adds no auth.
suriq.io
August 22, 2026 at 4:19 PM
Security researchers at Cycode disclosed critical flaws in NASA/JPL's AIT-GUI, allowing unauthenticated attackers to issue arbitrary spacecraft commands. Tracked as GHSA-p9r8-2q67-fp86, rated 9.4 CVSS, it affects versions 2.5.1 and earlier, fixed in 2.5.2.
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
thehackernews.com
August 21, 2026 at 6:44 PM
В отворения софтуер на НАСА/JPL за наземни станции е открита критична верига от уязвимости. При определена конфигурация е било възможно външно лице без необходимата оторизация да изпраща команди към свързани устройства и космически апарати, да стартира сценарии и да изпълнява последователности от...
Уязвимости в интерфейса на НАСА са позволявали изпращането на команди към космически апарати без оторизация
В отворения софтуер на НАСА/JPL за наземни станции е открита критична верига от уязвимости. При определена конфигурация е било възможно външно лице без необходимата оторизация да изпраща команди към свързани устройства и космически апарати, да стартира сценарии и да изпълнява последователности от команди, съобщава The Hacker News. Проблемите са открити от изследователя Ювал Елбар от компанията Cycode в AIT-GUI. AIT е отворен набор от инструменти за създаване на наземни системи, които приемат телеметрия и предават команди към космически апарати, научни уреди и CubeSat спътници. AIT-GUI служи като операторски интерфейс за работа с такива системи.
www.kaldata.com
August 21, 2026 at 3:43 PM
NASA’nın Yer Kontrol Yazılımında Kritik Açık: Bilgisayar Korsanları Uzay Araçlarına Erişebilirdi!

Uzay araştırmalarının dev ismi NASA, yazılım tarafında yaşanan beklenmedik bir güvenlik ihlali iddiasıyla siber güvenlik dünyasının gündemine oturdu. Uzay araçlarını yönlendirmek ve bilimsel cihazları…
NASA’nın Yer Kontrol Yazılımında Kritik Açık: Bilgisayar Korsanları Uzay Araçlarına Erişebilirdi!
Uzay araştırmalarının dev ismi NASA, yazılım tarafında yaşanan beklenmedik bir güvenlik ihlali iddiasıyla siber güvenlik dünyasının gündemine oturdu. Uzay araçlarını yönlendirmek ve bilimsel cihazları çalıştırmak için kullanılan özel bir kontrol panelinin, hiçbir şifre veya kimlik doğrulaması olmadan internete açık kaldığı anlaşıldı. Siber güvenlik firması Cycode araştırmacısı Yuval Elbar tarafından fark edilen bu açık, kötü niyetli kişilerin herhangi bir engelle karşılaşmadan sistem üzerinden uzay araçlarına komut göndermesine imkan tanıyordu.
ercanceviz.com.tr
August 21, 2026 at 1:51 PM
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attack…
#hackernews #news
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrument command bus. The chain, tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 on the CVSS v3.1 scoring system, impacts AIT-GUI
thehackernews.com
August 21, 2026 at 4:49 AM
Critical NASA AIT-GUI Flaw Lets Unauthenticated Attackers Issue Spacecraft Commands
Critical NASA AIT-GUI Flaw Lets Unauthenticated Attackers Issue Spacecraft Commands
A critical security flaw in NASA/JPL’s open-source AMMOS Instrument Toolkit GUI (AIT-GUI) could let an unauthenticated attacker send live commands to spacecraft and scientific instruments, run arbitrary scripts, and execute command sequences without ever logging in. Security researcher Yuval Elbar of Cycode disclosed an issue rated 9.4 on the CVSS v3.1 scale on August 13, 2026. This issue has been patched in AIT-GUI version 2.5.2, which was released on August 12, 2026. AIT-GUI is the browser-based operator console for the AMMOS Instrument Toolkit , a widely used open-source framework for building ground data systems that send commands to spacecraft and instruments and process the telemetry that comes back. In practical terms, it is the panel an operator uses to click a button and have that action translated into a real command sent to hardware, which is precisely why a routine web application bug becomes so consequential here. Critical NASA AIT-GUI Flaw According to the advisory , the AIT-GUI web server reads its configured host setting and then silently discards it, hardcoding the listener to bind on 0.0.0.0 across all network interfaces on port 8080 by default. An operator who deliberately restricts the console to localhost still ends up exposing it to the entire reachable network. Compounding that exposure, none of the application’s state-changing endpoints enforce authentication, authorization, or cross-site request forgery (CSRF) protection. The POST /cmd endpoint relays whatever command string it receives directly to the spacecraft command bus, while POST /script/run and POST /seq allow server-side script execution and command-sequence execution, respectively. The latter two endpoints also build filesystem paths from unvalidated user input, opening the door to path traversal outside their intended script and sequence directories. Researchers classified the issues under CWE-306 (missing authentication), CWE-352 (CSRF), and CWE-22 (path traversal). A separately tracked flaw, CVE-2026-60112, describes a related missing-authentication issue in which an attacker can obtain a valid session by calling Sessions.create() without any credential check, then invoke handle_cmd() to forward arbitrary commands straight to the AIT command bus. That CVE carries a CVSS v3.1 base score of 9.8 and was published on July 28, 2026, ahead of the fuller GHSA disclosure. Because the vulnerable endpoints accept standard form-encoded POST requests, they qualify as CORS “simple” requests that browsers deliver cross-origin without a preflight check. That means even a deployment that is firewalled off from the open internet is not necessarily safe: if an operator with browser access to the console simply visits a malicious webpage, that page can silently submit a form that fires commands at the console in the background. No credentials, no user interaction beyond opening a page, and no direct network exposure are required for this attack path to succeed. NASA-AMMOS has fixed the flaw in AIT-GUI 2.5.2, and organizations running the software are strongly urged to upgrade immediately and verify the console port is not reachable from untrusted networks. Cycode’s disclosure also recommends reviewing command and sequence history for any deployment that may have been exposed prior to patching. For teams maintaining or hardening deployments, the durable fixes include adding authentication, authorization, and CSRF protections to every state-changing route; binding the server to its configured host rather than the hardcoded 0.0.0.0; and confining script and sequence paths using canonicalization checks that mirror a safeguard already present elsewhere in the codebase on the /scripts/load endpoint. The disclosure underscores a broader lesson for ground systems and operational technology: these platforms inherit the same web application weaknesses seen across ordinary software, but the cost of a successful exploit is measured in real-world hardware actions rather than data breaches. No CVE had been formally assigned to the GHSA advisory at the time of writing, though a related CVE-2026-60112 has already been logged in the National Vulnerability Database. Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs:  Integrate TI Lookup in your SOC The post Critical NASA AIT-GUI Flaw Lets Unauthenticated Attackers Issue Spacecraft Commands appeared first on Cyber Security News .
cybersecuritynews.com
August 20, 2026 at 3:39 PM