Cycode researcher Yuval Elbar found an unauthenticated command execution flaw in NASA/JPL's AIT-GUI, which was picked up by The Hacker News.
Public source
Publisher name
Public post
This Week in Agentic Development Security. Your Weekend Reads from Cycode. Here's the roundup: → Agentic Code Scanning: this week we've officially launched Cycode's Agen…
Company
Cycode
Agentic Development Security
- Industry
- Computer and Network Security
- Location
- New York, US
- Company size
- 51–200 employees
About Cycode
Cycode is the only Complete Agentic Development Security Platform, securing AI development from prompt to runtime. Unlike standalone models and frontier lab tooling that only run when invoked on their own, Cycode is Always-On™. By unifying control, context, and autonomy in a single platform, with ADLC Security built in, Cycode continuously identifies risk across the AI development lifecycle, governs the AI tools developers use, correlates context across the entire software factory, and deploys and manages agents that prevent risk at AI speed. Global enterprises, including many of the world's largest Fortune 500s across Finance, Retail, Manufacturing, and software including multiple Anthropic Mythos launch partners trust Cycode. We are proud to be ranked #1 for the Software Supply Chain Security use case in Gartner's 2025 Critical Capabilities for Application Security Testing, recognized as a Leader in the IDC MarketScape: Worldwide ASPM 2025 Vendor Assessment, and named a Leader in the 2025 Frost Radar™ for Application Security Posture Management.
See moreLatest activity
Latest activity from Cycode
17 signals
Products & Services
Cycode published the latest edition of its newsletter featuring top stories on Agentic Code Scanning, agent blast radius, and a converged platform beating ten point tools.
Research & Knowledge
Cycode ran tests to determine the performance and cost of deterministic SAST, rules-based engines, and agentic code scanning.
Research & Knowledge
Cycode published Five AI security maturity models compared side-by-side for teams figuring out where they stand before picking a framework.
Discover more
Similar signals
Similar public activity from other companies.
Research & Knowledge
Lineaje
Lineaje published a research paper titled AI TAR VIDEO: An AI coding agent turned a routine repository read into a secret exfiltration pipeline — no jailbreak required, just the privilege it already had.
Research & Knowledge
Veracode
Veracode published its 2026 State of Software Security research finding that 82% of organizations carry security debt, up from 74% the previous year.
Research & Knowledge
DeepGuards
DeepGuards published three ServiceNow CVSS 10.0 findings that could allow unauthenticated code execution and SQL access.
Research & Knowledge
StepSecurity
StepSecurity published a case study written by Udi-Yehuda Tamar, VP of Platform Engineering and Global CISO at Checkmarx.
Research & Knowledge
Anchore