Kubernetes 1.33 was released today.
Backslash Security announced significant adoption of the Backslash App Graph, the industry’s first dynamic digital twin for application code.
App Graph has been a key driver of the company’s substantial momentum in the past twelve months, quadrupling its revenue and increasing its customer base by 150%.
The Backslash approach is a direct response to the rapid evolution of software development. Today, between 70% and 90% of any given software codebase is comprised of open-source components, while AI-powered coding tools are now generating code at an unprecedented scale and pace. As a result, AppSec teams struggle with legacy SAST and SCA tools designed for older, slower eras of code development. To address these pervasive issues, the Backslash App Graph accurately identifies real-world threats by creating a comprehensive model across the code environment, including both open-source and first-party code. It is a foundational technology that does not rely on third-party open source tools for scanning, nor does it require agents that complicate deployment.
“AI-generated and open-source code have created a Wild West of unprecedented risk, while security teams are stuck with tools designed to tackle yesterday’s problems,” said Shahar Man, CEO and co-founder, Backslash Security. “Application security is at a crossroads, and Backslash is flipping the paradigm with our foundational, digital twin-powered modeling that enables security teams to quickly visualize the issues in their code, understand their impact, and focus on real-world risks – no matter whether they were created by humans or AI.”
“Backslash’s App Graph is an integral part of our AppSec program, helping us prioritize remediation efforts with reachability assessments for dependencies,” said Guy Havusha, VP Security, CISO at monday.com. “It also provides a package upgrade simulator and automatic repository detection, enabling us to maintain our accelerated application delivery pace.”
In contrast to legacy tools, Backslash does not take a line-by-line approach to code analysis, but instead maps the application onto a multi-dimensional App Graph that exposes the connectivity between components of the application. The Backslash App Graph dramatically reduces time to research and remediate vulnerabilities, enabled by several unique capabilities:
■ Triggerability™ analysis, which identifies vulnerabilities that are both reachable and exploitable in non-theoretical, real-world execution.
■ Business Process Impact Analysis, which uses an LLM-driven engine that classifies vulnerabilities according to how they affect business processes – such as shopping cart checkout or user data ingestion.
■ Phantom Package Detection, which uncovers packages that are being used but have not been declared in the manifest file.
■ Predictive Upgrade Simulation, which provides the predicted risk footprint of each fix option, allowing developers to understand in advance the best course of action.
To see Backslash App Graph in action, schedule a demo, or meet the Backslash team at booth ESE-52 at the 2025 RSA Conference in San Francisco from April 28 - May 1, 2025.
Industry News
Docker announced a major expansion of its AI initiative with the upcoming Docker MCP Catalog and Docker MCP Toolkit.
Perforce Software announced the release of its latest platform update for Puppet Enterprise Advanced, designed to streamline DevSecOps practices and fortify enterprise security postures.
Azul announced JVM Inventory, a new feature of Azul Intelligence Cloud designed to address the complexity and risk of migrating off Oracle Java.
LaunchDarkly announced the acquisition of Highlight, a powerful, open source, full-stack application monitoring platform known for its error monitoring, logging, distributed tracing and session replay capabilities.
O’Reilly announced AI Codecon—a groundbreaking virtual conference series dedicated to exploring the rapidly evolving world of AI-assisted software development.
Veracode unveiled new capabilities offering proactive risk mitigation and automated security at enterprise scale.
Snyk launched Snyk API & Web, delivering a dynamic application security testing (DAST) solution designed to meet the growing demands of modern and increasingly AI-powered software development.
Check Point® Software Technologies Ltd. announced that it has ranked as a Leader and the only Outperformer for its Check Point Quantum Security Solutions in GigaOm’s latest Radar for Enterprise Firewall report.
Postman announced new releases designed to help organizations build APIs faster, more securely, and with less friction.
SnapLogic announced AgentCreator 3.0, an evolution in agentic AI technology that eliminates the complexity of enterprise AI adoption.
GitLab announced the general availability of GitLab Duo with Amazon Q.
Perforce Software and Liquibase announced a strategic partnership to enhance secure and compliant database change management for DevOps teams.
Spacelift announced the launch of Saturnhead AI — an enterprise-grade AI assistant that slashes DevOps troubleshooting time by transforming complex infrastructure logs into clear, actionable explanations.
CodeSecure and FOSSA announced a strategic partnership and native product integration that enables organizations to eliminate security blindspots associated with both third party and open source code.