Snyk API & Web Released
April 22, 2025

Snyk launched Snyk API & Web, delivering a dynamic application security testing (DAST) solution designed to meet the growing demands of modern and increasingly AI-powered software development.

The successful acquisition and integration of Probely's cutting-edge DAST technology into Snyk’s application security platform is a key milestone in unifying critical AppSec testing techniques into a single Developer Security platform.

Snyk API & Web offers a robust solution for developers and AppSec teams to proactively discover, inventory and secure API vulnerabilities before they become threats.

Snyk API & Web is committed to delivering more than just basic security features. As part of our ongoing development efforts, Snyk is working towards an additional integration enabling AppSec teams to access a centralized view of Web, API, and Code assets all within a single interface. This aims to empower teams with real-time insights, bringing together static application security testing (SAST), software composition analysis (SCA), and DAST findings in one seamless dashboard.

Additionally, Snyk API & Web is planned to include enterprise-grade capabilities through a new Command-Line Interface (CLI) designed for organizations with extensive asset portfolios. This enhancement will allow users to programmatically manage scans, targets, and findings at scale, streamlining workflows and enabling automation across CI/CD pipelines.

Snyk’s commitment to innovation is further exemplified by two groundbreaking features that will expand what’s possible in the DAST market:

- AI-Driven API Testing Engine. Powered by the innovative use of GenAI in this context, Snyk's AI-powered API Security Testing engine will help Snyk modernize the way APIs are tested: to help better map the ever-growing API attack surface and automate the scanning of their vulnerabilities. The engine makes use of a combination of GenAI and traditional AI/ML models to expand Snyk's coverage of critical aspects in OWASP's Top 10 API Security Risks, particularly on issues derived from exploits on business logic, such as OWASP's #1 Risk, BOLA (Broken Object Level Authorization).

- Code-Informed Dynamic Testing. Snyk API & Web is able to correlate static and dynamic analysis for smarter, more accurate vulnerability detection. By extracting critical information directly from code, this feature automatically configures DAST tests, identifies APIs, and generates their specifications to optimize scanning accuracy and efficiency. This unified approach provides comprehensive coverage, ensuring no vulnerability goes unnoticed.

Share this

Industry News

May 27, 2025

AI-fueled attacks and hyperconnected IT environments have made threat exposure one of the most urgent cybersecurity challenges facing enterprises today. In response, Check Point® Software Technologies Ltd.(link is external) announced a definitive agreement to acquire Veriti Cybersecurity, the first fully automated, multi-vendor pre-emptive threat exposure and mitigation platform.

May 27, 2025

LambdaTest announced the launch of its Automation MCP Server, a solution designed to simplify and accelerate the process of triaging test failures.

May 27, 2025

DefectDojo announced the launch of their next-gen Security Operations Center (SOC) capabilities for DefectDojo Pro, which provides both SOC and AppSec professionals a unified platform for noise reduction and prioritization of SOC alerts and AppSec findings.

May 22, 2025

Red Hat announced enhanced features to manage Red Hat Enterprise Linux.

May 22, 2025

StackHawk has taken on $12 Million in additional funding from Sapphire and Costanoa Ventures to help security teams keep up with the pace of AI-driven development.

May 21, 2025

Red Hat announced jointly-engineered, integrated and supported images for Red Hat Enterprise Linux across Amazon Web Services (AWS), Google Cloud and Microsoft Azure.

May 21, 2025

Komodor announced the integration of the Komodor platform with Internal Developer Portals (IDPs), starting with built-in support for Backstage and Port.

May 21, 2025

Operant AI announced Woodpecker, an open-source, automated red teaming engine, that will make advanced security testing accessible to organizations of all sizes.

May 21, 2025

As part of Summer '25 Edition, Shopify is rolling out new tools and features designed specifically for developers.

May 21, 2025

Lenses.io announced the release of a suite of AI agents that can radically improve developer productivity.

May 20, 2025

Google unveiled a significant wave of advancements designed to supercharge how developers build and scale AI applications – from early-stage experimentation right through to large-scale deployment.

May 20, 2025

Red Hat announced Red Hat Advanced Developer Suite, a new addition to Red Hat OpenShift, the hybrid cloud application platform powered by Kubernetes, designed to improve developer productivity and application security with enhancements to speed the adoption of Red Hat AI technologies.

May 20, 2025

Perforce Software announced Perforce Intelligence, a blueprint to embed AI across its product lines and connect its AI with platforms and tools across the DevOps lifecycle.

May 20, 2025

CloudBees announced CloudBees Unify, a strategic leap forward in how enterprises manage software delivery at scale, shifting from offering standalone DevOps tools to delivering a comprehensive, modular solution for today’s most complex, hybrid software environments.