Mend.io strengthens application security with AI runtime protection and faster zero-day response

Applications of AI


Mend.io announced new capabilities across Mend AI and Mend AppSec that enable organizations to quickly respond to both application risks and the expanded attack surface created by AI. Mend.io’s latest enhancements help teams identify critical risks, reduce manual investigations, accelerate response, and extend protection from development to operations.

As development accelerates, security teams face increasing risks, including an increasing amount of vulnerabilities, zero-days, software supply chain threats, and new risks posed by AI-powered applications. Today’s AppSec teams can no longer focus solely on securing pre-production, but increasingly need to extend to runtime as well. Mend.io specifically enhances its services to enable organizations to:

  • Please check the important things: Connect applications, dependencies, and AI risks directly to business-critical systems.
  • Fix what matters faster. Accelerate remediation with agent triage, actionable guidance, and rapid zero-day impact analysis.
  • Protect with confidence: Secure AI runtime operations and detect malicious packages at scale across containerized environments.

“AI is accelerating software development at an unprecedented pace, but it is also changing the amount and nature of risk that security teams must manage,” said Asaf Saar, VP and Chief Product Officer at Mend.io.

“Organizations need to quickly understand what actually impacts their applications, respond to new threats as they emerge, and protect an entirely new AI application attack surface. Mend.io brings these capabilities together to help security teams focus on what matters, remediate faster, and protect the applications they run.”

New features include:

  • Zero-day response acceleration. Improved zero-day processes allow organizations to quickly identify where newly disclosed vulnerabilities impact an application’s attack surface, trace vulnerabilities to underlying code and dependencies, and provide remediation guidance. This allows teams to prioritize responses based on the impact on actual applications, rather than treating every new vulnerability as an organization-wide emergency.
  • Mend AI extends security for AI applications to runtime. AI Agent Configuration Risk scans agent configuration files for prompt injection, command execution, compromised credentials, data leakage, excessive privileges, and policy bypass. Mend AI runtime protection also adds real-time guardrails that can be deployed in-app or via standalone proxies/APIs to inspect prompt injections, jailbreaks, sensitive data leaks, sensitive information leaks, and insecure content prompts and responses. Both extend Mend AI’s discovery, AI-BOM, model risk, system prompt enrichment, and red teaming across the entire AI lifecycle.
  • Mend AppSec SAST reduces the manual effort required to validate results. Agent SAST triage helps distinguish between true vulnerabilities and false positives and provides explanations and context for exploitation, allowing security teams to focus investigation and remediation on actionable findings. Mend.io’s Context Project Classification uses characteristics such as sensitive data and critical functionality to improve SAST prioritization.
  • Mend AppSec SCA expands container risk coverage. It helps identify malicious open source packages in container images, extending visibility into software supply chain risks alongside analysis of existing vulnerabilities and dependencies.

Additional AI-powered features are coming soon. AI-based detection applies AI inference to SAST vulnerability detection where broader application context is important. The Mend Intelligent Agent also helps security teams investigate and act on application security data more efficiently.

The new capabilities announced today are already helping security teams scale application security programs without adding complexity, providing deeper context for risks, accelerating response, and helping organizations protect evolving applications.

“Mend.io has been working with us for years, long before AI security existed, when application security was primarily SAST and SCA,” said Alen Pešikan, principal software engineer at Span Software and AI Solutions.

“Mend.io has now allowed us to grow our program to address the risks that AI poses to the generated code and the AI components themselves. Mend.io provides visibility into models, agents, prompts, and frameworks to help you prioritize what matters most to your business.SPAN We can respond to changing attack surfaces without overwhelming our teams. We can see where we’re at risk, focus our resources where it matters, and respond quickly to changing conditions.”



Source link