What's Happening?
At Infosecurity Europe, Ox Security emphasized the need for security to be integrated directly into AI coding tools to address risks associated with agentic development. Boaz Barzel, the vendor's field CTO, highlighted that traditional application security methods
are inadequate for the rapid code changes enabled by AI agents. These agents introduce new attack surfaces, including input, tools, execution, and output, which traditional security tools cannot effectively manage. Barzel advocated for embedding security within the building loop, ensuring continuous operation and contextual awareness. This approach aims to reduce mean time to resolve vulnerabilities and ensure comprehensive autonomous security checks for code changes.
Why It's Important?
The integration of security into AI coding tools is crucial as AI agents facilitate hundreds of code changes daily, increasing the potential for vulnerabilities. By embedding security into the development process, organizations can proactively address risks, reducing the time-to-exploit and improving overall cybersecurity resilience. This shift is essential as AI tools generate large volumes of code, potentially introducing vulnerabilities at machine speed without human oversight. The approach proposed by Ox Security could transform security from a reactive department to a proactive system behavior, enhancing the protection of AI-driven applications and reducing the risk of exploitation.
What's Next?
As the industry moves towards agentic development, organizations will need to adopt security measures that are integrated into the AI coding process. This may involve deploying security agents alongside coding agents to ensure continuous monitoring and validation of code changes. The focus will likely be on reducing the time vulnerabilities remain exploitable and increasing the coverage of autonomous security checks. As new agentic coding risks are identified, companies will need to adapt their security strategies to address these challenges, potentially leading to innovations in AI security tools and practices.











