Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Monday, 8 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Black Duck Launches Signal to Tackle the Security Risks of AI-Generated Code

by Guru Writer
March 23, 2026
in AI and Machine Learning, News
Black Duck Launches Signal to Tackle the Security Risks of AI-Generated Code
Share on FacebookShare on Twitter

Black Duck has announced the general availability of Black Duck Signal™, an agentic AI application security solution designed from the ground up to address the security challenges created by AI-native software development. The launch comes as AI coding assistants move from novelty to norm across enterprise software teams. Industry analysts predict that 90% of enterprise developers will be using AI coding tools by 2028, a shift that is fundamentally changing the volume, velocity, and nature of the code hitting production systems. The problem, according to Black Duck, is that the security tools designed to protect that code have not kept pace.

“AI is no longer just accelerating development, it’s actively authoring software,” said Jason Schmitt, CEO of Black Duck. “Signal unlocks AI-driven development by removing risk and bringing intelligence, determinism and governance to that reality.”

A Different Architecture for a Different Problem

Unlike traditional application security testing (AST) tools that rely on language-specific, rule-based scanning engines, Signal is built on an agentic AI architecture. Rather than a single model, it deploys a coordinated system of specialised AI security agents that work together to analyse code, assess the exploitability of vulnerabilities, prioritise risk, and recommend or automatically apply fixes, reasoning through issues with what Black Duck describes as human-like logic.

Central to that intelligence is ContextAI, Black Duck’s purpose-built application security model, trained on petabytes of human-validated security data accumulated over more than two decades. The company argues that this grounding in real-world security expertise is what separates Signal from general-purpose AI security tools: the agents aren’t just pattern-matching against known signatures, they’re drawing on deep contextual knowledge to make informed judgements about risk and remediation.

That distinction matters particularly for the types of vulnerabilities that are hardest to catch; complex, cross-file dataflow issues, business logic errors, and novel defects that don’t match any existing rule or signature. Signal’s multi-model approach means that different agents are applied at different stages of analysis, with Black Duck claiming each is optimised for the task at hand.

Proof in the Wild

Black Duck has pointed to a concrete real-world example to demonstrate Signal’s capabilities. The company’s Cybersecurity Research Center used Signal to identify a previously undisclosed authentication bypass vulnerability in Gitea, the popular open source Git platform, before it was publicly known. The finding, Black Duck says, illustrates Signal’s ability to surface high-impact logic flaws that conventional tools would miss entirely.

Built for Where Code Actually Gets Written

Signal integrates directly into the tools developers already use: AI coding assistants, IDEs, and automated pipelines, via model context protocol (MCP) and APIs. It analyses code continuously as it is written or generated, surfacing issues before they reach a commit rather than flagging them after the fact. Where traditional AST tools are known for high false positive rates that erode developer trust, Signal’s built-in exploitability analysis is designed to filter out non-issues and surface only what genuinely matters.

Because its intelligence is model-driven rather than rule-driven, Signal is also language and framework-agnostic from day one. It requires no rule updates, no language packs, and no tuning, meaning organisations are not left waiting for vendor support to catch up with the latest language features or frameworks used in their AI-generated code.

Governance at AI Scale

Beyond detection, Black Duck frames Signal as an enterprise governance tool. As AI coding assistants increasingly design and deliver production software autonomously, organisations face mounting challenges around security, compliance, and trust. Signal is positioned to give security and engineering leaders the visibility and control they need to govern AI-generated software at scale, without sacrificing the development velocity that AI tools are intended to deliver.

Black Duck Signal is now generally available.

ShareTweet
Previous Post

MIWIC26: Meera Tamboli, Digital Forensics and Incident Response Analyst, AVEVA

Next Post

Routers Replace PCs as Primary Threat Vector in Evolving Device Risk Landscape

Recent News

Frontline Workers Twice as Likely to Use Unapproved AI

Frontline Workers Twice as Likely to Use Unapproved AI

June 4, 2026
Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
data-cloud-security

Building a Digital Fortress: Why Cyber Security Matters More Than Ever

June 5, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol