SendTech Times
News
SYSTEMS SHIFT:

Cycode Adds Agentic Code Scanning to Control AI Review Costs

Newsroom brief

Cycode’s Agentic Code Scanning routes code review between AI and rule-based engines, with benchmark claims covering six CVEs, authorization flaws and MLflow detection volume.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: DeveloperTech
Cycode Adds Agentic Code Scanning to Control AI Review Costs
Image source: DeveloperTech

Cycode has added Agentic Code Scanning to its application-security platform, DeveloperTech reported, using AI routing and attack-path analysis to decide when code review needs a reasoning model instead of a cheaper rule-based scan.

The launch targets a cost and coverage problem created by AI-assisted software security.

Security teams have to choose which model reviews each commit, whether every repository deserves continuous scanning and how to explain to auditors which engine produced a finding.

Cycode’s answer is not a single model, but a system that selects the scanning method for the code path and risk signal in front of it.

The company presents the feature as a fourth dimension of its code-defense approach, alongside three scanning methods already running in production.

All four dimensions examine the same code and reconcile their results into one risk view, with Agentic Code Scanning used where rule matching alone may miss a multi-step vulnerability.

The product builds a cross-file attack chain around related findings instead of treating each alert as isolated.

Cycode’s Context Intelligence Graph adds code-call links, ownership details and reachability data, then directs remediation toward the lowest-cost change that can break the exploit chain.

Those exploitability-qualified findings can also trigger Cycode’s Agentic Workflows.

Teams define the event trigger, action sequence, confidence threshold and control boundary once, after which the workflow routes the issue to the engineer who wrote the code and returns fixes as pull requests validated against the original finding.

Each run leaves an audit trail showing what triggered the agent, what it did and which boundary applied.

Benchmark claims form the most specific part of the launch.

Cycode says the evaluation covered ten repositories and six programming languages, with every repository fixed to the vulnerable commit under test.

The set included six published-CVE applications and four deliberately vulnerable applications with answer keys that the company says were not used for engine tuning.

Cycode says rival tools in the test produced no valid catches across the six published CVEs.

Its deterministic engine found three injection or traversal bugs out of six, while Agentic Code Scanning found all six.

Two of the missed cases were authorization flaws in Gitea and Next.js that no rule engine in the test caught, including Cycode’s own.

The MLflow arbitrary file-read case showed the difference between detection volume and root cause.

A taint rule fired 573 times in that repository, with two hits in the actual CVE file and total findings ranging from 173 to 701 per repository.

Agentic Code Scanning returned one validated, root-caused finding for each CVE.

The test corpus and configurations are being published for reproduction, which gives customers a way to examine the claim beyond a closed vendor benchmark.

The open question for security teams is narrower than whether AI should review code at all: the buying test becomes whether agentic review can catch authorization and path-based vulnerabilities without turning every commit into an unmanaged model-cost event.

These are company-reported benchmark results.

Whether the same detection rate holds across a broader range of repositories, languages or vulnerability classes remains untested in the material released so far.

Share this article
inXf

Related articles

More
OpenAI Agent Website Incidents Put AI Safeguards Under Review
Cybersecurity

OpenAI Agent Website Incidents Put AI Safeguards Under Review

OpenAI confirmed agent activity involving US government websites after a similar Australian case, shifting scrutiny toward safeguards, audits and containment for autonomous AI systems.

MCP Python SDK Fix Closes OAuth Credential Redirect Flaw
Cybersecurity

MCP Python SDK Fix Closes OAuth Credential Redirect Flaw

The official MCP Python SDK has fixed a flaw that could let a malicious server redirect OAuth secrets, authorization codes and PKCE proof keys during AI tool sign-ins.

AI-Assisted SharePoint Chain Reaches Unauthenticated Code Execution
Cybersecurity

AI-Assisted SharePoint Chain Reaches Unauthenticated Code Execution

The Hacker News reported that Rapid7 disclosed a SharePoint exploit chain combining unauthenticated user impersonation with a separate remote-code-execution flaw on on-premises Microsoft servers.

Fleuret AI Raises €4M For Continuous AI Pentesting Platform
Cybersecurity

Fleuret AI Raises €4M For Continuous AI Pentesting Platform

Tech.eu reported that French startup Fleuret AI raised €4 million in pre-seed funding to develop an agentic-AI platform that turns penetration testing into a continuous security process.

AI Agent Hacks Put Legal Liability Gap Before US Lawmakers
Cybersecurity

AI Agent Hacks Put Legal Liability Gap Before US Lawmakers

CyberScoop found lawyers, regulators and senators split over whether existing hacking, consumer protection and state laws can hold AI companies liable when autonomous agents break into outside systems.

GitHub Actions Malware Risk Returned When Old Tags Came Back Online
Cybersecurity

GitHub Actions Malware Risk Returned When Old Tags Came Back Online

Two compromised GitHub Actions were disabled again after old malicious release tags became reachable, reviving CI/CD credential-theft risk tied to Mini Shai-Hulud.

Neo Raises $100M To Control Enterprise AI Software Actions
Cybersecurity

Neo Raises $100M To Control Enterprise AI Software Actions

SecurityWeek reported that Neo emerged from stealth with $100 million for a platform that governs AI agents, MCP servers and software actions across enterprise systems.

ZBT Router Firmware Implants Expose Root-Level Control Risk
Cybersecurity

ZBT Router Firmware Implants Expose Root-Level Control Risk

VulnCheck found three backdoor-like implants in ZBT-made or white-label routers, including 203 exposed DARKLANTERN instances across 22 countries and sinkhole traffic from 392 devices.

Keep Reading

More Stories

Latest
Kepler Targets 2027 Production for HBM Replacement MemoryCloud & Data CentersOct 6, 2026Kepler Targets 2027 Production for HBM Replacement MemoryEE Times reports that Kepler Computing is preparing 3D ferroelectric memory for 2027 production, promising higher capacity and bandwidth per watt while limiting reliance on advanced-node lithography.Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceCapital & PolicyOct 6, 2026Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceYokogawa Engineering Asia has launched a Singapore center focused on OT cyber resilience, training, response planning and recovery coordination for Southeast Asia, Oceania and Taiwan.ClickFix Attack Uses Browser Cache To Hide Malware PayloadCybersecurityOct 6, 2026ClickFix Attack Uses Browser Cache To Hide Malware PayloadMicrosoft Threat Intelligence traced a ClickFix cache-smuggling method that preloads malware into browser caches, then uses file size checks and a pasted Run command to launch later credential-theft stages.VOA Tests Six-Month Startup Buildout Before Funding DecisionsFintech & Digital PaymentsOct 6, 2026VOA Tests Six-Month Startup Buildout Before Funding DecisionsTechCabal’s interview with VOA Venture Partners founder Victoria Olayide Adesanya describes a six-month build programme that lets the firm work inside African financial-infrastructure startups before deciding whether to invest.Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCrypto/Web3Oct 6, 2026Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCoinDesk reported that bitcoin stayed near $86,000 while the U.S. Dollar Index reached about 102.5, with U.S. rate expectations and European political risks strengthening the dollar backdrop.Google Freezes OSS Bug Bounty Reports After AI Submission FloodCybersecurityOct 6, 2026Google Freezes OSS Bug Bounty Reports After AI Submission FloodGoogle has stopped accepting new product vulnerability reports in its OSS VRP after invalid automated submissions swamped reviewers, while older reports and some Cloud VRP routes remain open.GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%Fintech & Digital PaymentsOct 6, 2026GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%A GFT Technologies analysis says AI-linked software documentation can cut maintenance effort and speed developer onboarding when knowledge assets stay synchronized with code changes.Schneider Electric Lines Up $22.6 Billion PTC DealAIOct 5, 2026Schneider Electric Lines Up $22.6 Billion PTC DealSchneider Electric plans to buy PTC in a cash transaction valuing the US engineering software provider’s equity at about $22.6 billion, adding product-lifecycle software to its industrial AI push.Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueCapital & PolicyOct 5, 2026Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueOla Electric founder Bhavish Aggarwal pledged 20 Cr shares to finance his participation in a rights issue that forms part of a larger ₹1,500 Cr fundraising plan.Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseAIOct 5, 2026Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseNatrona County trustees questioned whether teacher AI tools expose student data, even as existing district rules already ban unauthorized generative AI use by students.AMD Prices 256-Core EPYC 9996 At $14,904 For Server BuyersChips & SemiconductorsOct 5, 2026AMD Prices 256-Core EPYC 9996 At $14,904 For Server BuyersTechRadar reports that AMD’s 6th Gen EPYC 9006 “Venice” lineup includes a 256-core EPYC 9996 with 512 threads, 1GB of L3 cache, a 600W default power rating and a $14,904 list price for 1,000-unit orders.New Relic Reports US$18 Million GreenOps Savings After AI CertificationCloud & Data CentersOct 5, 2026New Relic Reports US$18 Million GreenOps Savings After AI CertificationA New Relic company news item carried by iTWire says the observability vendor has earned ISO/IEC 42001 certification, joined the EU AI Pact and reported US$18 million in GreenOps savings from more than 80 engineering initiatives.