[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fMcok0zRWw--W3nkInGd5oqO5V3lOwLQtjW38btg2UL4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":46},"18977d9e-cdda-4f73-a432-9f6ff7ce2b53","ai-coding-environments-need-embedded-security-scanning","0efe72c7-7ef5-490f-a0fc-0e1d06d91040","AI Coding Environments Need Embedded Security Scanning","As AI-assisted development accelerates code output, security checks risk being bypassed or delayed, introducing vulnerabilities at scale before they are ever reviewed. Black Duck's Signal integration into Claude Desktop addresses the critical gap of 'shift-left' security by embedding scanning directly into the AI coding workflow via the Model Context Protocol (MCP). This matters because developers using AI tools may implicitly trust generated code, reducing manual scrutiny. Without automated, in-context security feedback, the speed advantage of AI coding can become a liability, rapidly propagating flawed or vulnerable code into production. Third-party integrations into AI platforms also introduce supply chain considerations that security teams must evaluate.","**Immediate actions:**\n- Audit all AI coding tools and plugins in use across the development team to identify gaps in integrated security scanning coverage.\n- Enable or mandate approved security scanning integrations (such as SAST\u002FSCA tools) within AI-assisted development environments before code is committed.\n\n**Long-term improvements:**\n- Establish a formal policy requiring security tool vetting before any third-party MCP or AI plugin integration is approved for developer use.\n- Incorporate AI-generated code into existing secure software development lifecycle (SSDLC) processes, including mandatory vulnerability scanning gates in CI\u002FCD pipelines.\n- Train developers on the risks of over-trusting AI-generated code and the importance of security review regardless of the code's origin.\n\n**Detection measures:**\n- Monitor AI coding tool integrations for changes in plugin versions or data-sharing behaviors that could introduce supply chain risk.\n- Track vulnerability findings from in-IDE scanning tools centrally to identify recurring weakness patterns introduced via AI-assisted development.",[12,13,14,15,16,17,18,19],"CIS Control 16 – Application Software Security","CIS Control 18 – Penetration Testing","NIST SP 800-218 (SSDF) – Secure Software Development Framework","NIST SA-11 – Developer Testing and Evaluation","NIST SA-15 – Development Process, Standards, and Tools","OWASP SAMM – Security Testing Practice","ISO\u002FIEC 27001 – A.14.2 Security in Development and Support Processes","SLSA Supply Chain Levels for Software Artifacts – Level 2+ provenance requirements","published","2026-09-02T18:21:24.00714+00:00","2026-09-02T18:21:23.906+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fwww.itsecurityguru.org\u002F2026\u002F09\u002F02\u002Fblack-duck-brings-ai-powered-vulnerability-scanning-into-claude-with-new-signal-integration\u002F?utm_source=rss&utm_medium=rss&utm_campaign=black-duck-brings-ai-powered-vulnerability-scanning-into-claude-with-new-signal-integration","black-duck-brings-ai-powered-vulnerability-scanning-into-claude-with-new-signal--0efff2","Black Duck brings AI-powered vulnerability scanning into Claude with new Signal integration",[28,34,40],{"id":29,"name":30,"slug":31,"description":32,"color":33},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":35,"name":36,"slug":37,"description":38,"color":39},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":41,"name":42,"slug":43,"description":44,"color":45},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]