<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>InfoQ - Application Security - News</title>
    <link>https://www.infoq.com</link>
    <description>InfoQ Application Security News feed</description>
    <item>
      <title>GitHub Expands Secret Scanning with General Availability of MCP Server Integration</title>
      <link>https://www.infoq.com/news/2026/05/github-mcp-secret-scanning/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Application+Security-news</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/05/github-mcp-secret-scanning/en/headerimage/generatedHeaderImage-1778422946373.jpg"/&gt;&lt;p&gt;GitHub has announced the general availability of secret scanning support through its MCP Server, extending automated credential detection and remediation capabilities into AI-assisted and agent-driven development workflows.&lt;/p&gt; &lt;i&gt;By Craig Risi&lt;/i&gt;</description>
      <category>github</category>
      <category>Model Context Protocol (MCP)</category>
      <category>Application Security</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Tue, 12 May 2026 12:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/05/github-mcp-secret-scanning/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Application+Security-news</guid>
      <dc:creator>Craig Risi</dc:creator>
      <dc:date>2026-05-12T12:00:00Z</dc:date>
      <dc:identifier>/news/2026/05/github-mcp-secret-scanning/en</dc:identifier>
    </item>
    <item>
      <title>Attacker Bought 30 WordPress Plugins on Flippa and Backdoored All of Them</title>
      <link>https://www.infoq.com/news/2026/05/wordpress-plugins-supply-chain/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Application+Security-news</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/05/wordpress-plugins-supply-chain/en/headerimage/generatedHeaderImage-1777874069748.jpg"/&gt;&lt;p&gt;An attacker purchased 30+ WordPress plugins on Flippa for six figures, planted a PHP deserialization backdoor in the first commit, and waited eight months before activating it across 400,000 installations. The attack used Ethereum smart contracts to resolve C2. WordPress.org has no mechanism for reviewing plugin ownership transfers, a gap that npm and PyPI addressed years ago.&lt;/p&gt; &lt;i&gt;By Steef-Jan Wiggers&lt;/i&gt;</description>
      <category>Software Supply Chain</category>
      <category>Application Security</category>
      <category>Dependency Management</category>
      <category>Security Vulnerabilities</category>
      <category>Development</category>
      <category>Architecture &amp; Design</category>
      <category>news</category>
      <pubDate>Wed, 06 May 2026 10:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/05/wordpress-plugins-supply-chain/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Application+Security-news</guid>
      <dc:creator>Steef-Jan Wiggers</dc:creator>
      <dc:date>2026-05-06T10:00:00Z</dc:date>
      <dc:identifier>/news/2026/05/wordpress-plugins-supply-chain/en</dc:identifier>
    </item>
    <item>
      <title>GitHub Enhances CodeQL with Declarative Security Modeling for Faster, More Flexible Analysis</title>
      <link>https://www.infoq.com/news/2026/05/github-codeql-security-modeling/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Application+Security-news</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/05/github-codeql-security-modeling/en/headerimage/generatedHeaderImage-1777889993931.jpg"/&gt;&lt;p&gt;GitHub has introduced a significant update to its CodeQL engine, enabling developers to define custom sanitizers and validators directly through "models-as-data," a move that simplifies how teams extend security analysis across their codebases.&lt;/p&gt; &lt;i&gt;By Craig Risi&lt;/i&gt;</description>
      <category>CodeQL</category>
      <category>github</category>
      <category>Application Security</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Tue, 05 May 2026 12:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/05/github-codeql-security-modeling/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=Application+Security-news</guid>
      <dc:creator>Craig Risi</dc:creator>
      <dc:date>2026-05-05T12:00:00Z</dc:date>
      <dc:identifier>/news/2026/05/github-codeql-security-modeling/en</dc:identifier>
    </item>
  </channel>
</rss>
