"Security, development, and AI now move as one," says Microsoft's director of cloud/AI security
product marketing.
Microsoft and GitHub "have launched a native integration between Microsoft Defender for Cloud and GitHub Advanced Security that aims to address what one executive calls decades of accumulated security debt in enterprise codebases..." according to The New Stack:
The integration, announced this week in San Francisco at the
Microsoft
Ignite 2025 conference and now available in public preview,
connects runtime intelligence from production environments directly
into developer workflows. The goal is to help organizations
prioritize which vulnerabilities actually matter and use AI to fix
them faster. "Throughout my career, I've seen vulnerability
trends going up into the right. It didn't matter how good of a
detection
engine and how accurate our detection engine was, people just
couldn't fix things fast enough," said Marcelo
Oliveira, VP of product management at GitHub, who has spent
nearly a decade in application security. "That basically resulted
in decades of accumulation of security debt into enterprise code
bases." According to industry data, critical and high-severity
vulnerabilities constitute 17.4% of security backlogs, with a mean
time to remediation of 116 days, said Andrew
Flick, senior director of developer services, languages and tools
at Microsoft, in a blog
post. Meanwhile, applications face attacks as frequently as once
every three minutes, Oliveira said.
The integration represents the first native link between runtime
intelligence and developer workflows, said Elif
Algedik, director of product marketing for cloud and AI security
at Microsoft, in a blog
post... The problem, according to Flick, comes down to three
challenges: security teams drowning in alert fatigue while AI rapidly
introduces new threat
vectors that they have little time to understand; developers ...
[>>>]