logo
Contrast Northstar brings real-time AI to application security

Contrast Northstar brings real-time AI to application security

Techday NZ12-06-2025
Contrast Security has announced the general availability of its new platform, Northstar, aimed at providing a unified application security experience for development, AppSec, and security operations teams.
The Northstar release introduces features which allow teams to monitor application-layer attacks in real time, mitigate breaches, and remediate vulnerabilities using artificial intelligence within minutes, according to the company.
The Contrast Graph
Central to the platform is the Contrast Graph, which creates a digital twin of an organisation's application and API environment. The Graph maps live attack paths, monitors runtime behaviour, and visualises the connection between vulnerabilities, threats, and system assets to facilitate prioritisation and remediation.
The company states that this live, dynamic context is intended to "eliminate the guesswork that plagues traditional tools" by focusing efforts on actual risk and allowing targeted, automated responses. Contrast's approach combines runtime data, contextual analysis, and AI-enabled auto-remediation in an effort to reduce noise and enable precise responses. Tyler Shields, Principal Analyst at Enterprise Strategy Group, said: "Connecting security operations processes with application security incident and vulnerability detection capabilities is a significant step towards breaking down the silos that exist between developers, application security, and security operations teams. This broad contextual analysis offering lends itself well to advanced AI-based prioritisation and automated remediation, which are the key security outcomes required by security organisations today."
Runtime intelligence
The Northstar release is designed to give Security Operations and AppSec teams a real-time understanding of application-layer threats as they occur. Active vulnerabilities can be auto-remediated with the new Contrast AI functionality, using live context and dynamic risk scoring to support decision making. The unified platform offers different views tailored to specific roles, so that developers can focus on prioritising remediation while SOC teams can identify and act on the most critical threats.
Martha Gamez-Smith, Information Security Officer at Texas Computer Cooperative | Education Service Center, Region 20, commented: "We are excited to see the new features and feel that Contrast is set apart from other competitors, beyond reach. It makes our jobs better and easier. The real data will allow our team to take action more efficiently."
Contrast Northstar pairs runtime intelligence with automation, and aims to streamline how organisations defend software against evolving risks by providing a shared perspective for development, security, and operational teams.
Unified user experience
The new release delivers a visual experience built around the Contrast Graph, providing real-time visibility into attacks, vulnerabilities, and business risks. These views can be tailored for each team and integrated with existing developer, CNAPP, and SIEM tools. The Contrast Graph functions as a live map, helping teams to better understand the relationships between vulnerabilities, threats, and assets to enable collaborative response.
Key features
Northstar features dynamic risk scoring that prioritises vulnerabilities based on their context in production, including architecture, threats, and business risk. The platform unifies Application Detection and Response (ADR) with Application Security Testing (AST), providing shared context for incident and vulnerability correlation. This aims to break down silos between teams and improve the speed and accuracy of threat resolution.
The Contrast AI SmartFix capability utilises Graph data to generate specific remediation plans, write code, create test scripts, and draft pull requests. The Contrast MCP Server makes runtime insights available across environments, supporting future AI-driven use cases.
The Deployment Hub is designed to simplify onboarding and the roll-out of updates across complex environments, helping organisations to deploy protection faster. The Flex Agent streamlines the process of agent deployment and updates, requiring no manual configuration and lessening installation times.
Northstar integrates with established security products such as Splunk, Wiz, and Sumo Logic, and the company says that additional integrations and strategic partnerships will be announced in the coming weeks.
Discussing the release, Jeff Williams, OWASP Founder, and Contrast Security Founder and CTO, said, "Northstar is the culmination of everything we've learned about defending modern software. We didn't just bolt together another set of tools—we reimagined AppSec from first principles. By combining runtime observability, real-time graph context, and AI-powered automation, we built a platform that doesn't just find problems—it understands them, prioritises them, and helps teams fix them fast. This is the platform I've wanted since OWASP's earliest days—one that doesn't just generate alerts, but actually defends the software that powers our world."
The Northstar release is now available to partners and enterprises looking to update their application security programmes via a unified, real-time security operations and remediation toolset. Additional partnerships and integrations are set to follow in the coming weeks.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Farming background handy with rural clients
Farming background handy with rural clients

Otago Daily Times

time4 days ago

  • Otago Daily Times

Farming background handy with rural clients

Selwyn Smith grew up on a Riversdale sheep and beef farm. Heavily influenced by the 1980s era, "which probably dissuaded everyone my age to go and do something different from farming", he chose a career off the land. But his parents remained on the farm, which was now leased out, and it was that ongoing tenure which gave him an understanding of challenges farmers faced, including compliance, regulation, succession and exit, which was to prove very beneficial when dealing with many rural clients, Mr Smith said. Plus there was the hands-on knowledge of farming practices that came with being a farmer's son as he recalled drafting lambs early morning and the school bus going past — "and I wasn't on it". An economics degree at the University of Otago and a postgraduate diploma in financial planning opened the door for Mr Smith to work in capital markets and give personalised investment advice. He started his career at the BNZ bank in Ranfurly, then one of three banks in the town. It was to give him a good grounding and not just in finance. In his first week, local publican Dave Weyer handed him a tam-o'-shanter and informed him he was on a curling team and his job was to bring the flagons of beer to the curling rink in Naseby every Monday. The learning curve of curling was steep, particularly with the sport's "own unique language", but living in the sports-mad Maniototo also meant that a passion for all sport was necessary. The hotel, bank and radio station formed the hub of the community and he could receive a phone call on a Saturday morning from someone at the service station whose eftpos card was not working; there was an expectation he would be able to "fix it on the spot". From there, Mr Smith returned to Dunedin and worked at various branches of the BNZ before shifting to Wellington to continue working for the bank. It was an "outstanding" time and he enjoyed the pace of life in the city. Clients were also busy people who made decisions quickly. But when a job opportunity arose in Dunedin with BNZ private banking, there was a lure to return given his fondness for hunting and fishing in the back country. Following some changes by BNZ in 2018-19, Mr Smith and colleague James Hunter decided they needed to find a new home to support their high-net-worth clients with the right level of research. They saw Jarden as the right fit for them and both resigned about a week before the Covid-19 pandemic hit, an unsettling period as they attempted to find somewhere to start an office under Covid restrictions. Ironically, the challenges of Covid turned into opportunities and allowed them to spend time building a business, getting the platform right and then opening the door to their Vogel St office to past and new clients, Mr Smith said. UK-born Mr Hunter moved to New Zealand with his family when he was 12. Initially, he thought he wanted to be a lawyer and he got into second-year law at the University of Otago but he realised that it was the financial papers he was doing on the side that he particularly enjoyed. Graduating in 2005, he got an entry-level job with BNZ in Wellington and when his now wife got a job opportunity in Sydney just before the Global Financial Crisis, they moved across the Tasman. His first role was with Macquarie Private Bank and he then moved to ANZ, then to CBA Institutional Bank and then CBA private banking. Sydney was a "fantastic" city to live in for a decade but it was also a bit of a rat race and he and his wife decided to return to New Zealand to be closer to family, Mr Hunter said. As both sets of parents were living in Queenstown, Dunedin was a natural fit to move to and also to start a family and Mr Hunter joined BNZ again. Mr Smith said the decision to establish the Jarden, now JBWere, office had paid off. It operated in a city with two very large competitors and its focus had to be unashamedly on high-net-worth investors. The consolidation of the two businesses meant the best parts of both businesses were brought together. JB Were would continue to be a boutique firm that developed bespoke solutions for its clients. A key part of the firm's operating model was the five in the office — him, Mr Hunter, wealth management adviser Tony Conroy, associate adviser Emma Townsend and associate Kate Lilley — focused on client solutions as a team, Mr Smith said. "The working-from-home model wasn't going to suit us very well. It doesn't allow us to grow discussions and solve problems as a team. It's a key part of our operating model to throw ideas around and solve issues where the team can come up with a better solution than one person." They could solve the most complex investment needs and had a large pool of offerings to choose from, but they were not tied to any type of investment. Often, the firm found, as clients moved into retirement, their financial advisers became more important than a solicitor or accountant because ongoing investment advice was needed to ensure that capital lasted. Dunedin born and bred, Emma Townsend started at Jarden five years ago. After studying at Otago Girls' High School and completing a commerce degree in tourism and management at the University of Otago she moved to Australia, where she ended up working for ANZ and got into financial services. Returning to Dunedin for family reasons, she worked initially for Craigs Investment Partners before joining Jarden, where she built some models to help run portfolios. Dealing with clients from all walks of life was the best part of her job and clients she had brought to the firm tended to be women, she said. In the past, it was predominantly men who made financial decisions in relationships and it was nice to see the change, she said. Also Dunedin raised, Tony Conroy initially completed a law degree with the intention of working in court and immediately got on a plane and went to London for four years. He worked in various roles and met his English wife before returning to New Zealand in December 1989, when New Zealand was "in one hell of a recession", Mr Conroy said. He met Mr Smith at BNZ, where he was a private banker for five years. From there, he worked at Forsyth Barr before he was headhunted by Westpac to go into private banking. He phoned Mr Smith when he heard his former colleague had left the bank to congratulate him on his new move and the pair got talking, which eventually led to him joining the new office. JBWere had a good culture and it was entering a new phase and, as Mr Smith put it, every day was a new day in what was a very fast-paced industry.

Palo Alto Networks unveils Cortex Cloud ASPM to block app risks
Palo Alto Networks unveils Cortex Cloud ASPM to block app risks

Techday NZ

time5 days ago

  • Techday NZ

Palo Alto Networks unveils Cortex Cloud ASPM to block app risks

Palo Alto Networks has introduced Cortex Cloud Application Security Posture Management (ASPM), a product designed to prevent security risks from impacting applications before they are deployed. The new Cortex Cloud ASPM module is positioned as a prevention-first solution, blocking vulnerabilities from reaching production environments. According to Palo Alto Networks, the product is intended to give security professionals and developers the ability to identify and address security risks in cloud and AI applications prior to deployment, streamlining the remediation process and reducing associated costs. Prevention-focused approach Cortex Cloud ASPM incorporates an open AppSec partner ecosystem, allowing organisations to aggregate data from various third-party code scanners within a central platform. This integration aims to improve security teams' visibility and enable them to work with their preferred development tools without disruption. Supported partner vendors include Black Duck, Checkmarx, GitLab, HashiCorp, Semgrep, Snyk, and Veracode. This release builds upon the existing Cortex Cloud platform, which previously combined cloud native application protection platform (CNAPP) capabilities with cloud detection and response (CDR) for real-time threat management. Cortex Cloud as a whole is designed to provide protection across the entire application lifecycle, using data that spans code, cloud infrastructure, and security operations centres (SOC). Detailing the organisation's vision, Sarit Tager, Vice President of Product Management at Palo Alto Networks, said: "As AI-generated code compresses application development from months to hours, security must evolve to protect the speed of innovation. Equipped with an industry-leading CNAPP, best-in-class CDR and now prevention-first ASPM, Cortex Cloud delivers the most comprehensive approach to cloud security and automatically stops risks before they reach production with end-to-end visibility across the entire application lifecycle." The integration of ASPM into Cortex Cloud is intended to enhance existing security offerings, enabling organisations to implement preventive controls across development and production environments. Key product features Cortex Cloud ASPM offers several core benefits. The platform is designed to proactively stop risks from progressing into live production environments by enforcing targeted guardrails based on application and business context. A key feature is the correlation of findings from both native security controls and third-party scanning solutions, providing prioritisation of critical and exploitable risks without mandating changes to existing development tools. Automation is another focus area for the product. The platform aims to minimise the need for manual remediation by automating security fixes, allowing both security and development teams to address vulnerabilities efficiently throughout the application lifecycle. Industry perspective Commenting on the challenges in application security, Katie Norton, Research Manager, DevSecOps and Software Supply Chain Security at IDC, said: "Application risks reaching production remain a persistent challenge for security teams and continue to leave organisations exposed. As development speed accelerates, the challenge is not just identifying vulnerabilities but focusing on those that pose real risk. By connecting application security with the live threat landscape, Palo Alto Networks' Cortex Cloud ASPM can help organisations to stop threats faster and operate more efficiently." Palo Alto Networks expects that the solution will allow organisations to streamline their approach to application security posture management, while accommodating the increasing pace of development associated with cloud and AI-driven applications. Availability Cortex Cloud ASPM is currently in early access, with general availability anticipated in the second half of 2025.

Palo Alto upgrades Cortex Cloud to tackle AI-driven code risks
Palo Alto upgrades Cortex Cloud to tackle AI-driven code risks

Techday NZ

time6 days ago

  • Techday NZ

Palo Alto upgrades Cortex Cloud to tackle AI-driven code risks

Palo Alto Networks has launched a new capability aimed at securing applications developed with AI-generated code. The latest addition, part of the Cortex Cloud platform, addresses the growing issue of quality and security lapses introduced by AI in software development. As organisations increasingly adopt AI-driven tools to speed up production, concerns are rising over poorly structured, insecure, or redundant code, sometimes described as "AI slop." These problems can result in application failures, unpredictable outages, and security vulnerabilities that are challenging to detect and resolve, particularly in cloud-native environments. ASPM focus The new module, Cortex Cloud Application Security Posture Management (ASPM), is described as a prevention-first solution, focusing on blocking security risks before deployment rather than remediating problems retrospectively. According to Palo Alto Networks, it automates the identification of potential risks and business impacts without disrupting development workflows, while prioritising serious security concerns over less significant issues. The company also introduced an open AppSec partner ecosystem within Cortex Cloud ASPM, enabling organisations to unify data from prominent third-party application security scanners. Partners include Black Duck, Checkmarx, GitLab, HashiCorp, Semgrep, Snyk and Veracode. This consolidation aims to give security teams a clearer, more comprehensive overview of their code security postures by aggregating both native and third-party insights in a single platform. The integration is designed to avoid the need for developers to switch between tools during their work. The new ASPM expansion builds on the February introduction of Cortex Cloud, a platform that merged Palo Alto Networks' cloud native application protection platform (CNAPP) and cloud detection and response (CDR) features. Customers using Cortex Cloud have access to AI-ready data spanning code repositories, cloud resources, and security operations centres, with the goal of unifying and streamlining security management. Industry perspectives "As AI-generated code compresses application development from months to hours, security must evolve to protect the speed of innovation. Equipped with an industry-leading CNAPP, best-in-class CDR, and now prevention-first ASPM, Cortex Cloud delivers the most comprehensive approach to cloud security and automatically stops risks before they reach production with end-to-end visibility across the entire application lifecycle," said Sarit Tager, Vice President of Product Management at Palo Alto Networks. According to the company, key benefits of Cortex Cloud ASPM include proactive prevention of issues from reaching production, prioritisation of genuine risks by correlating findings across a range of scanners and platforms, and extensive automation to reduce manual intervention by security and development teams. Application and software supply chain security is also a concern for industry analysts. Katie Norton, Research Manager for DevSecOps and Software Supply Chain Security at IDC, commented on the need for focused, efficient security amidst rapid development cycles. She stated, "Application risks reaching production remain a persistent challenge for security teams and continue to leave organizations exposed. As development speed accelerates, the challenge is not just identifying vulnerabilities but focusing on those that pose real risk. By connecting application security with the live threat landscape, Palo Alto Networks' Cortex Cloud ASPM can help organizations to stop threats faster and operate more efficiently." Availability Cortex Cloud ASPM is now in early access and is expected to become generally available in the second half of 2025. The company highlights the role of automated and context-aware security solutions as the pace of development increases and as AI continues to change software production practices within organisations.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store