René's URL Explorer Experiment


Title: Security Where It Matters: Runtime Context and AI Fixes Now Integrated in Your Dev Workflow | Microsoft Community Hub

Open Graph Title: Security Where It Matters: Runtime Context and AI Fixes Now Integrated in Your Dev Workflow | Microsoft Community Hub

Description: Security teams and developers face the same frustrating cycle: thousands of alerts, limited time, and no clear way to know which issues matter most....

Open Graph Description: Security teams and developers face the same frustrating cycle: thousands of alerts, limited time, and no clear way to know which issues matter most....

Mail addresses
?body=page.url
?body=page.url

Opengraph URL: https://techcommunity.microsoft.com/blog/appsonazureblog/security-where-it-matters-runtime-context-and-ai-fixes-now-integrated-in-your-de/4470794

direct link

Domain: aka.ms


Hey, it has json ld scripts:
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"item":"https://techcommunity.microsoft.com","name":"Microsoft Community Hub"},{"@type":"ListItem","position":2,"item":"https://techcommunity.microsoft.com/category/communities","name":"Communities"},{"@type":"ListItem","position":3,"item":"https://techcommunity.microsoft.com/category/products-services","name":"Products"},{"@type":"ListItem","position":4,"item":"https://techcommunity.microsoft.com/category/Azure","name":"Azure"},{"@type":"ListItem","position":5,"item":"https://techcommunity.microsoft.com/category/Azure/blog/AppsonAzureBlog","name":"Apps on Azure Blog"}]}
{"@context":"https://schema.org","@type":"BlogPosting","datePublished":"11/18/2025, 4:04:11 PM","description":"Security teams and developers face the same frustrating cycle: thousands of alerts, limited time, and no clear way to know which issues matter most. Applications suffer attacks as quickly as once every three minutes,1 emphasizing the importance of proactive security that prioritizes critical, exploitable vulnerabilities. Microsoft is leading this shift with new integrations in the end-to-end solution that combines GitHub Advanced Security’s developer-first application security tool with Microsoft Defender for Cloud's runtime protection, enhanced by agentic remediation. Now available in public preview.\nThis integration empowers organizations to secure code to cloud and accelerates tackling of security issues in their software portfolio using agentic remediation and runtime context-based vulnerability prioritization. The result: fewer distractions, faster fixes, better collaboration and more proactive security from code to cloud.\nThe DevSecOps Dilemma— too many alerts, not enough action\nOver the past decade, the application security industry has made significant strides in improving detection accuracy and fostering collaboration between security teams and developers. These advances have enabled both groups to work together on real issues and drive meaningful progress. However, despite these improvements, remediation trends across the industry have remained stagnant. Quarter after quarter, year after year, vulnerability counts continue to rise with critical / high vulnerabilities constituting 17.4% of vulnerability backlogs and a mean-time-to-remediation (MTTR) of 116 days2\nToday, three big challenges slow teams down:\n\nSecurity teams are drowning in alert fatigue, struggling to distinguish real, exploitable risks from noise. At the same time, AI is rapidly introducing new threat vectors that defenders have little time to research or understand—leaving organizations vulnerable to missed threats and evolving attack techniques.\nDevelopers lack clear prioritization while remediation takes long, so they lose time fixing issues that may never be exploited. Remediation cycles are slow, leaving systems exposed to potential attacks while teams debate which issues matter most or search for the right person to fix them \nBoth teams rely on separate, non-integrated tools, making collaboration slow and frustrating. Development and security teams frequently operate in silos, reducing efficiency and creating blind spots.\n\nThis leads to wasted time, unresolved threats, and growing backlogs. Teams are stuck reacting to noise instead of solving real problems.\nDevSecOps reimagined in the era of AI\nYour app is live and serving thousands of customers. Defender for Cloud detects a vulnerability in an internet-facing API that handles sensitive data. In the past, this alert would age  in a dashboard while developers worked on unrelated fixes because they didn’t know this was the critical one.\nNow, with the new integration, a security campaign can be created in GitHub filtering for runtime risk (internet exposed, sensitive data etc.) notifying the developer to prioritize this issue. The developer views the issue in their workflow, understands why it matters, and uses Copilot Autofix to apply an AI-suggested fix in minutes.\nThe developer can then select these risks at bulk and assign the GitHub Copilot coding agent to create a draft PR for a multi merge fix ready for human review.\n\nVirtual Registry: Code-to-Runtime Mapping\nCode to runtime mapping is possible with the Virtual Registry which makes GitHub a trusted source for artifact metadata. Integrated with Microsoft Defender for Cloud, the Virtual Registry enables smarter risk prioritization and faster incident response.\nTeams can quickly answer:\n\nIs this vulnerability running in production?\nIs it exposed to sensitive workloads?\nDo I need to act now?\n\nBy combining runtime and repository context, the Virtual Registry streamlines alert triage and incident response. We shipped a new set of filters to both Code Scanning and Dependabot and Security Campaigns that are based on the artifact metadata that is stored in the Virtual Registry.\nFaster fixes with agentic remediation\nThe integration includes Copilot Autofix, an AI-powered tool that suggests code changes to fix security problems. It checks that the fixes work and helps developers resolve issues quickly, without switching tools.\nTo complete the agentic work flow we can be bulk assign these autofixes to GitHub Copilot Coding agent to create a draft Pull Request awaiting human review.\nWhy this matters\n\nFewer alerts to sort through: Focus only on what’s exploitable in production.\nFaster fixes: AI-powered fix suggestions through GitHub Copilot Autofix have shown to fix 50% of alerts within the PR with a 70% reduction in mean time-to-remediation3\nBetter teamwork: Developers and security teams collaborate seamlessly. With collaborative security now powered by connected context, we’ve seen 68% of alert remediated using GitHub Advanced Security’s security campaigns.3\n\n\nTry it now\nThis feature is available in public preview and will be showcased at Microsoft Ignite. If your team builds cloud-native applications, this integration helps you protect code to cloud more effectively—without slowing down development.\nCustomer FAQs\nHow do I start using the integration?\nFrom Microsoft Defender for Cloud:\n\nGo to the environment section in the Defender for Cloud portal.\nGrant a new GitHub connector or update an existing one to provide consent to scan your source code.\nIf you use GitHub, setup is one click. You’ll immediately see initial scan results and recommended fixes.\n\nFrom GitHub:\n\nYou will be able to filter alerts by runtime context   in addition to receiving  AI-suggested fixes.\n\nHow do I purchase this integration?\nFor GitHub:\n\nGitHub Advanced Security (GHAS) is available as:\n\nCode Security SKU: $30 per committer/month (available April 2025)\nGHAS Bundle: $49 per committer/month (available now)\n\nGitHub Enterprise Cloud\nGitHub Copilot\n\nFor Microsoft Defender for Cloud CSPM:\nDefender CSPM: $5 per billable resource/month\n\nBoth can be enabled through the Azure Portal as Azure meters.\n\n \n[1]: Software Under Siege | AppSec Threat Report 2025 | Contrast Security\n[2]: Edgescan | Vulnerability Statistics Report 2025\n[3]: GitHub Internal Data","mainEntityOfPage":{"@type":"WebPage","@id":"https://techcommunity.microsoft.com/blog/appsonazureblog/security-where-it-matters-runtime-context-and-ai-fixes-now-integrated-in-your-de/4470794"},"headline":"Security Where It Matters: Runtime Context and AI Fixes Now Integrated in Your Dev Workflow","image":["https://techcommunity.microsoft.com/t5/s/gxcuf89792/images/bS00NDcwNzk0LWpMU1ZYaQ?revision=6"],"dateModified":"11/18/2025, 3:00:47 PM","author":{"@type":"Person","name":"AndrewMFlick","url":"https://techcommunity.microsoft.com/t5/s/gxcuf89792/images/dS0xMjQ0ODU4LXpYSjF5TA?image-coordinates=0%2C0%2C128%2C128"},"publisher":{"@type":"Organization","name":"TECHCOMMUNITY.MICROSOFT.COM"}}

twitter:cardsummary_large_image
og:typearticle
article:modified_time2025-11-18T07:00:47.718-08:00
og:imagehttps://techcommunity.microsoft.com/t5/s/gxcuf89792/images/bS00NDcwNzk0LWpMU1ZYaQ?revision=6
og:image:width1920
og:image:height821
og:site_nameTECHCOMMUNITY.MICROSOFT.COM

Links:

Skip to contenthttps://aka.ms/SecureCodetoCloudBlog#main-content
https://aka.ms/
Tech Communityhttps://aka.ms/
Community Hubshttps://aka.ms/Directory
Productshttps://aka.ms/
Topicshttps://aka.ms/
Blogshttps://aka.ms/Blogs
Eventshttps://aka.ms/Events
Skills Hubhttps://aka.ms/category/skills-hub
Communityhttps://aka.ms/
Registerhttps://aka.ms/t5/s/gxcuf89792/auth/oidcss/sso_login_redirect/provider/default?referer=https%3A%2F%2Ftechcommunity.microsoft.com%2Fblog%2Fappsonazureblog%2Fsecurity-where-it-matters-runtime-context-and-ai-fixes-now-integrated-in-your-de%2F4470794
Sign Inhttps://aka.ms/t5/s/gxcuf89792/auth/oidcss/sso_login_redirect/provider/default?referer=https%3A%2F%2Ftechcommunity.microsoft.com%2Fblog%2Fappsonazureblog%2Fsecurity-where-it-matters-runtime-context-and-ai-fixes-now-integrated-in-your-de%2F4470794
Microsoft Community Hubhttps://aka.ms/
Communitieshttps://aka.ms/category/communities
Productshttps://aka.ms/category/products-services
Azurehttps://aka.ms/category/azure
Apps on Azure Bloghttps://aka.ms/category/azure/blog/appsonazureblog
https://aka.ms/users/andrewmflick/1244858
AndrewMFlickhttps://aka.ms/users/andrewmflick/1244858
Software Under Siege | AppSec Threat Report 2025 | Contrast Securityhttps://www.contrastsecurity.com/software-under-siege-2025-report
Edgescan | Vulnerability Statistics Report 2025https://www.edgescan.com/stats-report/
application modernizationhttps://aka.ms/tag/application%20modernization?nodeId=board%3AAppsonAzureBlog
devopshttps://aka.ms/tag/devops?nodeId=board%3AAppsonAzureBlog
modern appshttps://aka.ms/tag/modern%20apps?nodeId=board%3AAppsonAzureBlog
https://aka.ms/users/andrewmflick/1244858
AndrewMFlickhttps://aka.ms/users/andrewmflick/1244858
View Profilehttps://aka.ms/users/andrewmflick/1244858
https://aka.ms/category/azure/blog/appsonazureblog
Apps on Azure Blog https://aka.ms/category/azure/blog/appsonazureblog
https://www.linkedin.com/sharing/share-offsite/?url=page.url
https://www.facebook.com/share.php?u=page.url&t=page-name
https://twitter.com/share?text=page-name&url=page.url
https://www.reddit.com/submit?url=page.url&title=page-name
https://bsky.app/intent/compose?text=page-name%21%20%F0%9F%A6%8B%0Apage.url
https://aka.ms/t5/s/gxcuf89792/rss/Community
Surface Pro 9 https://www.microsoft.com/en-us/d/surface-pro-9/93VKD8NP4FVK
Surface Laptop 5https://www.microsoft.com/en-us/d/surface-laptop-5/8XN49V61S1BN
Surface Studio 2+https://www.microsoft.com/en-us/d/surface-studio-2plus/8VLFQC3597K4
Surface Laptop Go 2https://www.microsoft.com/en-us/d/surface-laptop-go-2/8PGLPV76MJHN
Surface Laptop Studiohttps://www.microsoft.com/en-us/d/surface-laptop-studio/8SRDF62SWKPF
Surface Duo 2https://www.microsoft.com/en-us/d/surface-duo-2/9408KGXP4XJL
Microsoft 365https://www.microsoft.com/microsoft-365
Windows 11 appshttps://www.microsoft.com/windows/windows-11-apps
Account profilehttps://account.microsoft.com/
Download Centerhttps://www.microsoft.com/en-us/download
Microsoft Store supporthttps://go.microsoft.com/fwlink/?linkid=2139749
Returnshttps://go.microsoft.com/fwlink/p/?LinkID=824764&clcid=0x409
Order trackinghttps://account.microsoft.com/orders
Virtual workshops and traininghttps://www.microsoft.com/en-us/store/workshops-training-and-events?icid=vl_uf_932020
Microsoft Store Promisehttps://www.microsoft.com/en-us/store/b/why-microsoft-store?icid=footer_why-msft-store_7102020
Flexible Paymentshttps://www.microsoft.com/en-us/store/b/payment-financing-options?icid=footer_financing_vcc
Microsoft in educationhttps://www.microsoft.com/en-us/education
Devices for educationhttps://www.microsoft.com/en-us/education/devices/overview
Microsoft Teams for Educationhttps://www.microsoft.com/en-us/education/products/teams
Microsoft 365 Educationhttps://www.microsoft.com/en-us/education/buy-license/microsoft365
Education consultation appointmenthttps://www.microsoft.com/en-us/store/b/business-consultation?tab=educationconsultation&icid=CNavfooter_educationconsultation
Educator training and developmenthttps://education.microsoft.com/
Deals for students and parentshttps://www.microsoft.com/en-us/store/b/education
Azure for studentshttps://azure.microsoft.com/en-us/free/students/
Microsoft Cloudhttps://www.microsoft.com/en-us/microsoft-cloud
Microsoft Securityhttps://www.microsoft.com/en-us/security
Dynamics 365https://dynamics.microsoft.com/en-us/
Microsoft 365https://www.microsoft.com/en-us/microsoft-365/business/
Microsoft Power Platformhttps://powerplatform.microsoft.com/en-us/
Microsoft Teamshttps://www.microsoft.com/en-us/microsoft-teams/group-chat-software
Microsoft Industryhttps://www.microsoft.com/en-us/industry
Small Businesshttps://www.microsoft.com/en-us/store/b/business?icid=CNavBusinessStore
Azurehttps://azure.microsoft.com/en-us/
Developer Centerhttps://developer.microsoft.com/en-us/
Documentationhttps://learn.microsoft.com/docs/
Microsoft Learnhttps://learn.microsoft.com/
Microsoft Tech Communityhttps://techcommunity.microsoft.com/
Azure Marketplacehttps://azuremarketplace.microsoft.com/en-us/
AppSourcehttps://appsource.microsoft.com/en-us/
Visual Studiohttps://visualstudio.microsoft.com/
Careershttps://careers.microsoft.com/
About Microsofthttps://www.microsoft.com/en-us/about
Company newshttps://news.microsoft.com/
Privacy at Microsofthttps://privacy.microsoft.com/en-us
Investorshttps://www.microsoft.com/investor/default.aspx
Diversity and inclusionhttps://www.microsoft.com/en-us/diversity/
Accessibilityhttps://www.microsoft.com/en-us/accessibility
Sustainabilityhttps://www.microsoft.com/en-us/sustainability/
California Consumer Privacy Act (CCPA) Opt-Out IconYour Privacy Choiceshttps://aka.ms/yourcaliforniaprivacychoices
Sitemaphttps://www.microsoft.com/en-us/sitemap1.aspx
Contact Microsofthttps://support.microsoft.com/contactus
Privacy https://go.microsoft.com/fwlink/?LinkId=521839
Manage cookiesjavascript:manageConsent();
Terms of usehttps://go.microsoft.com/fwlink/?LinkID=206977
Trademarkshttps://go.microsoft.com/fwlink/?linkid=2196228
Safety & ecohttps://go.microsoft.com/fwlink/?linkid=2196227
About our adshttps://choice.microsoft.com
Share on LinkedInhttps://www.linkedin.com/sharing/share-offsite/?url=page.url
Share on Facebookhttps://www.facebook.com/share.php?u=page.url&t=page-name
Share on Xhttps://twitter.com/share?text=page-name&url=page.url
Share on Reddithttps://www.reddit.com/submit?url=page.url&title=page-name
Share on Blueskyhttps://bsky.app/intent/compose?text=page-name%21%20%F0%9F%A6%8B%0Apage.url
Share on RSShttps://aka.ms/t5/s/gxcuf89792/rss/Community

Viewport: width=device-width

Robots: index,follow


URLs of crawlers that visited me.