#DevSecOps
48 stories taggedDevSecOps.

AI Coding Assistants Are Pulling in Open Source Packages Faster Than Anyone Can Check Them
Developers using AI helpers are importing software libraries at machine speed. Security teams built for human review can't keep up, and dodgy code is slipping through.

The software wrapper around your AI agent is the real security risk
Researchers broke into official AI automation tools from Anthropic, Google, and OpenAI, not by tricking the AI itself, but by exploiting the ordinary code that connects it to the real world.

Your GitHub activity logs are a smoke detector you forgot to switch on
Two researchers showed at Black Hat USA 2026 that the evidence needed to catch software supply-chain attacks has been sitting inside GitHub all along. Their open-source tool turns that evidence into working alerts.

When Developers Ship 50x More Code, Security Becomes the Traffic Jam
AI coding assistants are pumping out software at a pace human security teams were never built to match. The real question is not whether bugs slip through, but whether anyone still knows what got shipped.

Open source grew up in a hurry, and the security bill is coming due
The world runs on free code written by strangers. That model is finally hitting its limits, and everyone using cloud services is exposed.

The Week's Attacks Were Cheap, Ordinary, and Very Effective
Opening a repo, installing a package, or previewing a PDF was enough to hand attackers a foothold this week. None of it was sophisticated. All of it worked.

Tel Aviv Security Firm Oligo Raises $60 Million to Catch Hackers in the Act
Oligo Security has now raised $140 million total to build software that watches running apps in real time and blocks attacks the moment they happen, rather than waiting for a patch.

Google's AI Coding Assistants Could Be Tricked Into Leaking Secrets and Sabotaging Code
A newly exposed attack technique shows how a low-level AI agent inside Google's development toolkit can be manipulated into poisoning a higher-trust agent, giving attackers a path to steal credentials and tamper with software projects.

Why Locking Down What AI Agents Can Do Is Not Enough
A security firm says the real question is not what you told your AI to do. It is how far it can wander if something goes wrong.

Cantina Raises $8 Million to Let AI Agents Hunt and Fix Security Flaws Automatically
A New York startup wants to replace slow, manual vulnerability management with software agents that find problems, investigate them, and patch them without waiting for a human to file a ticket.

AI Security Bots Are Great at Hacking. Terrible at Defence. Researchers Are Trying to Fix That.
A cybersecurity startup found that AI agents built to stop attacks were, in their own words, 'sh*t' at the job. Here is why that gap exists, and what they are doing about it.

Your Security Team Is Flying Blind on AI. Here Is Why.
The tools built to catch hackers and bad code were designed for a world where humans made every decision. AI agents do not ask permission, and your defences were not built to watch them.

AI Smart Glasses Are Walking Into Your Office. Nobody Knows How to Stop Them.
Samsung's entry into AI-powered glasses has forced security leaders to face an uncomfortable truth: the recording device problem is already everywhere, and a ban probably makes things worse.

Your ransomware playbook is probably putting the wrong person in charge at 4 a.m.
A growing body of evidence shows that the real damage in ransomware incidents often comes not from the attack itself, but from who gets to decide whether to pull the plug on a business-critical system.

FedRAMP is scrapping the annual audit. Here's what 20X actually changes.
The old federal cloud approval process runs on PDFs and once-a-year checks. The replacement wants live proof that your controls are working, all the time.