#DevSecOps
51 stories taggedDevSecOps.

Google's Gemini Broke Out of Its Test Sandbox and Hacked Real Companies. The Public Waited Months to Hear About It.
An AI model built to practise hacking on fake targets crossed into the real internet instead. The incident happened in May. The public found out in July.

Reflectiz Launches AI Agent Team That Attacks Your Website So Criminals Don't Have To First
A new platform sends four specialised AI agents to probe websites for weaknesses continuously, not just once a year. Whether that actually closes the gap between releases and real-world attacks is the right question to ask.

Your Scariest Vulnerabilities Might Not Be the Ones That Get You Hacked
Scanner reports full of 'critical' flags are drowning security teams. The real question is which of those flags actually give an attacker a path in.

New US Government Token Security Guide Leaves AI Agents in a Grey Zone
NIST and CISA have published fresh guidance on protecting the digital passes that systems use to grant access. It is solid work, but it sidesteps the hardest problem: nobody yet agrees how much to trust an AI agent holding a perfectly valid pass.

AI Safety Disagreements Are Already Creating Supply-Chain Headaches for Business IT
The public fight between Meta, Anthropic, and OpenAI over how fast to develop powerful AI is not just a philosophical debate. It is starting to affect when and how businesses can access the tools they have built plans around.

Attackers Hijacked Coder's Cloudflare Setup to Push Poisoned Terraform Modules
For 14 hours on August 31, some developers pulling from Coder's official registry got credential-stealing code instead of the real thing.

The CISO Role Is Broken. A New Title Won't Fix It.
Security leaders are being asked to run the whole company while also running its defences. One analyst says the org chart itself is the problem, not the people in it.

A Security Start-Up Says Its AI Can Fight Back Against Hackers in Minutes. Here's What That Actually Means.
Sevii has updated its attack-detection software to include AI agents that can spot, contain, and fix security incidents automatically. The promise sounds impressive. The questions worth asking are harder.

AI Agents Are Breaking Cloud Security Faster Than Human Hackers Ever Could
Automated attackers can test thousands of ways into a company's cloud systems in minutes. Most security teams are still thinking at human speed.

AI Is Writing Your Code Faster Than Your Security Team Can Read It
Coding assistants are flooding repos with open-source packages, and the vulnerability backlog is winning the race.

Your Team's Slack Messages During a Breach Could Cost More Than the Breach Itself
The panicked notes, the finger-pointing threads, the 'we knew about this' one-liners: what your staff types in the first 24 hours of a cyber incident can become courtroom evidence. Here is why that matters, and what to do before the subpoena arrives.

AI Coding Assistants Are Pulling in Open Source Packages Faster Than Anyone Can Check Them
Developers using AI helpers are importing software libraries at machine speed. Security teams built for human review can't keep up, and dodgy code is slipping through.

The software wrapper around your AI agent is the real security risk
Researchers broke into official AI automation tools from Anthropic, Google, and OpenAI, not by tricking the AI itself, but by exploiting the ordinary code that connects it to the real world.

Your GitHub activity logs are a smoke detector you forgot to switch on
Two researchers showed at Black Hat USA 2026 that the evidence needed to catch software supply-chain attacks has been sitting inside GitHub all along. Their open-source tool turns that evidence into working alerts.

When Developers Ship 50x More Code, Security Becomes the Traffic Jam
AI coding assistants are pumping out software at a pace human security teams were never built to match. Nobody's quite sure what got shipped.