Tag

#DevSecOps

48 stories taggedDevSecOps.

Macro close-up of a glowing blue search bar interface on a dark enterprise dashboard screen, with faint streams of data characters flowing outward from the inpu
AI Security

AI Coding Assistants Are Pulling in Open Source Packages Faster Than Anyone Can Check Them

Developers using AI helpers are importing software libraries at machine speed. Security teams built for human review can't keep up, and dodgy code is slipping through.

4 min read
Full-frame photoreal editorial shot of a laptop screen showing an anonymous online product page with rows of star ratings and review boxes, one review subtly hi
AI Security

The software wrapper around your AI agent is the real security risk

Researchers broke into official AI automation tools from Anthropic, Google, and OpenAI, not by tricking the AI itself, but by exploiting the ordinary code that connects it to the real world.

5 min read
Full-frame edge-to-edge photoreal news-editorial image of a laptop screen showing a generic browser extensions settings page with one entry greyed out and marke
Threat Intelligence

Your GitHub activity logs are a smoke detector you forgot to switch on

Two researchers showed at Black Hat USA 2026 that the evidence needed to catch software supply-chain attacks has been sitting inside GitHub all along. Their open-source tool turns that evidence into working alerts.

4 min read
Macro photograph of a glowing amber spider web stretched across a dark server rack interior, dew droplets catching the rack's blue LED light, sharp focus on the
AI Security

When Developers Ship 50x More Code, Security Becomes the Traffic Jam

AI coding assistants are pumping out software at a pace human security teams were never built to match. The real question is not whether bugs slip through, but whether anyone still knows what got shipped.

4 min read
Photoreal news-editorial image, 16:9 full-frame composition edge to edge
Opinion

Open source grew up in a hurry, and the security bill is coming due

The world runs on free code written by strangers. That model is finally hitting its limits, and everyone using cloud services is exposed.

4 min read
Full-frame edge-to-edge overhead photoreal shot of a developer's dark wooden desk at night, a laptop screen glowing with abstract green code, a small physical h
Threat Intelligence

The Week's Attacks Were Cheap, Ordinary, and Very Effective

Opening a repo, installing a package, or previewing a PDF was enough to hand attackers a foothold this week. None of it was sophisticated. All of it worked.

4 min read
Full-frame photoreal editorial image of a developer workstation at night, two nearly identical strings of hexadecimal characters glowing softly on a dark monito
Cloud Security

Tel Aviv Security Firm Oligo Raises $60 Million to Catch Hackers in the Act

Oligo Security has now raised $140 million total to build software that watches running apps in real time and blocks attacks the moment they happen, rather than waiting for a patch.

3 min read
Full-frame photoreal editorial image of a dark modern security operations centre at night, rows of monitors glowing with abstract identity graphs and network no
AI Security

Google's AI Coding Assistants Could Be Tricked Into Leaking Secrets and Sabotaging Code

A newly exposed attack technique shows how a low-level AI agent inside Google's development toolkit can be manipulated into poisoning a higher-trust agent, giving attackers a path to steal credentials and tamper with software projects.

3 min read
Extreme close-up of a sleek modern laptop keyboard with a faint blue-green digital glow emanating from the screen reflecting onto the keys, abstract streams of
AI Security

Why Locking Down What AI Agents Can Do Is Not Enough

A security firm says the real question is not what you told your AI to do. It is how far it can wander if something goes wrong.

3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
AI Security

Cantina Raises $8 Million to Let AI Agents Hunt and Fix Security Flaws Automatically

A New York startup wants to replace slow, manual vulnerability management with software agents that find problems, investigate them, and patch them without waiting for a human to file a ticket.

3 min read
A futuristic AI network integrating with various cybersecurity vendor logos
AI Security

AI Security Bots Are Great at Hacking. Terrible at Defence. Researchers Are Trying to Fix That.

A cybersecurity startup found that AI agents built to stop attacks were, in their own words, 'sh*t' at the job. Here is why that gap exists, and what they are doing about it.

4 min read
Full-frame overhead shot of a modern Android smartphone lying on a matte desk, screen glowing with faint white-on-white text patterns barely visible, next to a
AI Security

Your Security Team Is Flying Blind on AI. Here Is Why.

The tools built to catch hackers and bad code were designed for a world where humans made every decision. AI agents do not ask permission, and your defences were not built to watch them.

4 min read
US Capitol building under a cloudy sky, symbolizing legislative deadlock on surveillance laws
Policy & Regulation

AI Smart Glasses Are Walking Into Your Office. Nobody Knows How to Stop Them.

Samsung's entry into AI-powered glasses has forced security leaders to face an uncomfortable truth: the recording device problem is already everywhere, and a ban probably makes things worse.

4 min read
Photoreal editorial shot of an empty modern negotiation room with a single laptop open on a long dark table, a lock icon glowing faintly on the screen, harsh ov
Ransomware

Your ransomware playbook is probably putting the wrong person in charge at 4 a.m.

A growing body of evidence shows that the real damage in ransomware incidents often comes not from the attack itself, but from who gets to decide whether to pull the plug on a business-critical system.

5 min read
Wide editorial photograph of an empty corporate boardroom at dusk, long table with scattered open laptops each showing a different AI chatbot interface on scree
Policy & Regulation

FedRAMP is scrapping the annual audit. Here's what 20X actually changes.

The old federal cloud approval process runs on PDFs and once-a-year checks. The replacement wants live proof that your controls are working, all the time.

4 min read
© 2026 Threat Vectr