#DevSecOps
48 stories taggedDevSecOps · page 2 of 4.

AI Security Scanners Are Drowning Teams in False Alarms, and the Fix Isn't More AI
More than 60% of flagged security flaws are noise. A researcher testing a dozen tools says AI models make the problem worse, not better, because they lack the context to tell a real threat from a ghost.

Google Spent $32 Billion on Wiz. Now It Wants AI to Fight Hackers So Fast Humans Can't Keep Up
Criminals can hand off access to a breached company in 22 seconds. Google says only AI can respond that quickly, and it has built a new automated defence platform to prove it.

The Engineers Building Both Sides of the AI Security War
A new breed of security team is quietly writing the rules for how artificial intelligence gets used in cyberattacks and defenses. Most companies have never heard of them.

CISA Left AWS GovCloud Keys on GitHub for Six Months, Ignored Nine Alerts
The US cyber agency's own postmortem admits it missed automated warnings, muddled its reporting channels, and took two days to rotate leaked admin credentials.

GhostApproval: Six AI Coding Tools Were Tricking Developers Into Approving Dangerous Actions
A new attack pattern shows that the 'human approval' step built into AI coding assistants can be fed false information by the very tool it is supposed to oversee.

When your AI coder looks exactly like a hacker to the security software
Sophos found that popular AI coding assistants keep tripping the same alarms designed to spot break-ins, and the false alerts are piling up.

GitHub's Green 'Verified' Badge Can Lie: Signed Commits Cloned Without the Key
Researchers show anyone can produce a second signed commit that matches the author, date and files of a real one, keeping GitHub's Verified stamp while changing the unique fingerprint developers rely on.

AI Writes Code Faster Than Anyone Can Check It. That's the Problem.
Machine-generated code is flooding into production with fewer human eyes on it. Defenders are being asked to catch what nobody wrote by hand.

How One HR Giant Cut Its Security Bill by $250,000 — by Deleting Data It Never Needed
Vensure Employer Solutions was drowning in its own security logs. An AI-powered clean-up cut costs, halved response times, and proved that more data isn't always safer.

AI-Generated Code Is Outpacing Your Audit Process
CISOs are discovering that traditional software audits weren't built for a world where a developer can generate 500 lines of Go in forty seconds. Here's what the checklist needs to look like now.

The 2026 Vendor Survey Nobody Asked For, Except The Findings Actually Track
A survey of 1,200 practitioners says awareness is up and resilience is flat. Anyone running production already knew that.

Detection Engineering Grew Up. Most Security Stacks Didn't.
Behavior-based, CI/CD-integrated detection logic is eating vendor-supplied rules. Here's what's actually driving the shift — and what teams still get wrong.

Bash Shell Tricks From the '90s Are Breaking AI Coding Agents Wide Open
Old-school shell injection techniques can bypass safeguards in most open-source AI coding agents — and a poisoned repo is all it takes to start the chain.

BEC Keeps Winning Because It Looks Exactly Like Normal Work
The phishing payload is gone. The pretext is the payload now, and your SEG was never built for that.

Three npm Packages Squat PostCSS Names to Drop a Windows RAT
Typosquatted utilities pulled roughly a thousand combined downloads before researchers flagged them. The payload targets Windows developer machines, which is exactly where the credentials live.