#DevSecOps
50 stories taggedDevSecOps · page 2 of 4.

The Week's Attacks Were Cheap, Ordinary, and Very Effective
Opening a repo, installing a package, or previewing a PDF was enough to hand attackers a foothold this week. None of it was sophisticated. All of it worked.

Tel Aviv Security Firm Oligo Raises $60 Million to Catch Hackers in the Act
Oligo Security has now raised $140 million total to build software that watches running apps in real time and blocks attacks the moment they happen, rather than waiting for a patch.

Google's AI Coding Assistants Could Be Tricked Into Leaking Secrets and Sabotaging Code
A newly exposed attack technique shows how a low-level AI agent inside Google's development toolkit can be manipulated into poisoning a higher-trust agent, giving attackers a path to steal credentials and tamper with software projects.

Why Locking Down What AI Agents Can Do Is Not Enough
A security firm says the real question is not what you told your AI to do. It is how far it can wander if something goes wrong.

Cantina Raises $8 Million to Let AI Agents Hunt and Fix Security Flaws Automatically
A New York startup wants to replace slow, manual vulnerability management with software agents that find problems, investigate them, and patch them without waiting for a human to file a ticket.

AI Security Bots Are Great at Hacking. Terrible at Defence. Researchers Are Trying to Fix That.
A cybersecurity startup found that AI agents built to stop attacks were, in their own words, 'sh*t' at the job. Here is why that gap exists, and what they are doing about it.

Your Security Team Is Flying Blind on AI. Here Is Why.
The tools built to catch hackers and bad code were designed for a world where humans made every decision. AI agents don't ask permission, and your defences weren't built to watch them.

AI Smart Glasses Are Walking Into Your Office. Nobody Knows How to Stop Them.
Samsung's entry into AI-powered glasses has forced security leaders to face an uncomfortable truth: the recording device problem is already everywhere, and a ban probably makes things worse.

Your ransomware playbook is probably putting the wrong person in charge at 4 a.m.
A growing body of evidence shows that the real damage in ransomware incidents often comes not from the attack itself, but from who gets to decide whether to pull the plug on a business-critical system.

FedRAMP is scrapping the annual audit. Here's what 20X actually changes.
The old federal cloud approval process runs on PDFs and once-a-year checks. The replacement wants live proof that your controls are working, all the time.

AI Security Scanners Are Drowning Teams in False Alarms, and the Fix Isn't More AI
More than 60% of flagged security flaws are noise. A researcher who tested over a dozen tools says AI models make the problem worse because they lack the context to tell a real threat from a ghost.

Google Spent $32 Billion on Wiz. Now It Wants AI to Fight Hackers So Fast Humans Can't Keep Up
Criminals can hand off access to a breached company in 22 seconds. Google says only AI can respond that quickly, and it has built a new automated defence platform to prove it.

The Engineers Building Both Sides of the AI Security War
A new breed of security team is quietly writing the rules for how artificial intelligence gets used in cyberattacks and defenses. Most companies have never heard of them.

CISA Left AWS GovCloud Keys on GitHub for Six Months, Ignored Nine Alerts
The US cyber agency's own postmortem admits it missed automated warnings, muddled its reporting channels, and took two days to rotate leaked admin credentials.

GhostApproval: Six AI Coding Tools Were Tricking Developers Into Approving Dangerous Actions
A new attack pattern shows that the 'human approval' step built into AI coding assistants can be fed false information by the very tool it is supposed to oversee.