#DevSecOps
48 stories taggedDevSecOps · page 3 of 4.

AutoJack: A Drive-By to RCE Hiding in AutoGen Studio's Dev UI
A prototyping tool nobody treated as production becomes a one-click code execution chain. The fix is out. The pattern is not.

AWS Continuum Wants to Close the Gap Between AI-Generated Code and AI-Fixed Vulnerabilities
Amazon's new agentic security service promises continuous discovery, triage, and remediation. In practice, it's a bet that the same AI acceleration creating your backlog can also drain it.

June Patch Tuesday Breaks OLE Automation, Leaves Word and Excel Silent on Failure
A Windows update shipped June 9 quietly severed the OLE bridge between Office apps and dozens of third-party tools. No error message. Just nothing.

The SOC Triangle Was Always a Lie We Accepted. AI Is Changing the Math.
Security operations have run on a structural compromise for decades — quality, consistency, or cost: pick two. That constraint is finally starting to bend.

SearchLeak Shows How a Single Crafted URL Can Drain Your M365 Tenant
Varonis researchers chained three weaknesses in Copilot Enterprise Search into a full data-exfiltration path. Microsoft patched it. The attack class isn't going anywhere.

Poisoned Documents Can Freeze AI Agent Guardrails Dead in Their Tracks
Researchers found that a single malicious input can trap reasoning-based safety systems in extended thinking loops, slowing LangGraph deployments by 148x and starving co-located agents of resources.

AI Web Agents Have No Reliable Prompt Injection Defenses, Benchmark Finds
Researchers ran 3,168 adversarial tests against GPT-5 and Gemini-powered agents. The 'Robust Behavior' outcome — agent completes task, attacker gets nothing — never appeared.

OnyxC2 Stealer: $250/Month Buys You Encrypted Payloads and 200+ App Targets
A commodity infostealer is punching well above its price point. OnyxC2 brings DLL sideloading and in-memory execution to anyone with a credit card.

AI Red Teaming Grew Up. The Job Description Is Still Being Written.
The tools broke when LLMs arrived. Now the discipline is rebuilding itself in real time — and the threat model includes teenagers with too much free time.

Knowingly Shipping Vulnerable Code Has Become Standard Practice, Survey Finds
A Checkmarx survey of 2,350 security leaders finds nearly half of production code is AI-generated — and enterprises are deploying it despite knowing it carries unresolved flaws.

A Free LLM, a Custom Harness, and 27 Compromised VMs: The AI Worm You Don't Need a Lab to Build
University of Toronto researchers built a self-replicating AI worm using only locally-hosted open models. It spread to 82% of its targets. The threat model here isn't frontier AI — it's the misconfigured server you forgot about.

Voluntary AI Security Rules: The Industry Already Knows What That Means
Trump's AI cybersecurity executive order drew polite applause from vendors and quiet skepticism from practitioners. The gap between those two reactions is where the real story lives.

$7M Says Autonomous Agents Can Fix the Identity Sprawl Problem
Offroad exits stealth with a bet that AI-driven security agents can manage what platform teams stopped being able to track manually — machine identities, third-party app permissions, and the rest of the non-human identity mess.

GitHub's Browser VSCode Handed Attackers a Skeleton Key to Your Private Repos
An unscoped OAuth token, a Jupyter notebook, and a skipped publisher trust check. That's all it took.

A Dev Flag Left Microsoft Account Tokens Exposed Across Billions of Android Installs
A single misconfigured development setting bypassed token-protection controls in Microsoft's Android apps. The blast radius was massive.