Tag

#DevSecOps

51 stories taggedDevSecOps · page 3 of 4.

A close-up, sharply focused 16:9 editorial photograph of a developer's keyboard and monitor in a dimly lit office at night
AI Security

GhostApproval: Six AI Coding Tools Were Tricking Developers Into Approving Dangerous Actions

A new attack pattern shows that the 'human approval' step built into AI coding assistants can be fed false information by the very tool it is supposed to oversee.

4 min read
Full-frame photoreal editorial shot of a developer workstation at night, two large monitors filled with code and a security dashboard showing red alert badges,
AI Security

When your AI coder looks exactly like a hacker to the security software

Sophos found that popular AI coding assistants keep tripping the same alarms designed to spot break-ins, and the false alerts are piling up.

4 min read
Full-frame photoreal editorial image of a developer workstation at night, two nearly identical strings of hexadecimal characters glowing softly on a dark monito
Cloud Security

GitHub's Green 'Verified' Badge Can Lie: Signed Commits Cloned Without the Key

Researchers show anyone can produce a second signed commit that matches the author, date and files of a real one, keeping GitHub's Verified stamp while carrying a different hash than developers recorded.

4 min read
Full-frame edge-to-edge photoreal editorial shot of a developer's darkened workstation at night, multiple monitors glowing with lines of code reflecting off a m
AI Security

AI Writes Code Faster Than Anyone Can Check It. That's the Problem.

Machine-generated code is flooding into production with fewer human eyes on it. Defenders are being asked to catch what nobody wrote by hand.

3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Cloud Security

How One HR Giant Cut Its Security Bill by $250,000 — by Deleting Data It Never Needed

Vensure Employer Solutions was drowning in its own security logs. AI-assisted filtering cut costs, halved response times, and proved that collecting less can mean detecting more.

3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
AI Security

AI-Generated Code Is Outpacing Your Audit Process

CISOs are discovering that traditional software audits weren't built for a world where a developer can generate 500 lines of Go in forty seconds. The checklist needs to change now.

3 min read
Opinion

The 2026 Vendor Survey Nobody Asked For, Except The Findings Actually Track

The Bitdefender Cybersecurity Assessment polled 1,200 practitioners and concluded awareness is up and resilience is flat. Anyone running production already knew that.

3 min read
Cloud Security

Detection Engineering Grew Up. Most Security Stacks Didn't.

Behavior-based, CI/CD-integrated detection logic is eating vendor-supplied rules. What's actually driving the shift, and what teams still get wrong.

3 min read
AI Security

Bash Shell Tricks From the '90s Are Breaking AI Coding Agents Wide Open

Old-school shell injection techniques can bypass safeguards in most open-source AI coding agents, and a poisoned repo is all it takes to start the chain.

3 min read
Identity & Access

BEC Keeps Winning Because It Looks Exactly Like Normal Work

The phishing payload is gone. The pretext is the payload now, and your SEG was never built for that.

3 min read
Threat Intelligence

Three npm Packages Squat PostCSS Names to Drop a Windows RAT

Typosquatted utilities pulled roughly a thousand combined downloads before researchers flagged them. The payload targets Windows developer machines, which is exactly where the credentials live.

2 min read
AI Security

AutoJack: A Drive-By to RCE Hiding in AutoGen Studio's Dev UI

A prototyping tool nobody treated as production becomes a one-click code execution chain. The fix is out. The pattern is not.

3 min read
Cloud Security

AWS Continuum Wants to Close the Gap Between AI-Generated Code and AI-Fixed Vulnerabilities

Amazon's new agentic security service promises continuous discovery, triage, and remediation. In practice, it's a bet that the same AI acceleration creating your backlog can also drain it.

3 min read
Vulnerabilities

June Patch Tuesday Breaks OLE Automation, Leaves Word and Excel Silent on Failure

A Windows update shipped June 9 quietly severed the OLE bridge between Office apps and dozens of third-party tools. No error message. Just nothing.

3 min read
AI Security

The SOC Triangle Was Always a Lie We Accepted. AI Is Changing the Math.

Security operations have run on a structural compromise for decades, quality, consistency, or cost: pick two. That constraint is finally starting to bend.

3 min read
© 2026 Threat Vectr