#DevSecOps
50 stories taggedDevSecOps · page 4 of 4.

AI Web Agents Have No Reliable Prompt Injection Defenses, Benchmark Finds
Researchers ran 3,168 adversarial tests against GPT-5 and Gemini-powered agents. The 'Robust Behavior' outcome, agent completes task, attacker gets nothing, never appeared.

Knowingly Shipping Vulnerable Code Has Become Standard Practice, Survey Finds
A Checkmarx survey of 2,350 security leaders finds nearly half of production code is AI-generated, and enterprises are deploying it despite knowing it carries unresolved flaws.

A Free LLM, a Custom Harness, and 27 Compromised VMs: The AI Worm You Don't Need a Lab to Build
University of Toronto researchers built a self-replicating AI worm using only locally-hosted open models. It spread to 82% of its targets. The threat model isn't frontier AI, it's the misconfigured server you forgot about.

$7M Says Autonomous Agents Can Fix the Identity Sprawl Problem
Offroad exits stealth with a bet that AI-driven security agents can manage what platform teams stopped being able to track manually, machine identities, third-party app permissions, and the rest of the non-human identity mess.

India Sets a 12-Hour Clock on Exploited Vulnerabilities. Can Enterprises Actually Do It?
CERT-In's new AI-threat framework resets expectations around patch velocity, but the real test is whether organizations even know what's exposed.