Archives for August 2025
Month: August 2025

Malicious Nx Packages Used in Two Waves of Supply Chain Attack
The Nx build system was hit by a supply chain attack dubbed “s1ngularity,” leaking thousands of secrets and exploiting AI tools for data theft ...

Bringing Order to Chaotic Software Engineering Workflows
Software development has never been tidy, but the current landscape feels more chaotic than ever. Shannon Mason, chief strategy officer for Tempo, dives into why software engineering workflows remain chaotic and what ...

Why APIs Alone Won’t Cut It in the AI Era
Kumar Chivukula, co-founder and CEO of Codeglide.ai (a subsidiary of Upsera), explains why the rise of the Model Context Protocol (MCP) is reshaping how enterprises connect APIs to large language models. For ...

DevOps Platforms Show Cracks: GitHub Incidents Surge 58%, Azure, GitLab and Jira Also Under Pressure
GitProtect.io’s Mid-Year 2025 DevOps Threats Unwrapped report reveals a surge in disruptions across GitHub, GitLab, Bitbucket, Jira, and Azure DevOps — with 330 incidents in just six months. Rising outages, ransomware, and ...

Survey Surfaces Raft of AI Coding Issues Involving Embedded Systems
A new survey of 785 development and security professionals reveals that 89% of organizations are using AI coding assistants for embedded systems, but concerns over security, licensing risks, and governance remain. Python ...

Coding at the Speed of AI: Innovation, Vulnerability, and the GenAI Paradox
Generative AI accelerates software delivery but also reintroduces vulnerabilities, making secure coding practices, oversight, and developer training essential for safe adoption ...

How Engineers are Automating More with Less: Trends in DevOps Tooling
DevOps automation is shifting from complex, monolithic pipelines to lean, modular, AI-enhanced workflows—driving efficiency, cost savings, and better developer experience ...

AI Agent Onboarding is Now a Critical DevOps Function
Onboarding AI agents is no longer optional—DevOps must treat them like new engineers, with guardrails, observability, and lifecycle management to prevent operational debt ...

System Initiative Adds AI Agents to Infrastructure Automation Platform
System Initiative introduces autonomous AI agents to its infrastructure automation platform, using digital twins to help DevOps teams safely optimize and manage IT environments ...

Qwiet AI Extends Microsoft Support in Platform for Fixing Vulnerabilities
Qwiet AI extends its AI-driven application security platform with deeper Microsoft DevOps integrations, enhanced automation, and expanded AutoFix capabilities to proactively remediate code vulnerabilities ...

Staying on Top of Shadow AI
Shadow AI is the new shadow IT—slipping into organizations unseen, reshaping workflows and decisions before leadership realizes it exists ...

Broadcom Adds Argo and Ubuntu Support to VMware Cloud Foundation
Broadcom today at the VMware Explore 2025 conference unfurled a set of developer services for the instance of Kubernetes it has embedded into its VMware Cloud Foundation (VCF) platform that includes the ...