DevOps and Open Technologies
Widespread Mini Shai-Hulud Campaign Is a Matter of Trust
The latest series of attacks using the notorious Shai-Hulud worm puts into sharp focus the threats facing software developers and their CI/CD pipelines, an issue that has been raised in recent months ...
How Open Source Dependency and Repo Attacks Compromise DevOps Pipelines and How to Stay Safe
Modern applications rely on open source components for up to 90% of their code, creating a vast attack surface dominated by inhemalicious supply chain injections. High-profile incidents like Log4j and the sabotage ...
IBM Bob Takes AI Coding Assistants to the Next Level
IBM Bob goes beyond AI-assisted coding to support the full software development lifecycle — with governance, security, and multi-model orchestration built in ...
Cyber Threats to DevOps Platforms Rising Fast, GitProtect Report Finds
The number of incidents targeting DevOps platforms grew 21% in 2025, but the amount of downtime jumped almost 95%, the security firm said ...
Critical Microsoft GitHub Flaw Highlights Dangers to CI/CD Pipelines: Tenable
A critical vulnerability in a popular Microsoft GitHub repository could allow a threat actor to easily exploit its CI/CD infrastructure to run arbitrary code in the repository and gain access to secrets, ...
Claude Code Routines: Anthropic’s Answer to Unattended Dev Automation
Anthropic's Claude Code Routines let dev teams automate scheduled tasks, GitHub events, and API-triggered workflows from managed cloud infrastructure ...
Microsoft Field Engineers Built a Six-Agent Research Pipeline in VS Code That Fact-Checks Its Own Output
Azure Global Black Belts Diego Casati and Ray Kao developed Project Nighthawk, a multi-agent system that automates deep technical research for AKS and ARO with 100% source-grounding ...
Survey Surfaces Increased Reliance on Open Source Software to Build Apps
Open source adoption is surging, with 49% of IT teams increasing usage. However, 47% of staff spend 75% of their time on maintenance. Explore the impact of AI threats and EU regulations ...
Two Malicious npm Packages Aim to Steal Credentials and Other Secrets
Bad actors took over a npm maintainer account and have published two malicious packages designed to steal credentials, API keys, and other secrets from the computers of victims who download them from ...
Open SWE Captures the Architecture That Stripe, Coinbase and Ramp Built Independently for Internal Coding Agents
Explore Open SWE, the open-source framework by LangChain that codifies the internal AI coding agent architectures used by Stripe, Ramp and Coinbase. Released March 17, 2026, this MIT-licensed project offers a customizable ...
How eBPF and OpenTelemetry Have Simplified the Observability Function
Overview arguing that OpenTelemetry eBPF Instrumentation (OBI) — combined with OpenTelemetry Injector — removes barriers to full observability by enabling zero-code, kernel-level telemetry for Kubernetes and Linux environments, solving language, legacy, and ...
N. Korean Famous Chollima Hackers Use Malicious npm Packages to Steal Data
A group of more than two dozen malicious npm packages used to steal secrets and credentials from software developers has all the hallmarks – from infrastructure to operations – of Famous Chollima, ...

