DevSecOps
Sophisticated Supply Chain Attack Targeting Trivy Expands to Checkmarx, LiteLLM
The supply chain attack that compromised Aqua Security’s Trivy open source security vulnerability scanner and its associated GitHub Actions earlier this month continues to expand, with software development tools from Checkmarx and ...
Future Proofing the Foundation for AI-Ready Security Operations
Last December, the International Telecommunication Union (ITU), the United Nations’ (UN) body for information and communication technologies, supported Open Cybersecurity Schema Framework (OCSF) for ratification as an international standard by June 2026. Standardization is ...
Secure Code Warrior AI Agent Applies Policies to AI Generated Code
Secure Code Warrior (SCW) this week added an artificial intelligence (AI) agent that both identifies code generated by an AI coding tool and automatically applies the appropriate governance policies. Company CEO Pieter ...
Checkmarx Adds Orchestration Framework to DevSecOps Platform
Checkmarx this week revamped its DevSecOps platform to include an orchestration framework for managing tasks assigned to artificial intelligence (AI) agents. Additionally, the company has added two additional artificial intelligence (AI) agents ...
Arcjet Extends Runtime Policy Engine to Block Malicious Prompts
Arcjet today added an ability to detect and block risky prompts before they are shared with a large language model (LLM) embedded within an application. The Arcjet AI prompt injection protection capability ...
Secure DevOps at Scale: Integrating SRE, DevSecOps and Compliance
Enterprises developing SaaS products face the challenge of balancing innovation, security, and compliance. By adopting Secure DevOps practices—integrating security into every stage of development—and implementing site reliability engineering (SRE), organizations can enhance ...
Veracode Extends Package Firewall Reach to Microsoft Artifacts
Veracode has extended the reach of a Package Firewall that applies policies that limit what types of code can be downloaded from a repository to Azure Artifacts from Microsoft. Additionally, DevSecOps teams ...
7 Cybersecurity Tips for 2026 No One Will Tell You About
Nothing about 2026 feels stable anymore, especially in security. Attacks move faster than your monitoring stack, AI tools leak data behind your back and everyday convenience apps quietly turn into intrusion points. The biggest threats aren’t the ...
Three Encryption Resolutions for DevSecOps in 2026
As supply chain attacks surge and AI-powered threats grow, DevSecOps teams must strengthen CI/CD security. Learn why PKI, code signing, and certificate automation are critical in the year ahead ...
The MLSecOps Era: Why DevOps Teams Must Care about Prompt Security
AI-driven software delivery introduces new risks, especially prompt manipulation within CI/CD workflows. This article details the emerging fields of PromptOps and MLSecOps and offers practical strategies for securing prompts, models, and pipelines ...
DevSecOps in Practice: Closing the Gap Between Development Speed and Security Assurance
In the world of modern software development, speed is king. Teams are under constant pressure to release features, fix bugs and stay ahead of competitors. Yet, as development velocity increases, so does ...
AppOmni Open Sources Heisenberg Tool to Scan Pull Requests for Dependencies
AppOmni has made available an open source tool that automatically scans pull requests (PRs) to flag risky or newly published dependencies before they are merged. Dubbed Heisenberg, the tool can also be ...

