Editorial Calendar
North Korea Expands the Reach of PolinRider Supply Chain Attack Campaign
The North Korean-sponsored threat groups behind the long-running fake interview scams targeting developers are expanding the PolinRider supply chain campaign that has escalated over the past several months. Reports from cybersecurity vendors ...
‘GitLost’ Flaw Lets Attackers Trick GitHub AI Agent Into Leaking Private Repos
Noma researchers again show how easy it is to manipulate AI agents with malicious commands via indirect prompt injection attacks ...
How AI is Revamping DevSecOps Processes
Artificial Intelligence is pushing DevSecOps into a new phase where security is no longer just about detecting vulnerabilities, but increasingly about resolving them automatically within the flow of software delivery. As many ...
Block Details Builderbot Framework for Orchestrating AI Agents Across SDLC
The software engineers at Block have developed an orchestration layer they are using to manage artificial intelligence (AI) agents that have been trained to automate multiple tasks across their software development lifecycle ...
How Independent Service Deployments Expose the Limits of Conventional Regression Testing Tools
The architectural shift to independently deployable services was supposed to make software delivery faster and less risky. In many aspects, it has. Teams can ship a change to one service without coordinating ...
When AI Agents Get Production Access: The Next Big DevOps Risk
It wasn’t that long ago that AI assistants just watched from the sidelines. They could answer your questions, explain how things worked, sum up logs, and write deployment scripts. Handy, sure, but ...
Lightrun Adds Ability to Assess Impact Pull Request Will Have in Production
Lightrun is providing early access to an ability to verify whether a pull request (PR) will actually run in a production environment as part of its artificial intelligence (AI) platform for automating ...
Mozilla Shows the Danger of Indirect Prompt Injections in AI Coding Agents
A clean GitHub repository that contains no malicious code can launch an attack and fully compromise a developer’s systems by using indirect prompt injections to trick AI-powered coding agents like Anthropic’s Claude ...
Harness Adds Autonomous AI Agents to Automate DevOps Workflows
Harness today is providing DevOps teams with an ability to build and deploy autonomous artificial intelligence (AI) agents that automate the delivery of code to production environments. Trevor Stuart, a senior vice ...
Attackers Exploit SimpleHelp Flaw to Steal Info from AI Coding Assistants, Clouds
Threat actors are exploiting a known security flaw in the SimpleHelp remote monitoring and management (RMM) software to drop two previously unknown pieces of malware that can compromise a broad range of ...
Configuration Drift in a Multi-Cloud World
Configuration drift is the gap between the infrastructure state declared in code and the state actually running in your environment. It occurs when resources are changed outside of your infrastructure as code ...
From Phishing to Vishing: Why DevSecOps Must Rethink Communication Security
Key Takeaways: Vishing is the new frontline threat: Attackers are shifting from emails to phone-based scams, using AI and social engineering to bypass traditional security controls. DevSecOps must expand its scope: Securing ...

