Features
N. Korean Famous Chollima Hackers Use Malicious npm Packages to Steal Data
A group of more than two dozen malicious npm packages used to steal secrets and credentials from software developers has all the hallmarks – from infrastructure to operations – of Famous Chollima, ...
Eclipse Foundation Extends Scope and Reach of Open VSX Registry
The Eclipse Foundation launches a new framework for the Open VSX Registry, enhancing security features and transitioning to a hybrid architecture. With support from AI tool provider Cursor, this initiative aims to ...
Microsoft Executives Warn AI Could Limit the Developer Talent Pipeline
Generative AI is transforming software development at remarkable speed. But in a new paper written by two Microsoft executives, Azure CTO Mark Russinovich and Scott Hanselman, VP of the developer community, argue ...
ControlMonkey Extends IaC Automation Reach to Restore Network Services
ControlMonkey has extended its platform for automating infrastructure-as-code (IaC) to add an ability to reprovision network services following a disruption in service. Company CEO Aharon Twizer said this extension to the Cloud ...
Postman Adds Ability to Invoke API Code From Within Git Workflows
Discover how Postman’s new feature allows software engineering teams to manage API specifications, collections, and environments directly from Git repositories, simplifying workflows for AI agents in the development process ...
Google ADK Opens the Door to AI Agents That Work Inside Your DevOps Toolchain
Google ADK adds integrations for GitHub, GitLab, Jira, MongoDB, and seven observability tools. AI agents can now work inside your DevOps toolchain ...
Five Great DevOps Job Opportunities
DevOps.com is now providing a weekly DevOps jobs report through which opportunities for DevOps professionals will be highlighted as part of an effort to better serve our audience. Our goal in these ...
AI-Fueled Development Pushes Open-Source Risk to Extremes: Report
Artificial intelligence has shortened the timeline for software development from months to days. But according to new research, that acceleration is creating significant risks for security and compliance issues. Black Duck’s 2026 ...
Harness Readies Resilience Testing Platform to Make Applications More Robust
Harness today revealed that it will make available a set of open source tools for testing the resiliency of applications that are based on a chaos engineering platform the company gained with ...
Malicious NPM Package Gets Downloaded 50K Times Before Discovery
A malicious package downloaded approximately 50,000 times from a node package manager (npm) is providing an object lesson for adopting more DevSecOps best practices. Security researchers from Tenable discovered a “ambar-src” package ...
Security Flaws in Anthropic’s Claude Code Risk Stolen Data, System Takeover
Three critical vulnerabilities found in Anthropic’s Claude Code agentic AI developer tool could be exploited simply by cloning and opening an untrusted project and lead to system takeover, stolen API keys, and ...
Claude Code Remote Control Keeps Your Agent Local and Puts it in Your Pocket
Claude Code Remote Control lets developers run AI coding agents locally while supervising them from any browser or phone. Anthropic’s local-first approach contrasts with cloud agents and reshapes how teams govern AI-driven ...

