Tag: application security
Docker Introduces Open Sandbox Kit Spec for AI Agent Permissions
AI agents are getting good at probing the boundaries developers put around them. Their ability to improvise makes them hard to contain. “You ask for something in a very high-level, vague-at-best way ...
GitHub’s Security Autofix Agent Now Remembers What It Fixed
GitHub’s agentic autofix now uses Copilot Memory to reuse repository-specific security fix patterns, helping Copilot apply lessons from past vulnerabilities across future alerts, reviews and coding workflows ...
Leaked GitLab Email Tokens Can Reach Code, Secrets and CI/CD Pipelines
Security researchers have uncovered a GitLab behavior that could let attackers use a leaked project email address to push code, trigger CI/CD jobs and reach other repositories accessible to the address owner ...
DevSecOps Teams as Partners in Secure Software Delivery
DevSecOps teams can reduce last-minute release delays by shifting security decisions earlier, improving guardrails, clarifying ownership and making findings actionable ...
Why Shift Left is Dead
AI-driven development is exposing risks before code is written, forcing security teams to move beyond shift-left and govern agents, prompts, tools and data across the entire development lifecycle ...
Codex Sandbox Escapes Show Why Agent Guardrails Can’t Live Inside the Agent
Two patched OpenAI Codex vulnerabilities, Heapjack and Overpatch, exposed how coding agents can escape sandboxes and reach developer systems without approval prompts ...
Why Your CI/CD Pipeline Is Your Most Unprotected Attack Surface
CI/CD pipelines often hold privileged credentials, execute third-party code and connect directly to production, making pipeline security one of the most overlooked risks in modern DevOps ...
Stop Chasing 100% Test Coverage: Why DevOps Teams Need to Test Smarter, Not More
Every software team eventually runs into the same question: How much testing is enough? For years, the default answer has been "more." More automated tests. More regression suites. More environments. More devices ...
GitHub Widens the Door on Advanced Security Trials
GitHub raised its self-serve Advanced Security trial cap from 100 to 300 licenses, letting more mid-size Enterprise Cloud orgs test for free ...
Why AI Agents Shouldn’t Guess at Vulnerability Exploitability
Vulnerability prioritization is not a language problem. The safest agent architectures use models to interpret and explain, while deterministic systems traverse the evidence. Ask a security team a simple question: Of the ...
Broadcom Launches TrueSource Service to Secure Spring Framework
Broadcom launches TrueSource Trusted Artifacts to provide hardened Spring dependencies, secure open source packages and automated vulnerability remediation ...
Report Shines Spotlight on 91 Vulnerabilities Fixed in Latest Update to Spring Framework
Sonatype says 91 Spring vulnerabilities affecting more than 209,000 software components highlight how AI is accelerating vulnerability discovery and creating a new patching challenge for DevSecOps teams ...

