devsecops
49 articles with this tag
HIGH
INFO
INFO
INFO
INFO
CRITICAL
INFO
HIGH
CRITICAL
INFO
INFO
INFO
INFO
LOW
INFO
HIGH
MEDIUM
INFO
HIGH
HIGH
INFO
INFO
LOW
CRITICAL
CRITICAL
INFO
HIGH
INFO
CRITICAL
LOW
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
LOW
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
INFO
JFrog Artifactory flaw exploited days after patch release
How to Build an Injection and Data Handling Security Program
Virtual Event Today: CodeSecCon – Secure Your Code and Applications
Build or Buy? Making the Right Application Security Investment
Everyone's a Builder Now: Securing the AI-Powered Enterprise - Gil Geron - BH26 #2
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
A First Look at Agentic AppSec: Agentic Remediation and Malicious Code Defense
Inside the keyv npm Compromise: preinstall Malware, Trusted Provenance, and IDE Hooks
GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption
What Is Application Security? A Complete Guide
How to Build Application Detection and Response
Small teams are the heaviest users of AI coding agents
Defense-in-depth strategies for securing mobile applications - Ryan Lloyd - ASW #390
Docker security scanner uses AI to help explain, fix vulnerabilities
AI-Generated Code Security Risks: Why “Vibe Coding” Can Break Your App - WC #1
Attackers already know the secrets are on your developers’ machines. Do you?
Attackers Move Past Typosquatting to Realistic Package Impersonation
Detectify brings AppSec automation to AI agents with MCP Server and continuous testing
Organizations knowingly ship vulnerable code amid shrinking exploit windows
TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack
Bridging the Gap to Autonomous Fixes: Snyk and Atlassian Unveil Intelligent Remediation for Jira
AI is reshaping DevSecOps to bring security closer to the code
Aikido Security launches Endpoint to secure AI development and mitigate supply chain attacks
New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released
Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access
The State of Trusted Open Source Report
Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks
Chainguard locks down CI/CD with secure-by-default actions
OpenAI Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity Issues
Your dependencies are 278 days out of date and your pipelines aren’t protected
Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning
Why the shift left dream has become a nightmare for security and developers
From Exposure to Exploitation: How AI Collapses Your Response Window
Snyk and Cline: Securing the Future of Autonomous Coding
The new paradigm for raising up secure software engineers
Weaving Security into the Flow: New Snyk Studio Capabilities Power the AI Security Fabric
Vault Radar 2025 recap: Expanding visibility, deepening integration, and simplifying security
Product engineering teams must own supply chain risk
npm’s Update to Harden Their Supply Chain, and Points to Consider
Black Duck expands Polaris platform with unified, automated security across all major SCMs
Aqua Security: Built for This Moment
Automaker Secures the Supply Chain With Developer-Friendly Platform
How Duke Energy enforces cloud security at scale with Terraform & Vault, and 6 lessons
Armis Centrix brings unified, AI-driven application security to the SDLC
The Engineer's Guide to Elastic Detections as Code
New OSS secret scanner: Kingfisher (Rust) validates exposed creds + maps permissions
Tool: AST-based security scanner for AI-generated code (MCP server)
Making the Most of Your Docker Hardened Images Enterprise Trial – Part 3
Seven habits that help security teams reduce risk without slowing delivery