Features
Microsoft’s New Testing Agent Tackles the Trust Gap in AI-Generated Code
AI coding assistants write code fast. Whether that code can be trusted is a separate question, and it's becoming a more urgent one. Surveys this year put average developer trust in AI-generated ...
‘Flooding Dropper’ Is Hitting npm With a Tidal Wave of Malicious Packages
Threat researchers at Sonatype are warning developers of an expanding campaign that is generating a wide range of npm accounts and dropping small numbers of malicious packages from each one, essentially flooding ...
HackerOne Extends Platform Reach to Remediate Source Code Vulnerabilities
HackerOne has added a remediation capability to its H1 Platform that reduces the amount of time required to remediate validated vulnerabilities and other weaknesses affecting specific lines of source code. Nidhi Aggarwal, ...
Meta Launches AI Coding Agent to Challenge OpenAI and Anthropic
In an effort to catch up with OpenAI and Anthropic in one of AI's fastest-growing markets, Meta has launched its first AI coding agent, Muse Code, alongside an updated coding-focused AI model ...
AWS Extends DevSecOps Reach to AI Coding Tools from Anthropic and OpenAI
Amazon Web Services (AWS) this week at the Black Hat USA conference revealed it is working with both Anthropic and OpenAI to integrate their respective coding tools with a service it has ...
AWS Adds Agentic Workspace to Kiro AI Coding Tool
Amazon Web Services (AWS) this week added an open source workspace for its Kiro artificial intelligence (AI) coding tool that enables application developers to asynchronously assign tasks to an AI agent that ...
RapidFort Extends Open Source Software Security Reach to Runtime Environments
RapidFort today at the Black Hat USA conference announced it has extended its ability to secure open source software to the runtimes that DevOps teams deploy in production environments. Michael Wood, chief ...
Fast-Moving Shai-Hulud Attack Infects npm Packages with 2 Billion Monthly Downloads
Researchers at Aikido Security and Endor Labs are tracking a fast-spreading supply-chain attack that is compromising a wide range of npm software packages that combined have more than 2 billion installs a ...
N. Korea Group Behind Multiple Open Source Supply-Chain Attacks: Amazon
Amazon’s recent report attributing a series of compromises of open source software libraries to a North Korea-backed threat group encapsulates many of the expanding cyber risks increasingly facing developers, from the growing ...
Ten Great DevOps Job Opportunities
staging-devopsy.kinsta.cloud is now providing a weekly DevOps jobs report through which opportunities for DevOps professionals will be highlighted as part of an effort to better serve our audience. Our goal in these ...
Microsoft Confirms Copilot ‘Super App’ Is Coming This Year — and It’s About More Than Convenience
Microsoft is combining Copilot Chat, Code, Cowork and Autopilots into one super app, raising new questions about agent governance, identity, licensing and security ...
JetBrains Open-Sources KotlinLLM, a Research Prototype for Runtime Code Generation
JetBrains open-sources KotlinLLM, letting compiled Kotlin apps generate and persist LLM-written code at runtime instead of calling a model live ...

