Source Code Management (SCM) stories - Page 2
Trivy GitHub breach exposes CI/CD supply chain risk
Last month
#
devops
#
cloud security
#
application security
Aqua Security's Trivy GitHub Action was hijacked to ship infostealer code via CI/CD pipelines, exposing secrets across downstream users.
GitLab widens AI access & sets flat review pricing
Last month
#
devops
#
application security
#
devsecops
GitLab opens agentic AI to free-tier users, sets USD $0.25 flat fee for automated code reviews and expands security false-positive filtering.
BloodHound expands identity attack path mapping reach
Last month
#
data protection
#
encryption
#
pam
SpecterOps broadens BloodHound Enterprise to map identity attack paths across Okta, GitHub and Jamf-managed Macs in hybrid environments.
Entro launches AI agent governance tool for enterprises
Last month
#
data protection
#
digital transformation
#
cloud security
Entro launches AGA to map, monitor and control AI agents in enterprises, tackling shadow AI and non-human identity risks at scale.
Cobalt unveils service to manage enterprise pentesting
Last month
#
devops
#
cloud security
#
application security
Cobalt launches Security Program Manager service to run enterprise pentesting, align tests with business goals and speed up remediation.
North Korean IT workers infiltrate Western remote jobs
Last month
#
hcm
#
physical security
#
supply chain
North Korean IT workers using Western collaborators and fake identities are infiltrating remote jobs to funnel foreign salaries home.
ThoughtSpot unveils Spotter AI agents tailored by sector
Last month
#
saas
#
data analytics
#
digital transformation
ThoughtSpot rolls out Spotter for Industries, AI analytics agents tuned to sector rules to close the “context gap” in enterprise decisions.
Secure Code Warrior unveils AI code governance tool
Last month
#
application security
#
devsecops
#
supply chain
Secure Code Warrior launches SCW Trust Agent: AI, giving security teams commit-level visibility and control over AI-influenced code.
AI surge drives record secrets sprawl across GitHub
Last month
#
cloud security
#
application security
#
socs
AI-fuelled coding drives record 29 million hardcoded secrets on GitHub in 2025, with leaks from AI tools and services surging sharply.
1Password debuts Unified Access to secure AI agents
Last month
#
data protection
#
cloud security
#
mdm
1Password unveils Unified Access to secure AI agents and machine credentials, promising endpoint-to-agent visibility for security teams.
GitHub backs Alpha-Omega with fresh open source funds
Last month
#
siem
#
hyperscale
#
application security
GitHub joins tech giants in a USD $12.5 million Alpha-Omega push, boosting AI-powered defences for critical open source software.
Linux Foundation secures USD $12.5m for AI security
Last month
#
hyperscale
#
cloud security
#
supply chain
Linux Foundation wins USD $12.5m from tech giants to bolster AI-era open source security and ease pressure on overstretched maintainers.
VAST Data unveils Foundation Stacks for NVIDIA AI OS
Last month
#
hybrid cloud
#
aiops
#
open source
VAST Data unveils Foundation Stacks, turning NVIDIA AI Blueprints into production-ready pipelines on its AI Operating System.
VAST unveils Foundation Stacks to speed AI to production
Last month
#
hybrid cloud
#
digital transformation
#
hyperscale
VAST Data unveils Foundation Stacks, open-source pipelines turning NVIDIA AI Blueprints into production-ready workflows on its AI OS.
PagerDuty links Anthropic, Cursor & LangChain for AI ops
Last month
#
devops
#
apm
#
aiops
PagerDuty links Anthropic, Cursor and LangChain to expand its AI ops ecosystem, boosting incident response across modern software stacks.
ControlPlane unveils enterprise support for OpenBao
Last month
#
encryption
#
pam
#
cloud security
ControlPlane launches enterprise support for OpenBao as IBM's USD $6.4 billion HashiCorp deal drives demand for open source Vault alternatives.
GenAI drives patient data policy breaches in healthcare
Last month
#
malware
#
data protection
#
cloud security
GenAI use in healthcare is fuelling patient data policy breaches, with regulated records making up 89% of AI-linked violations, research shows.
Dify raises USD $30m to scale open-source AI workflows
Last month
#
partner programmes
#
rpa
#
risk & compliance
Dify secures USD $30m to expand its open-source platform for production-ready AI agent workflows across global enterprise teams.
JFrog flags 13 critical CI/CD flaws in GitHub workflows
Last month
#
siem
#
fintech
#
application security
JFrog warns 13 GitHub CI/CD workflow flaws, mostly critical, could let attackers hijack pipelines and steal secrets at scale.
Beyond silicon: AMD evolves AI processor performance, makes play for investment trillions
Last month
#
semiconductors
#
digital transformation
#
hyperscale
AMD shifts its AI pitch from raw silicon to open software and cloud access as it targets developers and a share of looming trillions.