Tag
8 articles tagged DevSecOps.
-
Microsoft Gaming Deputy CISO Aaron Zulman discusses the strategic shift in securing autonomous AI agents. The analysis covers the redefinition of containerization, the evolution of the CISO role from blocker to enabler, and the operational impact of AI on vulnerability remediation.
-
Tanya Janka, project leader for the OWASP Top 10 2025, discusses the inclusion of vibe coding as a critical risk. The analysis covers the shift from vulnerability memorization to secure coding habits, the expansion of supply chain threats to include human developers, and actionable strategies for engineering leaders to integrate security into AI-assisted workflows.
-
A strategic analysis of the shift from code-centric to agent-centric security. Key insights on managing non-deterministic AI behavior, the security implications of agent skills, and the necessity of agentic security frameworks for enterprise adoption.
-
Agentic AI introduces novel security vectors, including prompt injection and context supply chain attacks. This analysis outlines the 'Lethal Trifecta' of agent vulnerabilities and provides a framework for implementing least-privilege controls, context manifests, and human-in-the-loop governance to mitigate risk in AI-native engineering teams.
-
Andrew Hashka, Field CTO at GitLab, reveals why most enterprise AI strategies fail by focusing solely on coding. Discover how to leverage agentic workflows, robust governance, and cultural shifts to unlock sustainable productivity and competitive advantage in the software lifecycle.
-
Dan Lorink of Chainguard analyzes the exponential divergence between AI-driven development speed and legacy security postures. This brief outlines strategies for securing autonomous agents, optimizing CI/CD pipelines for high-volume code generation, and adapting open source maintenance models to agentic workflows.
-
Snyk reveals that 13.4% of published AI agent skills contain critical security vulnerabilities. This analysis explores the emerging threat landscape of prompt injections, obfuscated code, and supply chain risks in LLM ecosystems, offering actionable strategies for developers and security teams to mitigate these risks.
-
Docker's EVP of Engineering details the strategic pivot to free, open-source hardened container images. This move addresses the $60 billion supply chain threat landscape while establishing a secure foundation for the emerging AI agent economy.