GitHub stories
Security teams may get findings within 24 hours as Cobalt targets faster testing across sprawling software estates.
Pressure is mounting on businesses to secure AI data and recover faster after cyber incidents, as static labels and ad hoc restoration prove too slow.
Stricter checks now govern the 15,000-star repository as Google tries to stop weak instructions and broken links hurting AI coding agents.
Three out of four offensive security investigations traced back to identity or privilege, exposing access gaps across cloud, SaaS and AI systems.
Nearly half of scanned MCP server builds carried at least one security concern, underscoring fresh supply chain risks as AI agents rely on them.
Developers can now break large code changes into smaller reviews as GitHub rolls the feature out across all repositories.
Malicious packages are now spreading faster across code repositories, with Google saying open source ecosystems face the sharpest rise in risk.
Security teams can now trace attack routes across AWS and Microsoft Entra, as SpecterOps extends BloodHound into hybrid and AI-linked environments.
Subscription merchants could gain faster access to local payment methods as Recurly taps Juspay's Hyperswitch for more than 300 providers.
Critical vulnerability backlogs have swelled 29-fold, prompting a tool that sends fix plans into engineering systems and AI coding tools.
Enterprise AI agents are already generating revenue, but shortages of compute and skills could determine who captures the gains.
Merchants on Recurly will gain access to more than 300 payment providers through one integration, helping curb failed recurring charges.
Developers using AI assistants could face stolen credentials and poisoned repositories as the worm hides inside normal coding workflows.
Companies and individual developers have helped sustain open source as GitHub Sponsors passes USD $100 million, easing pressure on maintainers.
Limited internal access resumed after monitored tests found the model could bypass safeguards, prompting OpenAI to tighten trajectory-level monitoring.
Developers can now track Claude Code sessions more reliably on their own machines, with Agent Island 1.7.1 fixing local monitoring on macOS and Windows.
The platform lets security teams run AI pentests without exposing customer infrastructure data to external models.
Security chiefs face a widening breach risk as most firms plan to use AI agents, yet barely a third feel ready to secure them properly.
AI agents can now draft payments and wallet actions while final approval stays on a Ledger device, limiting theft if software is compromised.
Smaller firms can now run web app pentests in hours, as Intruder's AI service cuts costs to a fraction of manual reviews.