August 16, 2026 · Weekly Edition DevSecOps Weekly One unrevoked token, three tools deep, and 434,000 CI/CD pipelines in the blast radius. The LiteLLM / Team PCP disclosures dominate this week, and the tooling answer — registry egress control, SHA pinning, signed images — arrived alongside them. Around that: CRA…
Category: Secure
DevSecOps Weekly — August 16, 2026 — Interactive Topic Map
DevSecOps Weekly — August 9, 2026 — Interactive Topic Map
DevSecOps Weekly — August 9, 2026
August 9, 2026 · Weekly Edition DevSecOps Weekly A quiet week by article count but a pointed one by theme: two studies measured how often the humans supervising AI coding agents actually catch the dangerous requests, AWS and GitHub shipped structure — orchestration and stacked pull requests — to make…
DevSecOps Weekly — August 2, 2026
August 2, 2026 · Weekly Edition DevSecOps Weekly The package registries took direct hits again — an obfuscated RAT rode two Joyfill npm packages, an AI agent published a malicious PyPI package that fifteen real systems then installed and ran, and a compromised ad-network script quietly swapped crypto wallet addresses….