{"id":6050,"date":"2026-10-11T14:27:57","date_gmt":"2026-10-11T19:27:57","guid":{"rendered":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=6050"},"modified":"2026-10-11T14:27:57","modified_gmt":"2026-10-11T19:27:57","slug":"devsecops-weekly-october-11-2026","status":"publish","type":"post","link":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=6050","title":{"rendered":"DevSecOps Weekly \u2014 October 11, 2026"},"content":{"rendered":"<style>\n.single .entry-title,\n.single .entry-header .entry-title,\n.single .post-title,\n.single header.entry-header h1,\n.single h1.entry-title,\n.single .page-title,\n.post-template-default h1.entry-title,\n.post-template-default .entry-header,\narticle .entry-header,\narticle .entry-title { display: none !important; }\n.single .entry-header { margin: 0 !important; padding: 0 !important; }\n.single .entry-content { margin-top: 0 !important; padding-top: 0 !important; }\n<\/style>\n<table role=\"presentation\" class=\"wrapper\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"100%\">\n<tr>\n<td align=\"center\">\n<table role=\"presentation\" class=\"container\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"680\">\n<p>        <!-- Banner --><\/p>\n<tr>\n<td class=\"banner\" style=\"background-color:#082f49;background:linear-gradient(135deg,#082f49 0%,#0c4a6e 50%,#0891b2 100%);padding:36px 32px;color:#ffffff;\">\n<p class=\"date\" style=\"color:#ffffff !important;\">October 11, 2026 &middot; Weekly Edition<\/p>\n<h1 style=\"color:#ffffff !important;\">DevSecOps Weekly<\/h1>\n<p class=\"tagline\" style=\"color:#ffffff !important;\">Five of the world&rsquo;s largest banks now fund <strong>OSERA<\/strong>, a shared pipeline for attested open-source fixes that has already patched more than <strong>50<\/strong> Spring and Java projects. Linux 7.2 carried <strong>1,111<\/strong> AI-assisted commits, and AI coding tools are slipping code past SBOMs as the <strong>CRA<\/strong> moves toward mandatory SBOMs. <strong>OpenSSH 10.6<\/strong> turns on a post-quantum signature. One survey finds teams spending <strong>16.9 hours<\/strong> a week debugging and <strong>9.8<\/strong> writing code. Twenty-five stories.<\/p>\n<\/td>\n<\/tr>\n<p>        <!-- At a glance --><\/p>\n<tr>\n<td class=\"content\">\n<h2>This week at a glance<\/h2>\n<p>Open Source Summit Europe in Prague set the agenda this week, and the theme was <strong>who pays to fix open source, and how they prove the fix<\/strong>. FINOS launched the <strong>Open Source Enterprise Resiliency Alliance (OSERA)<\/strong> with six premier members, among them <strong>Deutsche Bank, Goldman Sachs, Morgan Stanley, NatWest and Royal Bank of Canada<\/strong>. The banks are tired of building the same patches separately; the release says one in five financial institutions keeps private forks of the same projects. In about three weeks the alliance published v0.1 of a patching and attestation standard and delivered attested updates for more than <strong>50<\/strong> Spring and Java projects. It is aiming for at least <strong>80<\/strong> patches a month through the end of the year. The OpenSSF added members including <strong>JetBrains<\/strong>, published CRA readiness guides, and showed <strong>Ericsson<\/strong> sending more than <strong>1,400<\/strong> fixes upstream instead of keeping private forks.<\/p>\n<p>The second thread is <strong>SBOMs that no longer describe what ships<\/strong>. TechTarget&rsquo;s report from Prague counts <strong>1,111<\/strong> commits tagged Assisted-by in Linux 7.2, against <strong>31<\/strong> in 7.0. Speakers warned that an agent can paste old, vulnerable open-source code into an application without it ever appearing in the SBOM, and that slopsquatted packages get listed as if they were legitimate. CRA vulnerability reporting has been in force since September, and SBOMs become mandatory in <strong>December 2027<\/strong>. The OpenChain Automotive SBOM Framework 1.0 gives car makers and suppliers one SBOM format to exchange. A CSO Online opinion piece argues that enterprises should link their SBOMs, cryptography BOMs and AI BOMs in one evidence graph instead of running six programs.<\/p>\n<p>The third thread is <strong>the comprehension gap<\/strong>. An Undo-commissioned survey of 300 engineering leaders found teams spending <strong>16.9 hours<\/strong> a week debugging and <strong>9.8<\/strong> producing code, with <strong>35%<\/strong> of generated code reaching production before anyone fully understands it. Stack Overflow&rsquo;s 2026 survey of <strong>30,903<\/strong> developers found only <strong>6.6%<\/strong> trust AI with important decisions. <strong>OpenSSH 10.6<\/strong> enabled the hybrid <code>ssh-mldsa44-ed25519<\/code> signature, and its maintainers said they will release more often after a flood of security reports, many of them found with AI. On the controls side, a CNCF post argues agents should never get root and should instead propose the next system state through the normal pipeline. NIST&rsquo;s NCCoE says its next DevSecOps build will demonstrate agentic AI writing, building and testing code.<\/p>\n<div class=\"watchlist\">\n<h2>On our watch list<\/h2>\n<ul>\n<li><strong>OSERA&rsquo;s first end-to-end platform release in November.<\/strong> FINOS plans it for the Open Source in Finance Forum in New York, together with a per-project sponsorship model. Watch whether it hits the 80-patches-a-month target and whether banks outside the founding group sign up.<\/li>\n<li><strong>Whether OSERA&rsquo;s attestation standard spreads beyond finance.<\/strong> Version 0.1 sets what a fix must meet before it is trusted. Watch for other regulated sectors, or the OpenSSF, adopting or aligning with it.<\/li>\n<li><strong>How SBOM tooling answers agent-inserted code.<\/strong> Static SBOMs miss code an agent copies in. Watch for continuous or build-time SBOM generation becoming the default, and for CRA guidance that addresses AI-assisted development directly.<\/li>\n<li><strong>NIST NCCoE DevSecOps comment deadline, 9 November.<\/strong> The webinar on 28 October covers Build 3, which will use agentic AI to develop, build and test code, and joint work on AI agent identity and authorisation. Watch what controls the reference build puts around the agent.<\/li>\n<li><strong>Post-quantum SSH in the wild.<\/strong> OpenSSH 10.6 enables <code>ssh-mldsa44-ed25519<\/code>. Watch for distributions shipping 10.6, for the hybrid algorithm becoming a default, and for incompatibilities with old experimental keys.<\/li>\n<li><strong>OpenSSH&rsquo;s faster release cadence.<\/strong> The maintainers tied it to a surge of AI-found security reports. Watch how many fixes the next few point releases carry, and whether other core projects follow.<\/li>\n<li><strong>Where open-source projects draw the AI line.<\/strong> COSMIC now requires contributors to declare no AI-generated content; a GNOME developer is pushing to accept AI-found bug reports. Watch for KDE and GNOME formal decisions and for policies that split &ldquo;AI found it&rdquo; from &ldquo;AI wrote it&rdquo;.<\/li>\n<li><strong>AGNTCon + MCPCon North America, 22&ndash;23 October in San Jose.<\/strong> The Agentic AI Foundation now has 270 members. Watch for agent authorisation and tool-call security on the agenda.<\/li>\n<li><strong>Open Source SecurityCon North America, 9 November in Salt Lake City.<\/strong> Watch for the first CRA reporting experience from manufacturers and for BOMHort and other SBOM governance tools maturing in the OpenSSF sandbox.<\/li>\n<li><strong>Whether review time becomes a tracked delivery metric.<\/strong> The Undo survey has 79% of leaders saying agents write code faster with no faster releases. Watch for teams measuring time-to-understand and review load alongside DORA metrics.<\/li>\n<\/ul><\/div>\n<p>            <!-- Topic map --><\/p>\n<div class=\"topic-map\">\n              <img decoding=\"async\" src=\"https:\/\/www.cybersecurityinstitute.com\/blog\/wp-content\/uploads\/2026\/10\/topic-map-devsecops-2026-10-11.png\" alt=\"Topic map of this week's DevSecOps Weekly stories\" loading=\"eager\"><\/p>\n<p class=\"caption\">This week&rsquo;s topic map: open-source supply chain at the centre. One cluster holds OSERA, FINOS and the banks funding shared, attested fixes. Another holds the EU Cyber Resilience Act, SBOMs, AI-inserted code, slopsquatting, OpenChain Automotive and SPDX. A third covers the comprehension gap: AI-generated code, debugging time, developer trust and review. Around them sit the controls (EPSS prioritisation, secrets rotation, propose-not-apply agents, NIST NCCoE) and OpenSSH&rsquo;s post-quantum signatures.<\/p>\n<p>              <!-- INTERACTIVE_MAP_LINK_START --><\/p>\n<p style=\"margin:10px 0 0;text-align:center;\"><a href=\"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=6049\" target=\"_blank\" rel=\"noopener\" style=\"display:inline-block;padding:8px 18px;background-color:#0f172a;color:#ffffff !important;text-decoration:none;border-radius:6px;font-size:13px;font-weight:600;\">View interactive topic map &rarr;<\/a><\/p>\n<p><!-- INTERACTIVE_MAP_LINK_END -->\n            <\/div>\n<p>            <!-- Article index --><\/p>\n<h2>Article index<\/h2>\n<h3>Fixing the commons together<\/h3>\n<div class=\"cluster-intro\">Banks pooling the cost of open-source fixes, the OpenSSF adding CRA guidance and members, OSPOs taking on AI governance, and projects drawing lines on AI-written code and AI-found bugs.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>1. <a href=\"https:\/\/www.linuxfoundation.org\/press\/major-banks-back-osera-to-deliver-industry-wide-remediation-standards-and-fixes-to-secure-open-source-software\">Major Banks Back OSERA to Deliver Industry Wide Remediation Standards and Fixes to Secure Open Source Software<\/a><\/td>\n<td class=\"src\">Linux Foundation<br \/><span style=\"font-size:11px;color:#94a3b8;text-transform:none;letter-spacing:0;\">Press release from FINOS, the initiative&rsquo;s home<\/span><\/td>\n<td class=\"dt\">Oct 7, 2026<\/td>\n<\/tr>\n<tr>\n<td>2. <a href=\"https:\/\/openssf.org\/press-release\/2026\/10\/06\/openssf-shares-expanded-membership-and-new-global-policy-resources-during-community-day-europe\/\">OpenSSF Shares Expanded Membership and New Global Policy Resources During Community Day Europe<\/a><\/td>\n<td class=\"src\">OpenSSF<br \/><span style=\"font-size:11px;color:#94a3b8;text-transform:none;letter-spacing:0;\">Press release<\/span><\/td>\n<td class=\"dt\">Oct 6, 2026<\/td>\n<\/tr>\n<tr>\n<td>3. <a href=\"https:\/\/www.linuxfoundation.org\/blog\/navigating-open-source-governance-in-the-age-of-artificial-intelligence-the-2026-state-of-ospos-and-open-source-management\">Navigating Open Source Governance in the Age of Artificial Intelligence: The 2026 State of OSPOs and Open Source Management<\/a><\/td>\n<td class=\"src\">Linux Foundation<\/td>\n<td class=\"dt\">Oct 6, 2026<\/td>\n<\/tr>\n<tr>\n<td>4. <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/10\/07\/openssh-10-6-released\/\">OpenSSH 10.6 enables a post-quantum signature algorithm, so experimental keys need replacing<\/a><\/td>\n<td class=\"src\">Help Net Security<\/td>\n<td class=\"dt\">Oct 7, 2026<\/td>\n<\/tr>\n<tr>\n<td>5. <a href=\"https:\/\/www.theregister.com\/software\/2026\/10\/07\/cosmic-shuts-the-door-on-ai-code-as-gnome-debates-letting-bug-reports-in\/5301141?ref=taaft\">COSMIC shuts the door on AI code as GNOME debates letting bug reports in<\/a><\/td>\n<td class=\"src\">The Register<\/td>\n<td class=\"dt\">Oct 7, 2026<\/td>\n<\/tr>\n<\/table>\n<h3>SBOMs, the CRA and evidence<\/h3>\n<div class=\"cluster-intro\">AI coding tools are putting code into products that never shows up in the SBOM, just as the CRA makes SBOMs mandatory. Automotive gets a common SBOM framework, and one practitioner argues for a single evidence graph instead of six BOM programs.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>6. <a href=\"https:\/\/www.techtarget.com\/it-infrastructure\/news\/366651862\/AI-coding-tools-run-riot-over-SBOM-controls-as-EU-CRA-looms\">AI coding tools run riot over SBOM controls as EU CRA looms<\/a><\/td>\n<td class=\"src\">TechTarget<\/td>\n<td class=\"dt\">Oct 9, 2026<\/td>\n<\/tr>\n<tr>\n<td>7. <a href=\"https:\/\/www.linuxfoundation.org\/press\/linux-foundation-releases-openchain-automotive-sbom-framework-1.0-for-greater-reliability-and-traceability-in-automotive-software\">Linux Foundation Releases OpenChain Automotive SBOM Framework 1.0 for Greater Reliability and Traceability in Automotive Software<\/a><\/td>\n<td class=\"src\">Linux Foundation<br \/><span style=\"font-size:11px;color:#94a3b8;text-transform:none;letter-spacing:0;\">Press release<\/span><\/td>\n<td class=\"dt\">Oct 7, 2026<\/td>\n<\/tr>\n<tr>\n<td>8. <a href=\"https:\/\/www.csoonline.com\/article\/4231283\/your-enterprise-doesnt-need-six-bom-programs-it-needs-one-evidence-graph.html\">Your enterprise doesn&#8217;t need six BOM programs. It needs one evidence graph<\/a><\/td>\n<td class=\"src\">CSO Online<br \/><span style=\"font-size:11px;color:#94a3b8;text-transform:none;letter-spacing:0;\">Opinion (contributor)<\/span><\/td>\n<td class=\"dt\">Oct 7, 2026<\/td>\n<\/tr>\n<\/table>\n<h3>Prioritise, contain, bound<\/h3>\n<div class=\"cluster-intro\">Practical controls: rank vulnerabilities by exploitation and reachability, revoke and rotate leaked secrets, and make agents propose changes instead of applying them.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>9. <a href=\"https:\/\/www.infoworld.com\/article\/4229731\/knowing-which-vulnerability-to-fix-first.html\">Knowing which vulnerability to fix first<\/a><\/td>\n<td class=\"src\">InfoWorld<br \/><span style=\"font-size:11px;color:#94a3b8;text-transform:none;letter-spacing:0;\">Author built the open-source tool he describes<\/span><\/td>\n<td class=\"dt\">Oct 5, 2026<\/td>\n<\/tr>\n<tr>\n<td>10. <a href=\"https:\/\/devops.com\/secrets-sprawl-and-rotation-a-practical-vault-management-playbook\/\">Secrets Sprawl and Rotation: A Practical Vault Management Playbook<\/a><\/td>\n<td class=\"src\">DevOps.com<br \/><span style=\"font-size:11px;color:#94a3b8;text-transform:none;letter-spacing:0;\">Contributed content<\/span><\/td>\n<td class=\"dt\">Oct 8, 2026<\/td>\n<\/tr>\n<tr>\n<td>11. <a href=\"https:\/\/www.cncf.io\/blog\/2026\/10\/08\/dont-give-ai-agents-root-make-them-propose-the-next-system-state\/\">Don&#8217;t give AI agents root. Make them propose the next system state.<\/a><\/td>\n<td class=\"src\">CNCF<br \/><span style=\"font-size:11px;color:#94a3b8;text-transform:none;letter-spacing:0;\">CNCF Ambassador post; author maintains Kairos<\/span><\/td>\n<td class=\"dt\">Oct 8, 2026<\/td>\n<\/tr>\n<tr>\n<td>12. <a href=\"https:\/\/www.nist.gov\/news-events\/news\/2026\/09\/new-nist-nccoe-resources-devsecops-and-october-28-webinar-agentic-ai\">New NIST NCCoE Resources on DevSecOps and October 28 Webinar on Agentic AI<\/a><\/td>\n<td class=\"src\">NIST<\/td>\n<td class=\"dt\">Sep 24, 2026<\/td>\n<\/tr>\n<tr>\n<td>13. <a href=\"https:\/\/www.infoq.com\/articles\/platform-engineering-playbook-production-llms\/\">The Platform Engineering Playbook for Production LLMs<\/a><\/td>\n<td class=\"src\">InfoQ<\/td>\n<td class=\"dt\">Oct 5, 2026<\/td>\n<\/tr>\n<\/table>\n<h3>The comprehension gap<\/h3>\n<div class=\"cluster-intro\">Code arrives faster than teams can understand it. Surveys and studies on where the time goes, and what that does to review, debugging and trust.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>14. <a href=\"https:\/\/www.infoq.com\/news\/2026\/10\/survey-complex-codebases-agents\/\">Survey Finds AI-Generated Code Increases Debugging and Failure Rates and Creates a Comprehension Gap<\/a><\/td>\n<td class=\"src\">InfoQ<br \/><span style=\"font-size:11px;color:#94a3b8;text-transform:none;letter-spacing:0;\">Vendor-commissioned survey (Undo)<\/span><\/td>\n<td class=\"dt\">Oct 7, 2026<\/td>\n<\/tr>\n<tr>\n<td>15. <a href=\"https:\/\/www.theregister.com\/software\/2026\/10\/10\/stack-overflow-survey-finds-devs-hooked-on-ai-but-not-totally-sold-on-its-judgment\/5301662\">Stack Overflow survey finds devs hooked on AI, but not totally sold on its judgment<\/a><\/td>\n<td class=\"src\">The Register<br \/><span style=\"font-size:11px;color:#94a3b8;text-transform:none;letter-spacing:0;\">Covers Stack Overflow&rsquo;s 2026 Developer Survey<\/span><\/td>\n<td class=\"dt\">Oct 10, 2026<\/td>\n<\/tr>\n<tr>\n<td>16. <a href=\"https:\/\/leaddev.com\/software-quality\/faster-code-isnt-faster-delivery\">Faster code isn&#8217;t faster delivery<\/a><\/td>\n<td class=\"src\">LeadDev<\/td>\n<td class=\"dt\">Oct 6, 2026<\/td>\n<\/tr>\n<tr>\n<td>17. <a href=\"https:\/\/drops.dagstuhl.de\/entities\/document\/10.4230\/LIPIcs.ESEM.2026.67\">Does Working with AI Agents Change How Developers Code, Test, and Review?<\/a><\/td>\n<td class=\"src\">Dagstuhl LIPIcs (ESEM 2026)<br \/><span style=\"font-size:11px;color:#94a3b8;text-transform:none;letter-spacing:0;\">Peer-reviewed study (ESEM 2026)<\/span><\/td>\n<td class=\"dt\">Oct 5, 2026<\/td>\n<\/tr>\n<tr>\n<td>18. <a href=\"https:\/\/www.infoworld.com\/article\/4231345\/cursor-writes-all-my-code-now.html\">Cursor writes all my code now<\/a><\/td>\n<td class=\"src\">InfoWorld<\/td>\n<td class=\"dt\">Oct 7, 2026<\/td>\n<\/tr>\n<tr>\n<td>19. <a href=\"https:\/\/www.infoworld.com\/article\/4229802\/ai-changed-my-role-before-it-changed-my-software.html\">AI changed my role before it changed my software<\/a><\/td>\n<td class=\"src\">InfoWorld<\/td>\n<td class=\"dt\">Oct 8, 2026<\/td>\n<\/tr>\n<\/table>\n<h3>Agents, teams and the junior pipeline<\/h3>\n<div class=\"cluster-intro\">How teams are reorganising around coding agents, and who learns the craft when agents take the entry-level work.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>20. <a href=\"https:\/\/leaddev.com\/ai\/ai-coding-tools-could-be-breaking-the-junior-engineer-pipeline\">AI-coding tools could be breaking the junior engineer pipeline<\/a><\/td>\n<td class=\"src\">LeadDev<\/td>\n<td class=\"dt\">Oct 5, 2026<\/td>\n<\/tr>\n<tr>\n<td>21. <a href=\"https:\/\/devops.com\/ai-is-taking-on-entry-level-engineering-work-who-trains-the-young-engineers\/\">AI Is Taking on Entry-Level Engineering Work. Who Trains the Young Engineers?<\/a><\/td>\n<td class=\"src\">DevOps.com<br \/><span style=\"font-size:11px;color:#94a3b8;text-transform:none;letter-spacing:0;\">Contributed content<\/span><\/td>\n<td class=\"dt\">Oct 7, 2026<\/td>\n<\/tr>\n<tr>\n<td>22. <a href=\"https:\/\/leaddev.com\/ai\/software-developers-are-becoming-agent-builders\">Software developers are becoming agent builders<\/a><\/td>\n<td class=\"src\">LeadDev<\/td>\n<td class=\"dt\">Oct 8, 2026<\/td>\n<\/tr>\n<tr>\n<td>23. <a href=\"https:\/\/www.oreilly.com\/radar\/coding-agents-love-decision-records\/\">Coding Agents Love Decision Records<\/a><\/td>\n<td class=\"src\">O&#x27;Reilly Radar<\/td>\n<td class=\"dt\">Oct 2, 2026<\/td>\n<\/tr>\n<tr>\n<td>24. <a href=\"https:\/\/www.infoq.com\/presentations\/agentic-dev-teams\/\">The Reinvention of the Dev Team<\/a><\/td>\n<td class=\"src\">InfoQ<br \/><span style=\"font-size:11px;color:#94a3b8;text-transform:none;letter-spacing:0;\">QCon London talk<\/span><\/td>\n<td class=\"dt\">Oct 7, 2026<\/td>\n<\/tr>\n<tr>\n<td>25. <a href=\"https:\/\/stackoverflow.blog\/2026\/10\/07\/part-6-an-operating-system-for-coding-agents-the-disciplined-build\/\">Part 6: An operating system for coding agents: the disciplined build<\/a><\/td>\n<td class=\"src\">Stack Overflow Blog<\/td>\n<td class=\"dt\">Oct 7, 2026<\/td>\n<\/tr>\n<\/table>\n<p>            <!-- Detailed write-ups --><\/p>\n<h2>Detailed write-ups<\/h2>\n<div class=\"article\">\n<h4>1. Banks stop paying the &ldquo;fork tax&rdquo; alone: OSERA ships attested open-source fixes<\/h4>\n<p class=\"meta\">Linux Foundation &middot; October 7, 2026<\/p>\n<p>FINOS, the Linux Foundation&rsquo;s financial-services foundation, announced at Open Source Summit Europe that the <strong>Open Source Enterprise Resiliency Alliance (OSERA)<\/strong> is operational. Six premier members fund it; the release names <strong>Deutsche Bank, Goldman Sachs, Morgan Stanley, NatWest and Royal Bank of Canada<\/strong>. The problem they want to fix is duplication. Banks running the same open-source projects each build, or pay someone to build, the same patches. Research cited in the release says one in five financial institutions keeps private versions of the same projects, which it calls the <strong>&ldquo;fork tax&rdquo;<\/strong>.<\/p>\n<p>The alliance has moved quickly. In about three weeks it published version <strong>0.1<\/strong> of a patching and attestation standard, which sets what a fix must meet before members trust it. It has delivered attested security updates for more than <strong>50<\/strong> widely used Spring and Java projects, available to members for production use. Vendor maintainers will handle newly disclosed vulnerabilities on managed release lines under a severity-based SLA, with a target of at least <strong>80<\/strong> patches a month through the end of 2026. RBC helps lead governance of the backporting pipelines. The first end-to-end platform release is planned for the Open Source in Finance Forum in New York in November. Morgan Stanley&rsquo;s <strong>Dov Katz<\/strong>, who chairs the remediation standards working group: <strong>&ldquo;An open, verifiable standard for remediation delivers trust at scale.&rdquo;<\/strong><\/p>\n<p>For DevSecOps teams outside finance, two things matter. First, a published attestation standard for backported fixes gives everyone a way to ask a supplier how a patch was built and checked. Second, it treats the long tail of unmaintained release lines as a shared cost instead of each organisation&rsquo;s private problem. The CRA&rsquo;s five-year patch duty creates exactly the same pressure for manufacturers. This is the initiative&rsquo;s own press release, and the funding banks have an obvious interest in the outcome.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.linuxfoundation.org\/press\/major-banks-back-osera-to-deliver-industry-wide-remediation-standards-and-fixes-to-secure-open-source-software\">https:\/\/www.linuxfoundation.org\/press\/major-banks-back-osera-to-deliver-industry-wide-remediation-standards-and-fixes-to-secure-open-source-software<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>2. AI coding tools are putting code into products that the SBOM never sees<\/h4>\n<p class=\"meta\">TechTarget &middot; October 9, 2026 &middot; CSO Online &middot; October 7, 2026<\/p>\n<p>Bruce Gain&rsquo;s report from Open Source Summit Europe brings numbers to a problem many teams suspect. A Linux Foundation survey of more than 600 respondents found <strong>94%<\/strong> use or pilot generative AI coding tools, and <strong>48%<\/strong> say the tools have increased their use of open source. In the kernel, Linux 7.2 carried <strong>1,111<\/strong> commits with an Assisted-by tag, against <strong>31<\/strong> in Linux 7.0, and added about 600,000 lines from a record 2,652 developers.<\/p>\n<p>Speakers described three ways this breaks SBOMs. An agent can copy old open-source code into an application, CVEs and all, without the component ever being declared. Omdia&rsquo;s <strong>Torsten Volk<\/strong>: <strong>&ldquo;an agent could grab some old open source code with CVEs attached&rdquo;<\/strong>. Static SBOMs taken at one point in time miss code agents add later. And <strong>slopsquatting<\/strong>, where attackers publish packages under names AI models invent, means the SBOM can faithfully list a malicious package that was installed in good faith. Kubermatic&rsquo;s <strong>Mario Fahlandt<\/strong>, a CNCF TOC member, runs a weekly job that scans CNCF projects with 2,500 workers and has stored 16,000 SBOMs: <strong>&ldquo;If we don&rsquo;t know which packages are inside of our software, we don&rsquo;t know if there&rsquo;s a security issue.&rdquo;<\/strong> CRA vulnerability reporting has applied since September; SBOMs become mandatory under the CRA in <strong>December 2027<\/strong>.<\/p>\n<p>A CSO Online opinion piece by HCLTech consultant Sunil Gentyala argues the answer is not more BOM programs. Software, cryptography, AI and emerging authorisation BOMs should keep their native formats (SPDX 3.0.1, CycloneDX 1.7) but be linked in one <strong>evidence graph<\/strong> with a common envelope: subject, version, digest, owner, validity and known gaps. He proposes a 90-day pilot on one critical service, comparing what was declared with the released binary and the deployment, and measuring time to find affected deployments rather than the number of SBOM files.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.techtarget.com\/it-infrastructure\/news\/366651862\/AI-coding-tools-run-riot-over-SBOM-controls-as-EU-CRA-looms\">https:\/\/www.techtarget.com\/it-infrastructure\/news\/366651862\/AI-coding-tools-run-riot-over-SBOM-controls-as-EU-CRA-looms<\/a>, <a href=\"https:\/\/www.csoonline.com\/article\/4231283\/your-enterprise-doesnt-need-six-bom-programs-it-needs-one-evidence-graph.html\">https:\/\/www.csoonline.com\/article\/4231283\/your-enterprise-doesnt-need-six-bom-programs-it-needs-one-evidence-graph.html<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>3. OpenSSF adds CRA guidance and members as OSPOs take on AI governance<\/h4>\n<p class=\"meta\">OpenSSF &middot; October 6, 2026 &middot; Linux Foundation &middot; October 6, 2026<\/p>\n<p>At Community Day Europe the OpenSSF welcomed four new general members: <strong>A-Team Systems, Emphere, DACHS IT GmbH and JetBrains<\/strong>. It published a <strong>CRA Readiness practitioner&rsquo;s guide<\/strong> and a CRA Readiness User Journey, plus role-based journeys for developers, security engineers, OSPO leaders and executives. A case study shows <strong>Ericsson Software Technology<\/strong> sending more than <strong>1,400<\/strong> dependency updates and security fixes upstream and retiring its private forks. OpenBao v2.6 shipped, and <strong>BOMHort<\/strong>, a Kubernetes-native SBOM visualisation and governance tool, joined the OpenSSF Sandbox. General manager <strong>Steve Fernandez<\/strong>: <strong>&ldquo;Securing the open source ecosystem is no longer just about patching isolated vulnerabilities.&rdquo;<\/strong><\/p>\n<p>The Linux Foundation&rsquo;s 2026 State of OSPOs report, released the same day, shows where that work lands inside companies. <strong>53%<\/strong> of large enterprises now have a formally structured OSPO. Of OSPOs involved in AI governance, <strong>79%<\/strong> work on policy, evaluation of open models and datasets, risk and legal review, and <strong>85%<\/strong> are brought in at or before technology selection. Licensing and security vulnerabilities are each managed as AI risks by <strong>65%<\/strong>. <strong>69%<\/strong> of organisations are prototyping or running agentic tools for OSPO work, and <strong>18%<\/strong> already run them in production. The top outcome OSPOs report is software quality, security and compliance (<strong>58%<\/strong>).<\/p>\n<p>The Ericsson case and OSERA make the same point from two directions: fixing upstream is cheaper than carrying forks. If your organisation has an OSPO, it is probably already part of AI tool selection, and it is the natural owner of CRA open-source obligations.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/openssf.org\/press-release\/2026\/10\/06\/openssf-shares-expanded-membership-and-new-global-policy-resources-during-community-day-europe\/\">https:\/\/openssf.org\/press-release\/2026\/10\/06\/openssf-shares-expanded-membership-and-new-global-policy-resources-during-community-day-europe\/<\/a>, <a href=\"https:\/\/www.linuxfoundation.org\/blog\/navigating-open-source-governance-in-the-age-of-artificial-intelligence-the-2026-state-of-ospos-and-open-source-management\">https:\/\/www.linuxfoundation.org\/blog\/navigating-open-source-governance-in-the-age-of-artificial-intelligence-the-2026-state-of-ospos-and-open-source-management<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>4. Car makers get one SBOM framework to exchange across the supply chain<\/h4>\n<p class=\"meta\">Linux Foundation &middot; October 7, 2026<\/p>\n<p>The Linux Foundation released <strong>OpenChain Automotive SBOM Framework 1.0<\/strong>, a common approach for creating and sharing SBOMs between automotive suppliers and OEMs. It defines how components and dependencies are structured, which data fields are required and which are recommended, and the criteria an SBOM must meet to count as complete and of adequate quality. It includes usage scenarios for data exchange across the supply chain.<\/p>\n<p>The framework aligns with <strong>SPDX<\/strong> (ISO\/IEC 5962) rather than replacing it. It comes from the OpenChain Automotive Working Group, chaired by Masato Endo, with participants including <strong>Toyota, Nissan, Volvo Cars and Hitachi Solutions<\/strong>. OpenChain general manager <strong>Mary Meixia Wang<\/strong>: <strong>&ldquo;This first release provides practical guidance and helps advance more consistent SBOM practices.&rdquo;<\/strong> The release cites growing regulatory and cybersecurity pressure but does not name specific regulations.<\/p>\n<p>The value is in the quality criteria. Many SBOMs that pass between companies today are technically valid and practically useless, because each party fills different fields. A sector-wide definition of a complete SBOM gives suppliers a target and gives OEMs something to reject against. Teams in other industries with long supply chains can borrow the approach.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.linuxfoundation.org\/press\/linux-foundation-releases-openchain-automotive-sbom-framework-1.0-for-greater-reliability-and-traceability-in-automotive-software\">https:\/\/www.linuxfoundation.org\/press\/linux-foundation-releases-openchain-automotive-sbom-framework-1.0-for-greater-reliability-and-traceability-in-automotive-software<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>5. OpenSSH 10.6 turns on a post-quantum signature and speeds up releases<\/h4>\n<p class=\"meta\">Help Net Security &middot; October 7, 2026<\/p>\n<p><strong>OpenSSH 10.6<\/strong>, released on 6 October, enables the hybrid signature algorithm <code>ssh-mldsa44-ed25519<\/code>, which pairs the post-quantum ML-DSA-44 with Ed25519. Keys generated with the earlier experimental support must be regenerated or removed. ssh and sshd also disable the LZ77 dictionary coder, which makes the Compression option less effective; the maintainers recommend compressing at the application level instead.<\/p>\n<p>Several hardening changes ride along. ssh now refuses usernames containing <code>$<\/code> or a backslash when they are passed on the command line, though names set with the User directive in config are exempt. sshd stores GSSAPI credentials only after authentication succeeds, sftp checks paths returned by the server more strictly, and a daylight-saving bug in ssh-keygen that could shift certificate expiry by up to an hour is fixed. GatewayPorts and StreamLocalForwarding are disabled on QNX 6, SCO OpenServer 5 and builds using <code>--disable-fd-passing<\/code>.<\/p>\n<p>The most telling line is about process. The maintainers will ship releases more often for now, after receiving a large number of security reports, many found by or with AI models, and they warn that others <strong>&ldquo;are likely to be able to discover these bugs too.&rdquo;<\/strong> For platform teams, that means shorter gaps between OpenSSH updates and less time to roll them out.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/10\/07\/openssh-10-6-released\/\">https:\/\/www.helpnetsecurity.com\/2026\/10\/07\/openssh-10-6-released\/<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>6. The comprehension gap: teams debug for 16.9 hours a week and write code for 9.8<\/h4>\n<p class=\"meta\">InfoQ &middot; October 7, 2026 &middot; The Register &middot; October 10, 2026<\/p>\n<p>A survey commissioned by <strong>Undo<\/strong>, which sells debugging and root-cause tools, and run by Coleman Parkes asked <strong>300<\/strong> senior engineering leaders responsible for mission-critical software, mostly in C and C++, where their time goes. The average team spends <strong>9.8 hours<\/strong> a week producing code and <strong>16.9 hours<\/strong> debugging it. <strong>35%<\/strong> of AI-generated code reaches production before the team fully understands it. In the past six months, <strong>81%<\/strong> had a production incident or outage, <strong>93%<\/strong> got an incorrect root-cause diagnosis from a hallucinating tool, and <strong>91%<\/strong> had test escapes or serious defects. <strong>79%<\/strong> say agents write code significantly faster, but releases are no faster. Undo&rsquo;s <strong>Greg Law<\/strong>: <strong>&ldquo;while agents are great at writing reams of code quickly, they&rsquo;re less capable at debugging it&rdquo;<\/strong>.<\/p>\n<p>Stack Overflow&rsquo;s 2026 Developer Survey, covered by The Register, shows developers responding the way you would expect. It drew <strong>30,903<\/strong> responses from 169 countries. About a third of daily AI users spend four or more hours a day with it. Yet only <strong>6.6%<\/strong> trust AI output for important work decisions, <strong>48%<\/strong> trust it only when they can easily verify it, and roughly <strong>four in five<\/strong> say source attribution matters when they judge an AI answer.<\/p>\n<p>The Undo numbers come from a vendor whose products address the problem the survey describes, so treat them as direction rather than measurement. They match what the Stack Overflow data and this week&rsquo;s practitioner essays say: code is cheap, understanding is not. For security that matters directly. Code nobody understands is code nobody can threat-model, and an incident in it starts with a slower diagnosis.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.infoq.com\/news\/2026\/10\/survey-complex-codebases-agents\/\">https:\/\/www.infoq.com\/news\/2026\/10\/survey-complex-codebases-agents\/<\/a>, <a href=\"https:\/\/www.theregister.com\/software\/2026\/10\/10\/stack-overflow-survey-finds-devs-hooked-on-ai-but-not-totally-sold-on-its-judgment\/5301662\">https:\/\/www.theregister.com\/software\/2026\/10\/10\/stack-overflow-survey-finds-devs-hooked-on-ai-but-not-totally-sold-on-its-judgment\/5301662<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>7. Severity is not priority: ranking fixes by exploitation and reachability<\/h4>\n<p class=\"meta\">InfoWorld &middot; October 5, 2026<\/p>\n<p><strong>Sonu Kapoor<\/strong> sets out a model that many teams will recognise and few apply consistently. <strong>CVSS<\/strong> describes how bad a vulnerability could be, not whether it is reachable or being exploited. <strong>EPSS<\/strong>, maintained by FIRST and updated daily, estimates the probability of exploitation in the next 30 days. <strong>CISA KEV<\/strong> records confirmed exploitation. His summary: <strong>&ldquo;Severity is a property of a vulnerability. Priority is a decision about a vulnerability in context.&rdquo;<\/strong><\/p>\n<p>He combines them into four lanes. Critical or high findings at or above the 90th EPSS percentile are <strong>Fix Now<\/strong>; those below it are <strong>Fix Soon<\/strong>. Medium or lower findings above the threshold go to <strong>Monitor<\/strong>, the rest to <strong>Lower Priority<\/strong>. In one example, a critical CVE sitting near the 77th percentile lands in Fix Soon, while a medium CVE above the 96th percentile is watched more closely. He adds reachability evidence from a Colorado State University study of 30 open-source projects and more than 6,000 scanner-reported CVEs: <strong>43.3%<\/strong> were statically unreachable, rising to <strong>53.1%<\/strong> for TypeScript and JavaScript.<\/p>\n<p>Kapoor implemented this model in CVE Lite CLI, an open-source tool he promotes in the piece. The method stands on its own: whatever scanner you use, adding EPSS, KEV and reachability to the sort order should remove a large share of the backlog from the urgent queue.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.infoworld.com\/article\/4229731\/knowing-which-vulnerability-to-fix-first.html\">https:\/\/www.infoworld.com\/article\/4229731\/knowing-which-vulnerability-to-fix-first.html<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>8. Don&rsquo;t give agents root: make them propose the next system state<\/h4>\n<p class=\"meta\">CNCF &middot; October 8, 2026 &middot; NIST &middot; September 24, 2026<\/p>\n<p>In a CNCF Ambassador post, <strong>Mauro Morales<\/strong>, who maintains the Kairos immutable OS project, argues against giving AI agents root or open host access. Instead, an agent inspects the system, records its assessment and opens a pull request that proposes the next state. Base-system changes live in a versioned definition and are consumed as a new image. The proposal goes through the same review, testing, image build, signing and release as a human change. The agent&rsquo;s identity may propose but may not approve or merge, change the pipeline, sign images or force a machine to take the new state. Agents run in short-lived environments sized to the threat model, and self-healing is limited to pre-authorised restart, replace or rollback. His line: <strong>&ldquo;We do not need to trust the model. We need to trust the boundaries around it.&rdquo;<\/strong><\/p>\n<p>NIST&rsquo;s National Cybersecurity Center of Excellence is heading the same way in its DevSecOps project. It added five items to its live document, including a mapping from the SSDF to DevSecOps practice and an updated AI section. <strong>Build 3<\/strong> will demonstrate agentic AI developing, building and testing code, in joint work with the NCCoE team on AI agent identity and authorisation. A webinar on <strong>28 October<\/strong> covers the plan, and comments are due by <strong>9 November<\/strong>.<\/p>\n<p>The pattern is worth adopting now. Routing agent changes through the same pipeline as human ones gives you review, provenance and signing for free, and separating the right to propose from the right to approve is a control auditors already understand.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.cncf.io\/blog\/2026\/10\/08\/dont-give-ai-agents-root-make-them-propose-the-next-system-state\/\">https:\/\/www.cncf.io\/blog\/2026\/10\/08\/dont-give-ai-agents-root-make-them-propose-the-next-system-state\/<\/a>, <a href=\"https:\/\/www.nist.gov\/news-events\/news\/2026\/09\/new-nist-nccoe-resources-devsecops-and-october-28-webinar-agentic-ai\">https:\/\/www.nist.gov\/news-events\/news\/2026\/09\/new-nist-nccoe-resources-devsecops-and-october-28-webinar-agentic-ai<\/a><\/p>\n<\/p><\/div>\n<p>            <!-- Calls to action --><\/p>\n<div class=\"watchlist\">\n<h2>Calls to action<\/h2>\n<ul>\n<li><strong>Count your private forks.<\/strong> List the open-source projects you patch internally instead of upstream. For each, decide whether to contribute the fix upstream, join a shared effort, or accept the cost of carrying it.<\/li>\n<li><strong>Generate SBOMs at build time, not at release.<\/strong> Agent-inserted code and copied snippets will not show up in an SBOM taken from a manifest. Make sure SBOMs come from the build and are compared with what actually deployed.<\/li>\n<li><strong>Check new dependencies for slopsquatting.<\/strong> Before an agent-suggested package is installed, confirm it exists with real history and maintainers. Block packages published in the last few days unless a person approves them.<\/li>\n<li><strong>Add EPSS and KEV to your vulnerability sort order.<\/strong> Rank findings by exploitation likelihood and reachability as well as CVSS, and agree a Fix Now threshold with engineering.<\/li>\n<li><strong>Revoke, then rotate.<\/strong> When a secret leaks, removing it from the repository is not enough. Revoke it first, rotate it, and scan internal repositories as well as public ones.<\/li>\n<li><strong>Inventory experimental post-quantum SSH keys.<\/strong> Any keys created with OpenSSH&rsquo;s earlier experimental post-quantum support must be regenerated or removed before or during the move to 10.6.<\/li>\n<li><strong>Take root away from agents.<\/strong> For any agent that changes infrastructure, require it to open a pull request through the normal pipeline. Make sure its identity cannot approve, merge or sign.<\/li>\n<li><strong>Comment on the NIST NCCoE DevSecOps material by 9 November.<\/strong> If you are building controls for agents in your SDLC, this is the reference implementation auditors will read.<\/li>\n<\/ul><\/div>\n<\/td>\n<\/tr>\n<p>        <!-- Footer --><\/p>\n<tr>\n<td class=\"footer\">\n<p class=\"brand\">DevSecOps Weekly<\/p>\n<p>A weekly intelligence bulletin from Security Radar LLC.<br \/>\n            Curated by Paul Davis &middot; <a href=\"mailto:paul.davis@security-radar.com\">paul.davis@security-radar.com<\/a><\/p>\n<p>&copy; 2026 Security Radar LLC. All rights reserved.<\/p>\n<p>Article titles and summaries are excerpted for review and commentary; all linked articles remain the copyright of their respective publishers and authors.<\/p>\n<p>*|LIST:ADDRESS|*<\/p>\n<p><a href=\"*|ARCHIVE|*\">View this email in your browser<\/a> &middot; <a href=\"*|UNSUB|*\">Unsubscribe<\/a><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>October 11, 2026 &middot; Weekly Edition DevSecOps Weekly Five of the world&rsquo;s largest banks now fund OSERA, a shared pipeline for attested open-source fixes that has already patched more than 50 Spring and Java projects. Linux 7.2 carried 1,111 AI-assisted commits, and AI coding tools are slipping code past SBOMs&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34,11],"tags":[],"class_list":["post-6050","post","type-post","status-publish","format-standard","hentry","category-secure","category-trends"],"_links":{"self":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/6050","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6050"}],"version-history":[{"count":1,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/6050\/revisions"}],"predecessor-version":[{"id":6065,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/6050\/revisions\/6065"}],"wp:attachment":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6050"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6050"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6050"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}