This week's articles
Securing the software factory at machine speed
GitLab's CISO argues that agentic AI development requires security, governance, and guardrails embedded in the SDLC execution path. The key metric is time from detection to verified remediation, driven to machine speed using AI-powered triage, constrained agent identities, and continuous scanning.
Test-driving Jev on a security task: identity resolution
Test-driving Jev, a decision model trained for calibrated probabilities, on identity resolution across five data sets. Compared against gpt-oss-20b, Claude Haiku 4.5, Sonnet 5 and Opus 5.5, and traditional entity resolution (Fellegi-Sunter and gradient-boosted trees), with cost, latency, prompt, stability and error analysis.
Enforce positive security with Cloudflare Application Profiles
Cloudflare Application Profiles launches a positive security layer for web apps: it learns HTTP request structure from traffic, flags deviations (type mismatches, out-of-range values, invalid UUIDs), and exposes violations as metadata for Security Rules enforcement.
How DigitalOcean Manages Credentials for Autonomous Agents
DigitalOcean Managed Agents secure autonomous workloads by ensuring agents never hold live credentials directly, utilizing ephemeral execution-time brokering via Action Gateway and strict runtime boundaries. This architecture aligns with NVIDIA's Open Agent Safety Platform and OpenShell policy schemas to prevent data exfiltration and limit blast radii across agent swarms.
Google's PageBreak Project
By combining agentic reasoning with live-site verification, PageBreak uncovered complex logic flaws that traditional scanners will often miss. The post shows three examples of high-severity vulnerabilities PageBreak found in Google applications.
|