Source Code Management (SCM) stories
Orca Security flags AI secrets & supply chain gaps
Last week
#
malware
#
devops
#
mfa
Orca Security warns that AI credentials, vulnerable dependencies and lax pipeline controls are leaving production environments exposed across US and Europe.
Cursor 3 retools coding workspace around AI agents
Last week
#
rpa
#
software development
#
agentic ai
Cursor 3 rebuilds the coding workspace around AI agents, adding cross-repository collaboration, cloud handoffs and review tools for developers.
Kestra raises USD $25 million to expand workflow platform
This month
#
saas
#
devops
#
hybrid cloud
Kestra secures USD $25 million from RTP Global to launch Kestra 2.0, roll out Kestra Cloud and expand in North America and Europe.
Liquibase launches database governance tools for enterprise
Last month
#
devops
#
rpa
#
apm
Liquibase rolls out AI-backed database governance and deployment connectors for ServiceNow, GitHub, Harness and Terraform to improve auditability.
Percona & Chainguard launch supported database images
Last month
#
virtualisation
#
devops
#
digital transformation
Percona teams up with Chainguard to offer supported, hardened container images for MySQL, PostgreSQL and MongoDB databases.
AppOmni adds Heisenberg mode after LiteLLM supply attack
Last month
#
virtualisation
#
cloud security
#
application security
AppOmni upgrades Heisenberg to help teams trace GitHub Actions and spot tainted dependencies after the LiteLLM supply chain breach.
Aerospike launches LangGraph memory layer for AI agents
Last month
#
open source
#
genai
#
llms
Aerospike adds durable memory for LangGraph agents to keep context through restarts, failures and concurrent sessions.
NetRise launches Provenance to trace open source risk
Last month
#
devops
#
iot security
#
iot
NetRise unveils Provenance, a tool to trace open source maintainers and stop risky dependencies before they spread through software.
'Human Risk' takes centre stage - Mimecast CEO
Last month
#
data protection
#
endpoint protection
#
phishing
Mimecast chief warns human risk is now cybersecurity's 'eighth layer' as malicious insiders overtake negligence in Australian attacks.
Veracode launches Fix for open-source vulnerability repair
Last month
#
devops
#
application security
#
devsecops
Veracode unveils an AI-driven tool that automatically fixes open-source vulnerabilities, tackling mounting security debt in software supply chains.
Trivy GitHub breach exposes CI/CD supply chain risk
Last month
#
devops
#
cloud security
#
application security
Aqua Security's Trivy GitHub Action was hijacked to ship infostealer code via CI/CD pipelines, exposing secrets across downstream users.
GitLab widens AI access & sets flat review pricing
Last month
#
devops
#
application security
#
devsecops
GitLab opens agentic AI to free-tier users, sets USD $0.25 flat fee for automated code reviews and expands security false-positive filtering.
BloodHound expands identity attack path mapping reach
Last month
#
data protection
#
encryption
#
pam
SpecterOps broadens BloodHound Enterprise to map identity attack paths across Okta, GitHub and Jamf-managed Macs in hybrid environments.
Entro launches AI agent governance tool for enterprises
Last month
#
data protection
#
digital transformation
#
cloud security
Entro launches AGA to map, monitor and control AI agents in enterprises, tackling shadow AI and non-human identity risks at scale.
Ultralytics launches end-to-end vision AI platform
Last month
#
edge computing
#
open source
#
ai
Ultralytics debuts an end-to-end vision AI platform, unifying labelling, training and deployment as firms demand tangible AI returns.
Cobalt unveils service to manage enterprise pentesting
Last month
#
devops
#
cloud security
#
application security
Cobalt launches Security Program Manager service to run enterprise pentesting, align tests with business goals and speed up remediation.
ThoughtSpot unveils Spotter AI agents tailored by sector
Last month
#
saas
#
data analytics
#
digital transformation
ThoughtSpot rolls out Spotter for Industries, AI analytics agents tuned to sector rules to close the “context gap” in enterprise decisions.
AI surge drives record secrets sprawl across GitHub
Last month
#
cloud security
#
application security
#
socs
AI-fuelled coding drives record 29 million hardcoded secrets on GitHub in 2025, with leaks from AI tools and services surging sharply.
Secure Code Warrior unveils AI code governance tool
Last month
#
application security
#
devsecops
#
supply chain
Secure Code Warrior launches SCW Trust Agent: AI, giving security teams commit-level visibility and control over AI-influenced code.
1Password debuts Unified Access to secure AI agents
Last month
#
data protection
#
cloud security
#
mdm
1Password unveils Unified Access to secure AI agents and machine credentials, promising endpoint-to-agent visibility for security teams.