Skip to main content

Tag: devops security

4 articles

Rows of servers in a well-lit data center with daylight visible through large windows, conveying a sense of vulnerability.

Mass-Scanning Campaign Exploits Vite Flaw to Harvest Cloud Credentials

A high-severity flaw in Vite, tracked as CVE-2026-39364, has been exploited in a mass-scanning campaign, allowing attackers to bypass security restrictions and harvest cloud credentials. By manipulating query parameters, unauthenticated attackers can leak sensitive files that were meant to be blocked.

Analyst 207
A coding workspace with a laptop on a clean surface, surrounded by office elements.

Microsoft Azure DevOps Flaw Exposes AI Review Agents to Hidden Attacks

Imagine a hidden sentence that only AI sees, turning a reviewer's own AI agent into a vulnerability that lets attackers access projects they shouldn't - a chilling security flaw discovered in Microsoft Azure DevOps. This flaw, known as a confused-deputy vulnerability, was cleverly exploited in a proof of concept by Manifold Security.

Analyst 207
Developer workstation with laptop and subtle signs of supply chain breach.

Miasma Malware Targets npm, GitHub in Expanded Supply Chain Attack

Over 550 GitHub repositories have been compromised in a massive supply-chain attack, with malware harvesting developer credentials and spreading across package registries and workflows. The attack has already infected numerous npm packages and one Go module, putting developer data at risk.

Analyst 207
Software engineer working with AI coding tools at a desk with multiple laptops and notes.

AI Coding Adoption Outpaces Governance, Raises Security Risks

The rapid adoption of AI coding tools has outpaced governance, with 97% of teams using AI assistants, but only 30% having a fully governed approach to oversight, leaving a significant security risk gap. This disconnect raises concerns about where risks are accumulating and how work is getting done.

Analyst 207