Author: Lou Covey

Collaboration, trust in DevOps at risk in AI age

Is AI damaging collaboration between coders?

We put this question out to the cybersecurity community a few weeks ago and the simple answer to the question is yes and no. The breach of GitHub earlier this year did some damage to the platform, more reputation ally than functionally. Big users abandoned it for other Git platforms and usage has dropped dramatically over the ensuing months. The good news is the damage was identified in minutes and mitigated quickly, after putting the fear of god into developers.

What was less reported though were simultaneous attacks by the same hackers on virtually every popular developer operations (DevOp) platform. GitLab, not just GitHub, and BitBucket were hit at the same time. By July, Jira and Confluence were discovered compromised. GitHub claimed there was no degradation in uptime, but independent monitoring showed a decline to 86%. As a comparison, AWS’ S3 operates at 99.999999999% up time or “eleven nines”, while GitHub’s own reports show nine nines this year.

AI at the core

The impact of this change is entirely the result of AI use. The hackers employed customized AI agents, breached Github and stolen 3,800 of its internal repositories. They poisoned a popular VS Code extension called Nx Console, pushed the malicious version to the Visual Studio Marketplace, and let auto-update distribute it. The compromised version was live for just 18 minutes, but that was enough.

Premium Membership Required

You must be a Premium member to access this content.

Join Now

Already a member? Log in here
Read more...

Watermarks: the good, bad, and ugly

There has been a lot of discussion and debate over Anthropic’s watermark announcement, but it’s not much of an issue. It is required not only by the EU but China so AI companies must provide this technology. So for those who don’t like it, this is a chance to make lemonade out of lemons.

At Cyber Protection Magazine, we see some very positive aspects of this developing technology. We use AI in various ways: to automate the processing of junk… er, press releases, research purposes and identifying original content. While the AI industry like to promote the scare tactic of replacing humans, we see it as an efficiency tool, freeing us to do the work of covering cybersecurity news.

Free Membership Required

You must be a Free member to access this content.

Join Now

Already a member? Log in here
Read more...

Not a lot of substance at Black Hat USA

Black Hat USA kicked off over the weekend and company announcements followed the marketing focus on agentic AI products and services. However, there was more hash than corned beef in these announcements. Most were repackaged current product offerings.

A handful of announcements targeted at Black Hat focused on AI-generated or agentic threats. Most of the announcements repeated announcements prior to the RSA conference,for "agentic AI security" marketing. These include Tenable, Bedrock Data, Cycode, LimaCharlie, Flint AI, GTB Technologies, Strike48, Alice, Menlo Security and Adaptive Security.

Among more interesting legitimate announcements were Backslash Security, and Lineaje.

Free Membership Required

You must be a Free member to access this content.

Join Now

Already a member? Log in here
Read more...

Baby bust is forcing a rethink of AI hype

When AI burst upon the scene a few years ago, it became a boon to the cybersecurity industry. The AI sector pushed a narrative that AI was not just a tool, but a way to replace human workers. Cyber threats exploded and there was greater demand for tools and services. The security industry glommed onto that narrative with AI-driven services. That had the expected result of destroying any goodwill available to AI technology.

However, recent revelations about the effectiveness of AI replacements are making proponents change their tune. What changed? Let’s start with human fertility.

Free Membership Required

You must be a Free member to access this content.

Join Now

Already a member? Log in here
Read more...

Scam Bucket: You can escape Meta Hell

Not all scams take money from you. One of the biggest security scams is the belief that once you have joined a Meta platform, it is impossible to leave. The news the Meta is working with a government contractor to make facial recognition tech for ICE agents has accelerated interest in how to escape Meta Hell. The question is, how?

Migration from Meta platforms is no longer a niche trend. Through 2025 and 2026 there is a sustained structural shift in the social media. Just consider the explosive growth of Bluesky, which closed 2025 with over 41.4 million registered users, a 60% year-over-year increase, with daily active users climbing past 4.5 million. That represents real growth from status into mainstream viability.

Free Membership Required

You must be a Free member to access this content.

Join Now

Already a member? Log in here
Read more...