General

Collaboration, trust in DevOps at risk in AI age

Is AI damaging collaboration between coders?

We put this question out to the cybersecurity community a few weeks ago and the simple answer to the question is yes and no. The breach of GitHub earlier this year did some damage to the platform, more reputation ally than functionally. Big users abandoned it for other Git platforms and usage has dropped dramatically over the ensuing months. The good news is the damage was identified in minutes and mitigated quickly, after putting the fear of god into developers.

What was less reported though were simultaneous attacks by the same hackers on virtually every popular developer operations (DevOp) platform. GitLab, not just GitHub, and BitBucket were hit at the same time. By July, Jira and Confluence were discovered compromised. GitHub claimed there was no degradation in uptime, but independent monitoring showed a decline to 86%. As a comparison, AWS’ S3 operates at 99.999999999% up time or “eleven nines”, while GitHub’s own reports show nine nines this year.

AI at the core

The impact of this change is entirely the result of AI use. The hackers employed customized AI agents, breached Github and stolen 3,800 of its internal repositories. They poisoned a popular VS Code extension called Nx Console, pushed the malicious version to the Visual Studio Marketplace, and let auto-update distribute it. The compromised version was live for just 18 minutes, but that was enough.

Premium Membership Required

You must be a Premium member to access this content.

Join Now

Already a member? Log in here
Read more...

Not a lot of substance at Black Hat USA

Black Hat USA kicked off over the weekend and company announcements followed the marketing focus on agentic AI products and services. However, there was more hash than corned beef in these announcements. Most were repackaged current product offerings.

A handful of announcements targeted at Black Hat focused on AI-generated or agentic threats. Most of the announcements repeated announcements prior to the RSA conference,for "agentic AI security" marketing. These include Tenable, Bedrock Data, Cycode, LimaCharlie, Flint AI, GTB Technologies, Strike48, Alice, Menlo Security and Adaptive Security.

Among more interesting legitimate announcements were Backslash Security, and Lineaje.

Free Membership Required

You must be a Free member to access this content.

Join Now

Already a member? Log in here
Read more...

Baby bust is forcing a rethink of AI hype

When AI burst upon the scene a few years ago, it became a boon to the cybersecurity industry. The AI sector pushed a narrative that AI was not just a tool, but a way to replace human workers. Cyber threats exploded and there was greater demand for tools and services. The security industry glommed onto that narrative with AI-driven services. That had the expected result of destroying any goodwill available to AI technology.

However, recent revelations about the effectiveness of AI replacements are making proponents change their tune. What changed? Let’s start with human fertility.

Free Membership Required

You must be a Free member to access this content.

Join Now

Already a member? Log in here
Read more...

Will Mythos & Glasswing End the Zero-Day Era as We Knew It?

For decades, cybersecurity strategy has revolved around a shared assumption: zero-day vulnerabilities are rare, expensive to find, and difficult to exploit at scale. That assumption is now breaking down. The emergence of Mythos, the advanced AI system developed by Anthropic, marks a turning point in how vulnerabilities are discovered, weaponized, and defended against—and it forces security leaders to rethink long-held priorities.

Free Membership Required

You must be a Free member to access this content.

Join Now

Already a member? Log in here
Read more...