Collaboration, trust in DevOps at risk in AI age
Is AI damaging collaboration between coders?
We put this question out to the cybersecurity community a few weeks ago and the simple answer to the question is yes and no. The breach of GitHub earlier this year did some damage to the platform, more reputation ally than functionally. Big users abandoned it for other Git platforms and usage has dropped dramatically over the ensuing months. The good news is the damage was identified in minutes and mitigated quickly, after putting the fear of god into developers.
What was less reported though were simultaneous attacks by the same hackers on virtually every popular developer operations (DevOp) platform. GitLab, not just GitHub, and BitBucket were hit at the same time. By July, Jira and Confluence were discovered compromised. GitHub claimed there was no degradation in uptime, but independent monitoring showed a decline to 86%. As a comparison, AWS’ S3 operates at 99.999999999% up time or “eleven nines”, while GitHub’s own reports show nine nines this year.
AI at the core
The impact of this change is entirely the result of AI use. The hackers employed customized AI agents, breached Github and stolen 3,800 of its internal repositories. They poisoned a popular VS Code extension called Nx Console, pushed the malicious version to the Visual Studio Marketplace, and let auto-update distribute it. The compromised version was live for just 18 minutes, but that was enough.

