DEV Community

# devsecops

Integrating security practices into the DevOps lifecycle.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Developers Are Now the Attack Surface

Developers Are Now the Attack Surface

Comments
10 min read
AI Security Scanning Tools in 2026: Snyk vs Semgrep vs OX Security — Real False-Positive Rates Tested

AI Security Scanning Tools in 2026: Snyk vs Semgrep vs OX Security — Real False-Positive Rates Tested

Comments
5 min read
Applying Checkov to Terraform as Code – A TFSEC Alternative

Applying Checkov to Terraform as Code – A TFSEC Alternative

Comments
3 min read
Supercharging Security: DevSecOps Security Scanning in CI/CD

Supercharging Security: DevSecOps Security Scanning in CI/CD

Comments
2 min read
Why Every CISO Needs an AIBOM in 2026 — And What Most Vendors Get Wrong

Why Every CISO Needs an AIBOM in 2026 — And What Most Vendors Get Wrong

Comments
9 min read
My Software Is EOL — What Do I Do Now?

My Software Is EOL — What Do I Do Now?

1
Comments
5 min read
Supply Chain Attacks: Schutz vor bösartigen Abhängigkeiten im IT-Betrieb

Supply Chain Attacks: Schutz vor bösartigen Abhängigkeiten im IT-Betrieb

Comments
5 min read
Determinism Over Degeneracy: Why Model Collapse Will Destroy "AI-First" Cyber Security

Determinism Over Degeneracy: Why Model Collapse Will Destroy "AI-First" Cyber Security

Comments
5 min read
Redis CVE-2026-23479: AI-Discovered RCE Flaw Exposes Two Years of Hidden Risk

Redis CVE-2026-23479: AI-Discovered RCE Flaw Exposes Two Years of Hidden Risk

Comments
10 min read
.NET NuGet Package Security — How to Scan Your C# Dependencies for Vulnerabilities

.NET NuGet Package Security — How to Scan Your C# Dependencies for Vulnerabilities

Comments
9 min read
Supply Chain Is the New Front Door: What May 2026 Taught Us About Third-Party Risk

Supply Chain Is the New Front Door: What May 2026 Taught Us About Third-Party Risk

Comments
7 min read
"It's not a bug, it's spec": a zero-click RCE in AI coding agents that three vendors won''t patch

"It's not a bug, it's spec": a zero-click RCE in AI coding agents that three vendors won''t patch

1
Comments
6 min read
Cybersecurity Has a Measurement Problem

Cybersecurity Has a Measurement Problem

Comments
4 min read
Why Every CISO Needs an AIBOM in 2026 and What Vendors Get Wrong

Why Every CISO Needs an AIBOM in 2026 and What Vendors Get Wrong

Comments
9 min read
IDOR in AI-Generated APIs: The Ownership Check Cursor Always Skips

IDOR in AI-Generated APIs: The Ownership Check Cursor Always Skips

1
Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.