🔑 Hole in GitHub’s browser-based VSCo...
📝 A vulnerability...
📰 Hole in GitHub’s browser-based VSCode editor could lead to stolen token | CSO Online
Built on 30M+ download open source tools (Syft & Grype) 🔧
Community-proven, enterprise-hardened 💪
https://anchore.com/platform/secure/
#SoftwareSupplyChain #SBOM #CyberSecurity #Compliance #DevSecOps
Start by spending five minutes at your next DSDM workshop discussing a real security incident that affected a services company and asking what your team would have done differently.
#DSDM #AgileDevelopment #CyberSecurity #DevSecOps #TechServices #RapidDevelopment #SmallTeam #SecurityCulture #AuthenticLeadership #IterativeDevelopment (23/23)
🔑 Microsoft Visual Studio Code Vulnerabil...
📝 A bug hunter le...
📰 www.theregister.com - Articles

Odysseus promises a self-hosted AI workspace with agents, memory, email and model serving. Its safest first test is narrower: localhost, dummy data, authentication on and no live mailbox until every tool permission is clear and the loopback defaults stay in place.
A prompt is not a security control. It’s a wish.
You can write “never touch production” into your AI agent’s prompt all you want - it’s probabilistic, so one day it ignores you anyway.
The fix is a boundary the agent physically can’t cross: a hard ceiling on identity (Vault), policy-as-code that rejects bad plans (Sentinel), a governed way to act (MCP).
IBM just consolidated the whole stack - the cage already exists.
https://devops.pink/ai-agent-needs-a-ceiling-not-a-better-prompt/

A prompt is not a security control. It's a wish. The Vault → Sentinel → MCP → ADLC → watsonx Orchestrate stack that gives AI agents a hard ceiling — and why IBM consolidating HashiCorp made the whole thing boring, in the best possible way.