FR
live
section

DevOps

Meta Launches Muse Code and Undercuts Claude Code by an Order of Magnitude

On August 5, 2026, Meta entered the coding agent market with Muse Code, a terminal agent powered by Muse Spark 1.2. Rather than competing on raw model intelligence, Meta built the most advanced agent harness on the market: multi-agent fan-out, isolated git worktrees, full JSONL audit logging, and pricing up to 10× lower than Claude Code. Here’s what it means for DevOps teams.

khunt Weaponizes Oracle's Embedded JVM to Run Post-Exploitation Toolkit from Inside the Database

On August 5, 2026, Huntress researchers documented an attack where the khunt toolkit was compiled and executed inside an Oracle database via SQL injection on an Apache Tomcat endpoint. Attackers abused Oracle's embedded JVM to run OS commands with SYSTEM privileges, steal Windows hashes, and map the network. The message to DBAs is clear: your database is a full Java runtime — treat it like one.

A GitHub issue with zero repo privileges can run code on Anthropic and Google CI runners — Black Hat 2026 tears apart coding agent trust

On August 5, 2026, Novee Security demonstrated at Black Hat USA that a GitHub issue opened by an account with no write access was enough to execute arbitrary code on the CI runners behind Claude Code, Gemini CLI, and OpenAI Codex repositories. If your CI/CD pipeline executes code from GitHub issues without sandboxing, treat this as a CVE with no patch — yet.

ChainDrop infects 1,300 npm packages and 2 billion monthly downloads

A self-propagating supply-chain attack named ChainDrop compromised over 1,300 packages on the npm registry on August 4, 2026. The infected packages accounted for 2 billion monthly downloads and reached organizations including Deliveroo, Qlik, and ServiceTitan. Audit your dependencies now.

TeamCity CVSS 9.8 RCE demands immediate patching — here's what you need to do

JetBrains disclosed CVE-2026-63077 on July 27, 2026 — a CVSS 9.8 unauthenticated remote code execution flaw affecting every on-premises TeamCity instance. No active exploitation has been detected yet, but the clock is ticking: TeamCity's history with state-sponsored attackers makes this a drop-everything patch scenario.

DevOps Isn’t Dead — It’s Called Platform Engineering Now

The 2026 State of DevOps Report from Puppet/Perforce confirms platform engineering as the dominant delivery model, driven by the explosion of AI in software pipelines. Without governance, AI accelerates failure as fast as it accelerates deployment.

GitHub Actions Hands You the Runner Keys — You Do the Driving

Custom runner images hit general availability on March 26, 2026 after a six-month public preview. They eliminate per-job setup and speed up pipelines — but shift image maintenance, security patching, and versioning squarely onto your team.

Kubernetes 1.36 makes GPUs a shareable resource with DRA going GA

Released on 22 April 2026, Kubernetes 1.36 graduates Dynamic Resource Allocation to general availability. GPUs are no longer an opaque integer count — they become attribute-aware, partitionable resources the scheduler can reason about natively.

Vault Enterprise 2.0 Ditches Static Credentials for Identity-Based Security

HashiCorp announces Vault Enterprise 2.0 with Workload Identity Federation, automated Linux credential rotation, and high-performance envelope encryption. The question shifts from ’who knows the password’ to ’who can prove their identity’ — and that changes everything about how we secure infrastructure.

ingress-nginx is retiring in March 2026: here’s your Gateway API migration plan

The ingress-nginx project ends all maintenance in March 2026. The GitHub repository has been archived since March 24, no further security patches will be published, and CVE-2025-1974 demonstrated the architectural risks of a controller built on arbitrary annotations. Gateway API is the mandatory migration target, and it’s ready.

Type at least two characters.

navigate open esc dismiss