FR
live
tag

#devsecops

GitHub Security Lab ships an agent that fuzzes a C/C++ repo end to end

On 24 September 2026, GitHub Security Lab released an autonomous fuzzing pipeline that writes its own harnesses, reads its own coverage and drafts its own vulnerability reports. The fuzzing bottleneck — human attention — is handed to an LLM, but the code runs on the host with no container in between.

GitLab 19.4 brings AI agents under the same governance as CI/CD

Released September 17, 2026, GitLab 19.4 governs MCP server tools, restricts their access, and hands agents pipeline control through save_pipeline and get_job. For teams deploying AI agents in the enterprise, the DevSecOps control plane becomes the governance layer.

GitLab patches a CVSS 10 arbitrary file-read flaw, exploited within 24 hours

On September 11, 2026, GitLab shipped an out-of-band release for CVE-2026-85706, a CVSS 10 path traversal that reads server files with no authentication via the commits API. The flaw is already being probed in the wild — patch self-managed instances before an attacker reads secrets.yml.

GitLab patches a critical unauthenticated GraphQL code injection flaw (CVSS 9.4)

On August 18, 2026, GitLab released fixes for two vulnerabilities, including a critical code injection via a GraphQL directive (CVE-2026-19478, CVSS 9.4) exploitable remotely without authentication or user interaction, allowing attackers to modify or delete public projects. Every self-managed installation must upgrade immediately — GitLab.com and GitLab Dedicated are already patched.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss