TechDay New Zealand - Aotearoa's technology news network
Kiwi Edition · 2026

The Ultimate Guide to DevSecOps

A curated Kiwi edition of TechDay news, analysis, interviews, reviews, job moves, and related resources for DevSecOps.

What to know about DevSecOps

DevSecOps represents the integration of security practices within the DevOps process, aiming to build security into every phase of software development and delivery. This approach helps organisations accelerate development cycles while maintaining strong security and compliance standards.

Exploring recent stories tagged with DevSecOps reveals a dynamic field where AI-driven tools, cloud-native security, and collaboration between development, security, and operations teams are shaping the future of secure software delivery. Topics such as risk management, container and API security, supply chain protection, and the rising importance of observability and automation are frequently discussed.

For readers interested in how organisations are addressing evolving cybersecurity threats while enhancing agility and innovation, the DevSecOps tag offers insights into technology advancements, cultural shifts, and best practices that help teams deliver resilient, secure software faster. Whether you are a developer, security professional, or IT leader, following DevSecOps stories provides valuable perspectives on securing modern software development in an increasingly complex digital landscape.

Kiwi DevSecOps News

Regional stories with direct local relevance

Analyst Insights

Research and market analysis connected to DevSecOps

Expert Columns

Interviews

Interviews and video coverage from the network

Recent DevSecOps News

Google launches CodeMender to scan & fix vulnerabilities
Digital Transformation

Google launches CodeMender to scan & fix vulnerabilities

Developers may get patched code faster as Google's preview agent scans repositories, tests exploits and drafts fixes for review.

Today

Cisco launches Antares AI models for code flaw pinpointing
IT Department

Cisco launches Antares AI models for code flaw pinpointing

Security teams could cut hours from patching work as open-weight Antares models narrow flaws to the relevant code segment.

Today

CrowdStrike warns of malware targeting AI coding tools
Threat intelligence

CrowdStrike warns of malware targeting AI coding tools

Developers using AI assistants could face stolen credentials and poisoned repositories as the worm hides inside normal coding workflows.

Today

Qualys joins Chainguard's Athena security coalition
Threat intelligence

Qualys joins Chainguard's Athena security coalition

The coalition has now processed more than 40,000 findings, underscoring how quickly open source flaws can spread across corporate systems.

Today

IBM upgrades Bob with multi-agent tools & analytics
Productivity

IBM upgrades Bob with multi-agent tools & analytics

Growing pressure on software teams to govern AI output and costs has prompted IBM to add multi-agent tools and analytics to Bob.

Today

Lineaje launches AI vulnerability elimination factory
Security Operations Centres

Lineaje launches AI vulnerability elimination factory

The tool aims to help developers cut vulnerability backlogs and reach no exploitable flaws within 90 days as AI coding expands risk.

Today

Hugging Face hit by AI agent intrusion in production
Robotics

Hugging Face hit by AI agent intrusion in production

Autonomous AI agents breached internal systems and exposed limited datasets and credentials, prompting Hugging Face to urge users to rotate tokens.

Yesterday

Tenable adds code security to its exposure platform
Digital Transformation

Tenable adds code security to its exposure platform

Security teams can now rank code flaws against wider business risk as Tenable One links static vulnerability data with cloud, identity and attack-path exposure.

2 days ago

F5 adds fleet management tools for BIG-IP environments
Software Updates

F5 adds fleet management tools for BIG-IP environments

Security teams under pressure to patch faster can now track and stage BIG-IP updates across fleets without losing audit control.

Last week

Google Cloud unveils 13 Gemini Enterprise agent demos
App development

Google Cloud unveils 13 Gemini Enterprise agent demos

Developers can now use Google Cloud's examples to build and govern Gemini-powered agents for approvals, compliance and data workflows.

Last week

FIS joins Anthropic cyber security project with Mythos 5
Supply Chain

FIS joins Anthropic cyber security project with Mythos 5

For thousands of banks and payments firms, the trial could help spot software flaws before they disrupt critical financial systems.

Last week

Google Cloud issues guardrails for AI vulnerability agents
Threat intelligence

Google Cloud issues guardrails for AI vulnerability agents

Security teams are being warned to keep humans and strict controls in place as AI agents can miss context and leak sensitive code.

Last week

Google Cloud unveils AI security blueprint for GKE
Managed Services

Google Cloud unveils AI security blueprint for GKE

The framework targets CISOs and platform teams as they move AI systems into production, amid rising risks from prompts, models and outputs.

Last week

Google Cloud sets out AI security plan with Gemini & Wiz
Threat intelligence

Google Cloud sets out AI security plan with Gemini & Wiz

Defenders could gain a faster edge against AI-driven attacks as Google Cloud ties Gemini, Wiz, CodeMender and Mandiant into one platform.

Last week

GitLab 19.2 adds AI tools for security & workflows
Identity and Access Management

GitLab 19.2 adds AI tools for security & workflows

The update aims to cut review bottlenecks by auto-fixing vulnerable dependencies and surfacing code flaws scanners often miss.

Last week

CleanStart launches Clean Libraries to secure AI code
Chief Technology Officers

CleanStart launches Clean Libraries to secure AI code

Developers face earlier checks on risky open-source dependencies as AI coding tools speed up software assembly and raise supply chain concerns.

Last week

Cloudflare uses eBPF to boost edge security & routing
Network Infrastructure

Cloudflare uses eBPF to boost edge security & routing

The shift has helped the network operator block massive attacks in seconds while reducing reliance on custom kernel patches and specialist hardware.

Last week

Targeted open source malware attacks on developers soar
Threat intelligence

Targeted open source malware attacks on developers soar

Malicious package advisories jumped from 21 in 2023 to 1,576 in 2025, as attackers increasingly target developers before code reaches production.

Last week

AI coding models make working code, not secure code
IT Department

AI coding models make working code, not secure code

Working output from the latest AI coding tools was secure barely a third of the time, exposing a widening risk for software teams.

Last week

Mandiant warns on exposed Cloud Run serverless apps
Identity and Access Management

Mandiant warns on exposed Cloud Run serverless apps

Exposed serverless apps can let attackers steal tokens, read secrets and take over cloud projects if weak code is left unpatched.

Last week

Job Moves