CNCF's shadow-AI post makes the case for treating agents as identities
Give an AI agent a Git token and a Kubernetes ServiceAccount. Now ask which team owns it, and where its logs go. If you cannot answer both in one br…
Tech news from the best sources
Give an AI agent a Git token and a Kubernetes ServiceAccount. Now ask which team owns it, and where its logs go. If you cannot answer both in one br…
Seventy-seven percent of surveyed organizations experienced a software supply chain incident in the twelve months before Omdia ran its 2026 survey,…
A token that skips 2FA is a bad idea (until you need one at 3am) You automate your npm publishes with a token that skips the 2FA prompt, because rob…
Are you looking for vulnerability intel that standard scanners skip? OSV-Scanner is an awesome SCA tool for unearthing vulnerabilities in open-sourc…
Every CI job is a small, under-supervised computer with your production secrets in its environment and root inside its container. (Comforting, isn't…
TL;DR Bumblebee is a read-only supply chain scanner from Perplexity AI that checks your installed packages, editor extensions, MCP configs, and brow…
Note: The Hermes repo contains no explicit statement saying "we don't use LangChain because…". This article works on two levels: the industry-wide c…
This article was originally published on LucidShark Blog . On February 17, 2026, a developer opened a GitHub issue on the Cline repository. The issu…