DevSecOps

3 posts tagged devsecops.

Oct 5, 2026

Policy as Code for AI Agents in 2026: Cedar at the Gateway, Rego in the Hook, and the 11.2% the Model Still Lets Through

What actually enforces limits on AI agents in 2026: OPA 1.21 and Rego v1 after the founders moved to Apple, Cedar in Amazon Bedrock AgentCore Policy (GA 3 March 2026, 13 regions, default deny), Kyverno 1.19 retiring ClusterPolicy for CEL, Claude Code hooks that deny even in bypass mode, Codex's Seatbelt and bwrap sandboxes, the MCP 2026-07-28 authorization spec, and why none of it is optional while browser-agent injection success sits at 11.2% and OpenAI says the problem is unlikely to ever be fully solved. With a tested Rego policy and a Cedar policy for tool calls.

13 min
Oct 5, 2026

CRA Reporting Went Live on 11 September: 24 Hours to ENISA, 3.08 Billion Rekor Entries, 17% of PyPI Attested, 92% SBOM False Positives

Supply-chain compliance in 2026: what the Cyber Resilience Act's Article 14 duty requires since 11 September 2026 (24-hour early warning, 72-hour notification, ENISA's Single Reporting Platform), what waits until 11 December 2027, how the open-source steward role works, where SBOMs stand (CISA's 2026 minimum elements, CycloneDX 1.7, a 92 percent false-positive rate in a 2,414-repo study), how far provenance has got (SLSA 1.2, 20 percent of PyPI uploads via trusted publishing, Rekor at 3.08 billion entries), the US retreat from mandates, and the pipeline I would run.

13 min
Oct 5, 2026

AI SOC Agents in 2026: 98% Accuracy Claims, 23 to 34% on the Benchmark, and 0% of Teams Letting Them Act Alone

What the security-operations agents from Microsoft, Google, CrowdStrike, Palo Alto, SentinelOne, Torq and a billion-dollar startup cohort actually do in 2026 and what is measured: a median of 100 alerts a day and 28 percent never investigated, 75-minute mean investigations, Microsoft's $4-an-hour compute units and Google's token meter, CrowdStrike's 98 percent triage claim against Meta's 23 to 34 percent benchmark, Anthropic's and Google's reports of attackers running agents against defenders, and a Sigma rule and CI step that keep a human on the merge button.

14 min