SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers

Source Code Management (SCM) stories

Flux result 15775f93 6354 42eb 9892 8efeae6bf886

GitLab expands Google Cloud partnership for Vertex AI

Yesterday
#
devops
#
hybrid cloud
#
cx
GitLab deepens Google Cloud partnership so Duo Agent Platform users can tap Vertex AI models, while counting the spend against existing commitments.
Flux result 6e43f861 242a 4606 a620 43480305c4e9

Orca Security flags AI secrets & supply chain gaps

Last week
#
malware
#
devops
#
mfa
Orca Security warns that AI credentials, vulnerable dependencies and lax pipeline controls are leaving production environments exposed across US and Europe.
Email attachment20260407 2398999 9lzpuc

Cursor 3 retools coding workspace around AI agents

Last week
#
rpa
#
software development
#
agentic ai
Cursor 3 rebuilds the coding workspace around AI agents, adding cross-repository collaboration, cloud handoffs and review tools for developers.
Craig nielsen

From chaos to code efficiency: AI's big software development shift

Last week
#
devops
#
hybrid cloud
#
digital transformation
AI is boosting developer output, but Australian firms are finding the bigger challenge is joining up fragmented tools, data and governance.
Email attachment20260406 1015143 8xx90v

Avocado warns on code repository supply chain attacks

Last week
#
cloud security
#
phishing
#
application security
Avocado urges Australian firms to tighten repository security as the ACSC reissues a high alert on active supply chain attacks and secrets sprawl.
Images  1

Kestra raises USD $25 million to expand workflow platform

This month
#
saas
#
devops
#
hybrid cloud
Kestra secures USD $25 million from RTP Global to launch Kestra 2.0, roll out Kestra Cloud and expand in North America and Europe.
Flux result 6560ca2a f119 40da 861e 65fc76f6e524

Liquibase launches database governance tools for enterprise

Last month
#
devops
#
rpa
#
apm
Liquibase rolls out AI-backed database governance and deployment connectors for ServiceNow, GitHub, Harness and Terraform to improve auditability.
Flux result ff85c0f6 aa13 4ff7 ae42 c0b79c19e791

Percona & Chainguard launch supported database images

Last month
#
virtualisation
#
devops
#
digital transformation
Percona teams up with Chainguard to offer supported, hardened container images for MySQL, PostgreSQL and MongoDB databases.
Flux result 86c5d3ff 8544 4b88 ac41 93781b8158bc

AppOmni adds Heisenberg mode after LiteLLM supply attack

Last month
#
virtualisation
#
cloud security
#
application security
AppOmni upgrades Heisenberg to help teams trace GitHub Actions and spot tainted dependencies after the LiteLLM supply chain breach.
Flux result 478b1860 1027 4f08 ae1d ef0c6e3c5f85

Aerospike launches LangGraph memory layer for AI agents

Last month
#
open source
#
genai
#
llms
Aerospike adds durable memory for LangGraph agents to keep context through restarts, failures and concurrent sessions.
Flux result 0b725e6f 488f 44c4 b57e 5c23a2bc516f

NetRise launches Provenance to trace open source risk

Last month
#
devops
#
iot security
#
iot
NetRise unveils Provenance, a tool to trace open source maintainers and stop risky dependencies before they spread through software.
Editorial network ops center ai led observability aiops opsroom

New Relic named IDC MarketScape AIOps leader again

Last month
#
devops
#
data analytics
#
digital transformation
New Relic secures a third consecutive Leader ranking in IDC's Worldwide AIOps 2026 assessment, highlighting its AI-led observability tools.
Marc van zadelhoff

'Human Risk' takes centre stage - Mimecast CEO

Last month
#
data protection
#
endpoint protection
#
phishing
Mimecast chief warns human risk is now cybersecurity's 'eighth layer' as malicious insiders overtake negligence in Australian attacks.
Editorial software dev code review open source supply chain shield repair vulnerable deps

Veracode launches Fix for open-source vulnerability repair

Last month
#
devops
#
application security
#
devsecops
Veracode unveils an AI-driven tool that automatically fixes open-source vulnerabilities, tackling mounting security debt in software supply chains.
Editorial compromised software supply chain key token leak dark

Trivy GitHub breach exposes CI/CD supply chain risk

Last month
#
devops
#
cloud security
#
application security
Aqua Security's Trivy GitHub Action was hijacked to ship infostealer code via CI/CD pipelines, exposing secrets across downstream users.
Ai assisted code review inclusive dev team modern office

GitLab widens AI access & sets flat review pricing

Last month
#
devops
#
application security
#
devsecops
GitLab opens agentic AI to free-tier users, sets USD $0.25 flat fee for automated code reviews and expands security false-positive filtering.
Hybrid it security control room cloud mac okta github network

BloodHound expands identity attack path mapping reach

Last month
#
data protection
#
encryption
#
pam
SpecterOps broadens BloodHound Enterprise to map identity attack paths across Okta, GitHub and Jamf-managed Macs in hybrid environments.
Corporate security ops room network map ai agents permissions governance

Entro launches AI agent governance tool for enterprises

Last month
#
data protection
#
digital transformation
#
cloud security
Entro launches AGA to map, monitor and control AI agents in enterprises, tackling shadow AI and non-human identity risks at scale.
Corporate it security control room flat illustration pen testing

Cobalt unveils service to manage enterprise pentesting

Last month
#
devops
#
cloud security
#
application security
Cobalt launches Security Program Manager service to run enterprise pentesting, align tests with business goals and speed up remediation.
Us corporate operations room wall dashboards data analytics

ThoughtSpot unveils Spotter AI agents tailored by sector

Last month
#
saas
#
data analytics
#
digital transformation
ThoughtSpot rolls out Spotter for Industries, AI analytics agents tuned to sector rules to close the “context gap” in enterprise decisions.