IT Brief India - Technology news for CIOs & IT decision-makers
India
Indian Edition · 2026

The Ultimate Guide to DevSecOps

A curated Indian edition of TechDay news, analysis, interviews, reviews, job moves, and related resources for DevSecOps.

What to know about DevSecOps

DevSecOps represents the integration of security practices within the DevOps process, aiming to build security into every phase of software development and delivery. This approach helps organisations accelerate development cycles while maintaining strong security and compliance standards.

Exploring recent stories tagged with DevSecOps reveals a dynamic field where AI-driven tools, cloud-native security, and collaboration between development, security, and operations teams are shaping the future of secure software delivery. Topics such as risk management, container and API security, supply chain protection, and the rising importance of observability and automation are frequently discussed.

For readers interested in how organisations are addressing evolving cybersecurity threats while enhancing agility and innovation, the DevSecOps tag offers insights into technology advancements, cultural shifts, and best practices that help teams deliver resilient, secure software faster. Whether you are a developer, security professional, or IT leader, following DevSecOps stories provides valuable perspectives on securing modern software development in an increasingly complex digital landscape.

Indian DevSecOps News

Regional stories with direct local relevance

Analyst Insights

Research and market analysis connected to DevSecOps

Expert Columns

Interviews

Interviews and video coverage from the network

Recent DevSecOps News

Synack report says vulnerability testing gap widens
Digital Transformation

Synack report says vulnerability testing gap widens

Enterprises are testing only about 32% of their attack surface, leaving many assets outside regular security checks as threats grow faster.

Today

HackerOne links validated flaws to Wiz cloud platform
Digital Transformation

HackerOne links validated flaws to Wiz cloud platform

Security teams may cut backlogs as validated HackerOne flaws are mapped into Wiz, linking exploit evidence to cloud assets for faster prioritisation.

Yesterday

MySQL exposures & slow fixes plague firms, study finds
Digital Transformation

MySQL exposures & slow fixes plague firms, study finds

Nearly half of organisations are leaving risky ports and services open, with midmarket firms taking up to 56 days to fix exposures.

Yesterday

HackerOne & Wiz link validated findings to cloud risk
Digital Transformation

HackerOne & Wiz link validated findings to cloud risk

Security teams can now rank cloud flaws by exploitability and impact, as validated HackerOne reports feed directly into Wiz's risk graph.

Yesterday

Cisco open-sources Foundry Security Spec for AI testing
Security Operations Centres

Cisco open-sources Foundry Security Spec for AI testing

Security teams will be able to verify AI-generated vulnerability findings more reliably, as Cisco's framework tackles false positives and invented issues.

2 days ago

CyberCX report finds 29% of tests exposed severe flaws
Digital Transformation

CyberCX report finds 29% of tests exposed severe flaws

AI systems and social engineering tests proved especially risky, as CyberCX found severe weaknesses in half and 77% of cases respectively.

3 days ago

Exaforce raises USD $125m in Series B for AI security
Digital Transformation

Exaforce raises USD $125m in Series B for AI security

The funding will help the cyber security start-up expand in Japan and Europe as it pushes AI tools to cut investigation times and false positives.

3 days ago

Secure Code Warrior launches Bedrock security training
Risk & Compliance

Secure Code Warrior launches Bedrock security training

Developers using generative AI will get hands-on lessons on prompt injection and data leakage as AWS expands Bedrock adoption.

4 days ago

AI now routine in cyber attacks, Google report finds
Threat intelligence

AI now routine in cyber attacks, Google report finds

Security teams face a broader threat as criminals and state-backed actors use generative AI to speed hacks, phishing and malware.

4 days ago

Sonatype joins Linux Foundation registry working group
Advanced Persistent Threat Protection

Sonatype joins Linux Foundation registry working group

Sonatype joins Linux Foundation registry working group to tackle funding, governance and security pressures as package downloads near 10 trillion.

5 days ago

KnowBe4 partners Secure Code Warrior on AI training
Encryption

KnowBe4 partners Secure Code Warrior on AI training

Organisations using AI in software development will get training on secure coding and governance as vulnerabilities and data risks mount.

Last week

OpenAI launches GPT-5.5-Cyber for vetted defenders
Firewalls

OpenAI launches GPT-5.5-Cyber for vetted defenders

Vetted security teams will get fewer refusals on authorised tasks as OpenAI tightens access around its most permissive cyber model.

Last week

Rapid7 joins OpenAI cyber programme to speed defence
Digital Transformation

Rapid7 joins OpenAI cyber programme to speed defence

The tie-up could help security teams cut false alarms and patch faster as automated attacks shrink defenders’ reaction time.

Last week

Synack launches Sara AI Pentesting for wider coverage
Data Protection

Synack launches Sara AI Pentesting for wider coverage

The move aims to widen security coverage as firms struggle to test expanding attack surfaces quickly enough.

Last week

Malicious OpenClaw skill spreads Remcos RAT & GhostLoader
SmartPhones

Malicious OpenClaw skill spreads Remcos RAT & GhostLoader

AI agent workflows are being targeted by a fake OpenClaw skill that installs Remcos RAT and GhostLoader on Windows, macOS and Linux.

Last week

Kamiwaza launches AI platform for regulated sectors
Government

Kamiwaza launches AI platform for regulated sectors

Regulated organisations can now run AI across distributed data while preserving access controls, audit trails and compliance boundaries.

Last week

Chainguard launches compliant EKS add-ons in AWS Marketplace
Public Sector

Chainguard launches compliant EKS add-ons in AWS Marketplace

The listing gives regulated AWS customers a faster route to compliant Kubernetes components, avoiding custom hardening and patching work.

Last week

Cloudflare warns of AI code review prompt injection
Virtual Private Networks

Cloudflare warns of AI code review prompt injection

Detection of malicious code can collapse when AI reviewers are fed large files packed with harmless text, Cloudflare's research shows.

Last week

OpenObserve raises USD $10 million for Observability 3.0
Network Infrastructure

OpenObserve raises USD $10 million for Observability 3.0

The funding will help OpenObserve expand as more firms seek unified monitoring for AI-heavy systems and growing telemetry volumes.

This month

Intruder launches AI pentesting for faster validation
DevOps

Intruder launches AI pentesting for faster validation

Security teams can now validate scanner findings in minutes as Intruder rolls out AI agents to cut false positives and speed remediation.

This month