Four real CI/CD breaches of 2025 (tj-actions, Nx, Amazon Q, GitHub MCP) and how agentpipe and agentpipe SaaS catch CI injection (clinejection) before secrets leak.
We shipped agentpipe v0.9, and it is a big one. agentpipe started life as a local CI/CD security scanner you ran by hand from a terminal. It now lives inside your pipeline and reviews…
2025 was the year AI agent security stopped being a conference slide and turned into real incidents: live CVEs, leaked secrets, wiped production databases. An AI coding agent reads any tool description as a…
An AI coding agent is like an intern you handed every key on day one: files, shell, production access, tokens. Except the intern gets tired and asks twice, while the agent executes everything at…
CVE-2026-60004 in Gitea (CVSS 9.8): repo write access to a planted git hook to RCE as the service account. Default open registration makes it near-unauth.
Microsoft disclosed a maximum-severity Entra ID flaw: unauthenticated RCE via unsafe deserialization, CVSS 10.0. Microsoft fixed it server-side — here's what defenders should still do.