The Ultimate Guide to DevSecOps
A curated Asian edition of TechDay news, analysis, interviews, reviews, job moves, and related resources for DevSecOps.
What to know about DevSecOps
DevSecOps represents the integration of security practices within the DevOps process, aiming to build security into every phase of software development and delivery. This approach helps organisations accelerate development cycles while maintaining strong security and compliance standards.
Exploring recent stories tagged with DevSecOps reveals a dynamic field where AI-driven tools, cloud-native security, and collaboration between development, security, and operations teams are shaping the future of secure software delivery. Topics such as risk management, container and API security, supply chain protection, and the rising importance of observability and automation are frequently discussed.
For readers interested in how organisations are addressing evolving cybersecurity threats while enhancing agility and innovation, the DevSecOps tag offers insights into technology advancements, cultural shifts, and best practices that help teams deliver resilient, secure software faster. Whether you are a developer, security professional, or IT leader, following DevSecOps stories provides valuable perspectives on securing modern software development in an increasingly complex digital landscape.
Asian DevSecOps News
Regional stories with direct local relevance
Broadcom launches VMware Private AI Cloud for enterprises
Enterprises can now keep AI workloads and sensitive data on the same private cloud, as Broadcom adds governance and security controls.
ITSEC Asia launches Bronyx AI for automated testing
Businesses may get security test results in hours as ITSEC Asia's new platform flags risks and keeps human consultants in the loop.
Singapore software security gap exposed in JFrog study
Despite strong governance on paper, Singapore firms are struggling to enforce software security controls as AI and open-source use accelerates.
Modulus Labs cuts incident response time by 40% with Datadog
Payment failures now surface in seconds for Modulus Labs after it unified monitoring and security, cutting resolution time by more than 40 per cent.
Leading Agentic AI teams in Singapore: What technology leaders should know
With 93% of Singapore executives now treating AI software innovation as strategic, leaders face a tougher test: keeping experts aligned and shipping fast.
AI uncovers 'SvelteSpill' flaw in Vercel SvelteKit apps
AI pentesting tool uncovers 'SvelteSpill' bug in default SvelteKit apps on Vercel, exposing cached private data before a platform fix.
Analyst Insights
Research and market analysis connected to DevSecOps
RevEng.AI launches binary analysis models for code
Broadcom launches TrueSource for secure open source
Rocket Software adds AI tools for IBM i modernisation
F5 expands AI Gateway to curb costs & secure agents
Contrast launches CVE Shield to block exploit attacks
Featured News
Expert Columns
Supercharged security: Cyber risk in the age of frontier AI
AI deserves our appreciation, but only if we're honest about what we're appreciating
Buying more tools won't scale your security ambitions, operational maturity will
A strategic blueprint for governing AI-enabled software development
As agentic development accelerates, workflow auditability becomes a bottleneck
Why organisations in Asia Pacific are rethinking their AI deployment strategies
Leading Agentic AI teams in Singapore: What technology leaders should know
Secure by default: Moving beyond secure by design
Why the next endpoint and SASE disruption will not come from a security vendor
The security challenges in AI-assisted software development
Interviews
Interviews and video coverage from the networkRecent DevSecOps News
Group-IB adds CSPM to Unified Risk Platform for cloud
Group-IB has added cloud security posture management to its Unified Risk Platform, automating misconfiguration detection and compliance checks.
Check Point backs Google Cloud to close ASEAN 'Cloud Gap'
Check Point backs Google Cloud tools to close ASEAN's 'cloud gap', promising in-band, AI-driven security without slowing digital growth.
Sirisoft & Red Hat champion automation for AI-ready IT
Sirisoft and Red Hat urge Thai enterprises to treat automation as core AI-ready IT infrastructure, redefining ROI beyond simple cost cuts.
AI speeds coding but costs Singapore teams a day weekly
AI is speeding up coding for Singapore's software teams, but fragmented tools and poor workflows are costing them a day each week.
SolarWinds: Looking beyond DevOps to fix cybersecurity
The role of DevOps in security has seen increasing popularity due to its sound philosophy around productivity and adaptability.
Cycode launches agentic code scanning & attack chaining
Security teams could see fewer false positives and faster fixes as Cycode's new system blends rule-based checks with AI to trace attack paths.
JFrog launches AI-era security tools for software supply
As AI coding agents speed up development, JFrog is adding controls meant to keep governance, compliance and patching from lagging.
Google Cloud adds VPC security tools for BlackLine
Security teams can now trace blocked cloud requests faster, as Google Cloud rolls out policy intelligence for VPC Service Controls to cut investigation time.
Westcon-Comstor signs Sonar deal across EMEA & APAC
Partners across EMEA and APAC gain a route into AI coding and DevSecOps projects as SonarQube checks aim to cut security and governance risks.
Ping Identity launches controls for personal AI agents
Businesses using personal AI agents in the workplace now face tighter access checks, as Ping aims to stop unsanctioned actions and improve audit trails.
AI-generated cyber attacks to hit firms soon, warn experts
Many firms lack the capacity to fix existing flaws fast enough, leaving them exposed as AI-generated attacks scale up, experts warn.
Kobalt.io signs security partnerships across North America
Enterprise buyers and defence contractors will get a clearer route to certification as Kobalt.io broadens its North American security network.
Commvault links recovery actions into CrowdStrike SOAR
Joint users can now automate cyber recovery steps during incidents, cutting handoffs and helping preserve clean backup points for ransomware response.
TrendAI tops CyberGym with 97% exploit-remediation rate
Enterprises could cut their exposure window as TrendAI's AESIR scored 97% on an independent benchmark against confirmed software flaws.
Google Cloud launches fault injection testing preview
Fault testing aims to cut outage risk for cloud users as Google Cloud previews a tool that simulates failures before customers are hit.
Noah Labs AI touts governed software agents for defence
Governed agents could speed urgent fixes in defence systems while keeping air-gapped code changes auditable, approved and traceable.
NVIDIA, SAP back OpenBao as secrets tool gains ground
Growing use by major tech groups is helping open source secrets manager OpenBao win trust as cloud and AI credential risks mount.
GitLab adds enterprise controls for agentic AI tools
Regulated teams can now keep AI processing inside GitLab Dedicated, with new secret handling, spending caps and security fixes added in 19.3.
Google Cloud warns startups on AI scaling pitfalls
Startups risk leaked keys, quota throttling and surprise bills unless they tighten controls as AI prototypes move into production.
Endor Labs adds buildless C support to AI SAST tool
Developers can now scan C code earlier in the process, as Endor Labs says its buildless AI SAST found 96 of 102 known bugs in tests.