InfoWorld |
|
||||||
AWS takes aim at runaway AI agent behavior with Strands Box12:18 Amazon Web Services (AWS) has introduced an open-source sandbox for AI agents that allows developers to restrict their actions based on previous behavior, seeking to address security risks as enterprises give autonomous systems greater access to applications and data. The tool, called Strands Box, combines operating system-level isolation with policies that govern what agents can do. Released in … AI changed my role before it changed my software11:24 My first attempt at vibe coding face-planted. I shook my head and stared at the screen. Well, this is obviously not for me. I became convinced the problem was the AI. I had uploaded the working Excel spreadsheet that already contained the business logic, workflows, and calculations I wanted the AI to replicate. How hard could this possibly be for “ artificial intelligence ” to translate into an a… AI-powered data pipeline observability: Stop monitoring and start preventing11:24 Devops tools are making it increasingly easy to monitor data pipeline failures. But in many cases, those alerts are already too late. Take marketing campaigns, for example. Every mistake in data for marketing and sales has a trickle-down effect on revenue. William Flaiz , founder of CleanSmartLabs , shares one example. One of his B2B clients increased their marketing spend by 40%, yet revenue rem… AWS’ support for Iceberg materialized views on Redshift could help lower analytics costs15:36 AWS has added support for Iceberg materialized views to its managed cloud data warehouse service, Amazon Redshift, in an effort to help enterprises lower analytics costs. Materialized views are precomputed, stored results of queries that data warehouses such as Redshift can use to avoid repeatedly running compute-intensive queries when the same analytical workloads are run repeatedly, reducing co… Encrypted instructions trick Copilot CLI into spilling developer secrets14:42 GitHub Copilot CLI can be made to read sensitive files from a developer’s machine and send their contents to an attacker from a single web page. Security researchers at Adversa AI said the new attack technique, dubbed Cryptographic Context Injection (CCI), hides malicious instructions inside encrypted content. These instructions are treated as trusted context when Copilot CLI decrypts the content… Five keys to controlling AI token costs7.října We spent the last decade building entire finops departments just to decipher what the cloud bill was saying. Just when we figured out how to stop leaving idle compute instances running, generative AI introduced an infinitely more opaque, faster-moving layer of spend. AI bill shock has spread like a slow moving hurricane across the industry. Aside from the spike in large language model (LLM) costs… Cursor writes all my code now7.října I was at the gym yesterday, talking with a relatively new CrossFitter named John, and naturally he asked me what I do for a living. I said I write software all day. But it hit me—I don’t actually write software anymore. I told him that, nowadays, Cursor writes all my code—I just tell Cursor what to do. I’ve written about how code isn’t important anymore and that we won’t be writing code much long… Atlassian launches AMP to tackle AI code visibility, attribution7.října Atlassian today rolled out new offerings designed to make it easier for IT to differentiate coding by AIs from human coding. The problem is that such distinctions in the enterprise today are rarely binary, as much coding has lots of each. The lack of meaningful visibility into code origin is a massive problem for most large businesses, said Jamil Valliani , head of AI products at Atlassian, in an… Atlassian’s critical flaw turns eight enterprise products into one big security problem7.října A newly-disclosed critical flaw in Atlassian’s data center software has a remarkably wide reach, affecting eight core products across the company’s enterprise portfolio. CVE-2026-21589 , rated 9.3 (critical) in severity, is an arbitrary file access vulnerability that could allow an attacker with no login access to read files in web app root directories that they should not otherwise see, and pote… AI has accelerated coding. Now software organizations must redesign everything around it6.října Software teams running AI coding tools are generating more output than ever before. Commits are up. Pull requests move faster. By the numbers, developer productivity is what the tools promised. Delivery performance is a different story. Many organizations report that deployments have slowed and governance overhead has grown. The AI tools worked. The system around them did not scale with them. The… One week to TechCrunch Disrupt: What’s next for AI and software development6.října First AI gave us code completion, predicting the lines of code, functions, and boilerplate we needed based on what we’d already typed. Then came code suggestions and code generation, where AI writes new code or improves existing code based on a natural language prompt. Today, coding agents can look at your code, suggest improvements, compile and test the improved code, and iterate on that to come… ServiceNow takes aim at enterprise AI’s workflow bottleneck with AI Workflow Factory6.října ServiceNow has launched two AI solutions that can help enterprises identify business processes ripe for automation, build the workflows to address them, and continuously improve them with AI agents. AI Workflow Factory and Autonomous Engineer, announced on Tuesday, will bring process discovery, AI-assisted development and workflow execution into a single system that ServiceNow says can help enter… Don’t buy a consultant’s AI framework6.října Every major consulting firm offers its own prebuilt architectural framework, model, or reference architecture for generative AI and agentic AI . The pitch is nearly identical from firm to firm: “We’ve done this before, we’ve packaged the patterns, and if you start from our blueprint, you’ll get down the path faster.” It’s an age-old consulting technique. Get the client interested in an out-of-the… Money can’t buy enterprise trust6.října I thought the AI boom was producing a new level of bad behavior , what with MongoDB CEO CJ Desai peacing out, not to mention Google’s earlier controversial “acquihire ” of Windsurf’s executive team. But I was wrong: Money has a long history of hollowing out our ethical norms. The problem in these and other AI moves isn’t really about the money, but rather about the trust, or lack thereof, left in… JDK 27: The quiet before the storm5.října Every September, with metronomic regularity, we have a new version of the Java platform. One small point about timing is that the first release candidate of JDK 27 was delayed by two weeks due to the release of the first Critical Security Patch Update (CPSU) for the JDK. The need for a CPSU is a direct implication of AI models , such as Anthropic’s Claude Mythos, becoming much better at identifyi… |