<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>InfoQ</title>
    <link>https://www.infoq.com</link>
    <description>InfoQ feed</description>
    <item>
      <title>Azure Virtual Desktop Hybrid Reaches GA with Licensing Details Unpublished</title>
      <link>https://www.infoq.com/news/2026/09/avd-hybrid-ga/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/09/avd-hybrid-ga/en/headerimage/generatedHeaderImage-1788339494959.jpg"/&gt;&lt;p&gt;Microsoft has made Azure Virtual Desktop Hybrid generally available. Session hosts run on customer hardware through Azure Arc while brokering stays in Azure. The Hybrid service license is unpriced, Windows Server support requires RDS CALs with Software Assurance, and multi-session Windows is not supported at all.&lt;/p&gt; &lt;i&gt;By Steef-Jan Wiggers&lt;/i&gt;</description>
      <category>Cloud</category>
      <category>Cost Optimization</category>
      <category>Compliance</category>
      <category>Hybrid Cloud</category>
      <category>Virtualization</category>
      <category>DevOps</category>
      <category>Development</category>
      <category>Architecture &amp; Design</category>
      <category>news</category>
      <pubDate>Wed, 09 Sep 2026 08:54:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/09/avd-hybrid-ga/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Steef-Jan Wiggers</dc:creator>
      <dc:date>2026-09-09T08:54:00Z</dc:date>
      <dc:identifier>/news/2026/09/avd-hybrid-ga/en</dc:identifier>
    </item>
    <item>
      <title>vim.async's Addition Modernizes Neovim’s Async Architecture for Better Stability</title>
      <link>https://www.infoq.com/news/2026/09/async-lua-neovim/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://www.infoq.com/styles/static/images/logo/logo_bigger.jpg"/&gt;&lt;p&gt;Neovim has introduced a structured concurrency library in its Lua standard library via the vim.async namespace. This framework provides a standardized method for managing async workflows, addressing issues related to task management and error propagation. It allows for cooperative scheduling and clear task hierarchies, improving plugin development and error handling in asynchronous operations.&lt;/p&gt; &lt;i&gt;By Olimpiu Pop&lt;/i&gt;</description>
      <category>Asynchronous Programming</category>
      <category>Vim</category>
      <category>AsyncAPI</category>
      <category>Development</category>
      <category>news</category>
      <pubDate>Wed, 09 Sep 2026 06:06:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/09/async-lua-neovim/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Olimpiu Pop</dc:creator>
      <dc:date>2026-09-09T06:06:00Z</dc:date>
      <dc:identifier>/news/2026/09/async-lua-neovim/en</dc:identifier>
    </item>
    <item>
      <title>HashiCorp Packer 1.16 Adds Native SLSA Provenance Generation and Verification for Machine Images</title>
      <link>https://www.infoq.com/news/2026/09/hashicorp-packer-verification/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/09/hashicorp-packer-verification/en/headerimage/generatedHeaderImage-1788853414930.jpg"/&gt;&lt;p&gt;HashiCorp has released Packer v1.16.0, adding native support for generating, signing, and verifying SLSA provenance attestations for every image the tool builds. The release provides teams with a secure, tamper-proof record of how a machine image was made. It does this without needing extra supply-chain tools.&lt;/p&gt; &lt;i&gt;By Claudio Masolo&lt;/i&gt;</description>
      <category>Hashicorp</category>
      <category>Virtual Machines</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Tue, 08 Sep 2026 14:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/09/hashicorp-packer-verification/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Claudio Masolo</dc:creator>
      <dc:date>2026-09-08T14:00:00Z</dc:date>
      <dc:identifier>/news/2026/09/hashicorp-packer-verification/en</dc:identifier>
    </item>
    <item>
      <title>Presentation: Platform Engineering in the Age of AI</title>
      <link>https://www.infoq.com/presentations/ai-platform-engineering-roundtable/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/presentations/ai-platform-engineering-roundtable/en/mediumimage/medium-1788861349861.jpg"/&gt;&lt;p&gt;The panelists explain how platform teams adapt to support AI-assisted engineering, highlighting which capabilities belong in the platform. They discuss trade-offs between standardization and developer autonomy, while sharing strategies to manage AI tooling, security guardrails, and shifting workflows.&lt;/p&gt; &lt;i&gt;By Stéphane Di Cesare, Davide de Paolis, Stephen Cihak, Camila Macedo, Renato Losio&lt;/i&gt;</description>
      <category>Internal Developer Portal</category>
      <category>Artificial Intelligence</category>
      <category>Developer Experience</category>
      <category>Transcripts</category>
      <category>Platform Engineering</category>
      <category>InfoQ Live - August 2026</category>
      <category>DevOps</category>
      <category>Development</category>
      <category>AI, ML &amp; Data Engineering</category>
      <category>presentation</category>
      <pubDate>Tue, 08 Sep 2026 14:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/presentations/ai-platform-engineering-roundtable/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Stéphane Di Cesare, Davide de Paolis, Stephen Cihak, Camila Macedo, Renato Losio</dc:creator>
      <dc:date>2026-09-08T14:00:00Z</dc:date>
      <dc:identifier>/presentations/ai-platform-engineering-roundtable/en</dc:identifier>
    </item>
    <item>
      <title>GitLab Warns That AI Agent Sandboxes Are Only as Secure as Their Network Access</title>
      <link>https://www.infoq.com/news/2026/09/gitlab-ai-sandbox-access/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/09/gitlab-ai-sandbox-access/en/headerimage/generatedHeaderImage-1788446396087.jpg"/&gt;&lt;p&gt;GitLab warns that isolating an AI coding agent in a sandbox does not necessarily make the agent safe. In a new security analysis, the company describes an internal evaluation in which an AI agent escaped its sandbox by exploiting a vulnerable package proxy that had been explicitly placed on the sandbox's allowlist.&lt;/p&gt; &lt;i&gt;By Craig Risi&lt;/i&gt;</description>
      <category>AIOps</category>
      <category>AI Security</category>
      <category>AI Development</category>
      <category>Artificial Intelligence</category>
      <category>GitLab</category>
      <category>DevOps</category>
      <category>AI, ML &amp; Data Engineering</category>
      <category>news</category>
      <pubDate>Tue, 08 Sep 2026 12:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/09/gitlab-ai-sandbox-access/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Craig Risi</dc:creator>
      <dc:date>2026-09-08T12:00:00Z</dc:date>
      <dc:identifier>/news/2026/09/gitlab-ai-sandbox-access/en</dc:identifier>
    </item>
    <item>
      <title>Presentation: A Solopreneur's Journey: From Engineer to Puzzle Master and Storyteller</title>
      <link>https://www.infoq.com/presentations/solopreneur-journey/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/presentations/solopreneur-journey/en/mediumimage/joe-cassavaugh-medium-1788338336405.jpg"/&gt;&lt;p&gt;Joe Cassavaugh shares his journey from software engineer to successful solopreneur with a $2M+ indie franchise. He explains how he scaled production to 10 games in 5 years, adopted Unity to boost velocity 4-6x, optimized content pipelines, and leveraged refactoring patterns. He discusses key trade-offs between corporate engineering and solopreneurship for senior devs and leaders.&lt;/p&gt; &lt;i&gt;By Joe Cassavaugh&lt;/i&gt;</description>
      <category>Best Practices</category>
      <category>Transcripts</category>
      <category>Game Development</category>
      <category>QCon San Francisco 2025</category>
      <category>Development</category>
      <category>presentation</category>
      <pubDate>Tue, 08 Sep 2026 09:10:00 GMT</pubDate>
      <guid>https://www.infoq.com/presentations/solopreneur-journey/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Joe Cassavaugh</dc:creator>
      <dc:date>2026-09-08T09:10:00Z</dc:date>
      <dc:identifier>/presentations/solopreneur-journey/en</dc:identifier>
    </item>
    <item>
      <title>Article: Implementing Chaos Engineering in Financial Payment Systems: Lessons from Enterprise ECS Deployments</title>
      <link>https://www.infoq.com/articles/chaos-engineering-ecs-payments/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/articles/chaos-engineering-ecs-payments/en/headerimage/chaos-engineering-ecs-payments-header-1788254676411.jpg"/&gt;&lt;p&gt;Standard chaos engineering assumes experiments stop cleanly, blast radius is knowable in advance, and production is fair game. Payment systems violate all three. Salim Adedeji describes ECS-specific failure modes from enterprise deployments: a 60-second DNS TTL that produced 93-second failover, retry logic amplifying database load 2.4x, and AZ rebalancing loops that generic tooling misses.&lt;/p&gt; &lt;i&gt;By Salim Adedeji&lt;/i&gt;</description>
      <category>Cloud</category>
      <category>Containers</category>
      <category>Amazon Web Services</category>
      <category>Reliability</category>
      <category>Compliance</category>
      <category>Financial Applications</category>
      <category>Fault Tolerance</category>
      <category>Chaos Engineering</category>
      <category>Site Reliability Engineering</category>
      <category>DevOps</category>
      <category>Development</category>
      <category>Architecture &amp; Design</category>
      <category>article</category>
      <pubDate>Tue, 08 Sep 2026 09:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/articles/chaos-engineering-ecs-payments/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Salim Adedeji</dc:creator>
      <dc:date>2026-09-08T09:00:00Z</dc:date>
      <dc:identifier>/articles/chaos-engineering-ecs-payments/en</dc:identifier>
    </item>
    <item>
      <title>Does ICANN Open the Door on Identity Theft by Dropping 3rd Level .name Domains Registrations?</title>
      <link>https://www.infoq.com/news/2026/09/name-domain-drop/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://www.infoq.com/styles/static/images/logo/logo_bigger.jpg"/&gt;&lt;p&gt;Neil Fraser's disclosure highlights a regulatory change affecting the .name top-level domain. Following ICANN's approval, Verisign will eliminate third-level registrations due to declining usage. This affects about 22,000 registrants and raises security concerns, as released second-level domains could be exploited. Affected users are considering legal options to challenge the decision.&lt;/p&gt; &lt;i&gt;By Olimpiu Pop&lt;/i&gt;</description>
      <category>Cloud</category>
      <category>DNS</category>
      <category>Security</category>
      <category>Infrastructure</category>
      <category>DevOps</category>
      <category>Development</category>
      <category>news</category>
      <pubDate>Tue, 08 Sep 2026 08:08:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/09/name-domain-drop/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Olimpiu Pop</dc:creator>
      <dc:date>2026-09-08T08:08:00Z</dc:date>
      <dc:identifier>/news/2026/09/name-domain-drop/en</dc:identifier>
    </item>
    <item>
      <title>Netflix Moves toward Open Source Flink Autoscaler for 30,000+ Streaming Jobs</title>
      <link>https://www.infoq.com/news/2026/09/netflix-flink-autoscaler/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/09/netflix-flink-autoscaler/en/headerimage/generatedHeaderImage-1787937137575.jpg"/&gt;&lt;p&gt;Netflix is moving toward the open-source Apache Flink Autoscaler for more than 30,000 streaming jobs across multiple AWS regions. The operator-level approach addresses limitations of Netflix’s cluster level autoscaler for complex, stateful pipelines. Netflix reports a 58% reduction in annualized Flink compute expenditure for one team, saving approximately $1.1 million annually.&lt;/p&gt; &lt;i&gt;By Leela Kumili&lt;/i&gt;</description>
      <category>Apache</category>
      <category>Clusters</category>
      <category>Cloud Computing</category>
      <category>Distributed Systems</category>
      <category>Apache Kafka</category>
      <category>Temporal Patterns</category>
      <category>Event Stream Processing</category>
      <category>Kubernetes</category>
      <category>Scalability</category>
      <category>Kubernetes Operator</category>
      <category>Optimization</category>
      <category>Spring Boot</category>
      <category>Apache Flink</category>
      <category>Data Pipelines</category>
      <category>DevOps</category>
      <category>Development</category>
      <category>Architecture &amp; Design</category>
      <category>news</category>
      <pubDate>Mon, 07 Sep 2026 14:06:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/09/netflix-flink-autoscaler/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Leela Kumili</dc:creator>
      <dc:date>2026-09-07T14:06:00Z</dc:date>
      <dc:identifier>/news/2026/09/netflix-flink-autoscaler/en</dc:identifier>
    </item>
    <item>
      <title>Presentation: From AI Agent Demo to Production: Automated Testing and Evaluation</title>
      <link>https://www.infoq.com/presentations/ai-agent-testing-evaluation/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/presentations/ai-agent-testing-evaluation/en/mediumimage/zhou-yu-medium-1787813732120.jpeg"/&gt;&lt;p&gt;Zhou Yu discusses why AI agents stall in demo phase and shares how simulation-driven testing solves compliance and reliability bottlenecks. Learn how Columbia and Arklex AI use synthetic user personas, trajectory entropy, and automated CI/CD pipelines to evaluate multi-turn agents, catch edge cases before deployment, and scale self-learning workflows in production.&lt;/p&gt; &lt;i&gt;By Zhou Yu&lt;/i&gt;</description>
      <category>Large language models</category>
      <category>Quality</category>
      <category>Performance Evaluation</category>
      <category>Testing</category>
      <category>QCon AI Boston 2026</category>
      <category>Transcripts</category>
      <category>Reliability</category>
      <category>Agents</category>
      <category>Simulation</category>
      <category>Automated testing</category>
      <category>Performance</category>
      <category>Data</category>
      <category>Development</category>
      <category>Architecture &amp; Design</category>
      <category>AI, ML &amp; Data Engineering</category>
      <category>presentation</category>
      <pubDate>Mon, 07 Sep 2026 11:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/presentations/ai-agent-testing-evaluation/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Zhou Yu</dc:creator>
      <dc:date>2026-09-07T11:00:00Z</dc:date>
      <dc:identifier>/presentations/ai-agent-testing-evaluation/en</dc:identifier>
    </item>
    <item>
      <title>Zone Redundancy Comes to API Management Standard v2</title>
      <link>https://www.infoq.com/news/2026/09/apim-standard-v2-zone-redundancy/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://www.infoq.com/styles/static/images/logo/logo_bigger.jpg"/&gt;&lt;p&gt;Microsoft has enabled zone redundancy on the Standard v2 tier of Azure API Management, following its arrival on Premium v2 in December. Standard v2 starts at $700 per month against $2,801 for Premium v2, but carries a 99.95% SLA rather than 99.99%. Zone redundancy can only be configured when creating an instance.&lt;/p&gt; &lt;i&gt;By Steef-Jan Wiggers&lt;/i&gt;</description>
      <category>Cloud</category>
      <category>Cost Optimization</category>
      <category>API Gateway</category>
      <category>Azure</category>
      <category>Microsoft Azure</category>
      <category>Reliability</category>
      <category>API</category>
      <category>Fault Tolerance</category>
      <category>Microsoft</category>
      <category>DevOps</category>
      <category>Development</category>
      <category>Architecture &amp; Design</category>
      <category>news</category>
      <pubDate>Mon, 07 Sep 2026 10:09:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/09/apim-standard-v2-zone-redundancy/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Steef-Jan Wiggers</dc:creator>
      <dc:date>2026-09-07T10:09:00Z</dc:date>
      <dc:identifier>/news/2026/09/apim-standard-v2-zone-redundancy/en</dc:identifier>
    </item>
    <item>
      <title>CERN Renounces RHEL in Favor of  Debian for its Accelerator Controls Infrastructure</title>
      <link>https://www.infoq.com/news/2026/09/cern-debian-infra/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/09/cern-debian-infra/en/headerimage/generatedHeaderImage-1788760881078.jpg"/&gt;&lt;p&gt;CERN engineers announced a shift from Red Hat-based distributions to Debian for its accelerator control systems. This decision stems from Red Hat's tightening compiler mandates, which threatened legacy hardware. The transition, focused on 2,200 specialized control machines, is set for completion in late 2026, while CERN's other systems will remain with Red Hat and AlmaLinux.&lt;/p&gt; &lt;i&gt;By Olimpiu Pop&lt;/i&gt;</description>
      <category>Linux</category>
      <category>Infrastructure</category>
      <category>Debian</category>
      <category>DevOps</category>
      <category>Development</category>
      <category>news</category>
      <pubDate>Mon, 07 Sep 2026 07:07:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/09/cern-debian-infra/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Olimpiu Pop</dc:creator>
      <dc:date>2026-09-07T07:07:00Z</dc:date>
      <dc:identifier>/news/2026/09/cern-debian-infra/en</dc:identifier>
    </item>
    <item>
      <title>vlt 1.0 Ships as a Drop-in npm Replacement with Phased Installs, Graph Queries, and Malware-Blocking</title>
      <link>https://www.infoq.com/news/2026/09/vlt-npm-replacement/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/09/vlt-npm-replacement/en/headerimage/generatedHeaderImage-1788539629791.jpg"/&gt;&lt;p&gt;vlt, created by the original npm team, has launched version 1.0 as a drop-in replacement for npm. It features phased installations to prevent automatic script execution, a queryable dependency graph with over 60 selectors, and hosted registries that block malicious packages. The tool aims to enhance security and streamline the JavaScript development process.&lt;/p&gt; &lt;i&gt;By Daniel Curtis&lt;/i&gt;</description>
      <category>Web Development</category>
      <category>JavaScript</category>
      <category>Security</category>
      <category>NPM</category>
      <category>TypeScript</category>
      <category>Development</category>
      <category>news</category>
      <pubDate>Mon, 07 Sep 2026 06:31:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/09/vlt-npm-replacement/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Daniel Curtis</dc:creator>
      <dc:date>2026-09-07T06:31:00Z</dc:date>
      <dc:identifier>/news/2026/09/vlt-npm-replacement/en</dc:identifier>
    </item>
    <item>
      <title>Java News Roundup: TornadoVM 6, JReleaser, LangChain4j, Java Operator SDK, JHipster, Yupiik Fusion</title>
      <link>https://www.infoq.com/news/2026/09/java-news-roundup-aug31-2026/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/09/java-news-roundup-aug31-2026/en/headerimage/java-news-roundup-image-1788715275955.jpg"/&gt;&lt;p&gt;This week's Java roundup for August 31st, 2026, features news highlighting: the GA release of TornadoVM 6.0; point releases of JReleaser, LangChain4j, Java Operator SDK, JHipster, Kotlin Toolchain and Yupiik Fusion; and maintenance releases of Micronaut and GraalVM Development Kit.&lt;/p&gt; &lt;i&gt;By Michael Redlich&lt;/i&gt;</description>
      <category>Java Operator SDK</category>
      <category>JDK 27</category>
      <category>GraalVM</category>
      <category>Kotlin</category>
      <category>TornadoVM</category>
      <category>LangChain4j</category>
      <category>JReleaser</category>
      <category>Yupiik</category>
      <category>JDK 28</category>
      <category>Java</category>
      <category>JHipster</category>
      <category>Micronaut</category>
      <category>Development</category>
      <category>Architecture &amp; Design</category>
      <category>news</category>
      <pubDate>Mon, 07 Sep 2026 02:30:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/09/java-news-roundup-aug31-2026/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Michael Redlich</dc:creator>
      <dc:date>2026-09-07T02:30:00Z</dc:date>
      <dc:identifier>/news/2026/09/java-news-roundup-aug31-2026/en</dc:identifier>
    </item>
    <item>
      <title>Google Mantis: an Agentic Vulnerability Scanning Harness for Reducing False Positives</title>
      <link>https://www.infoq.com/news/2026/09/google-mantis-vulnerability-scan/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/09/google-mantis-vulnerability-scan/en/headerimage/google-mantis-scanner-1788693601725.jpeg"/&gt;&lt;p&gt;Google has open-sourced Mantis, an AI-agent framework designed to automate the software vulnerability lifecycle, from identifying and validating vulnerabilities to reproducing and fixing them. Google says it developed Mantis to address the high rate of false positives and hallucinated vulnerabilities produced by conventional AI-powered code scanning.&lt;/p&gt; &lt;i&gt;By Sergio De Simone&lt;/i&gt;</description>
      <category>Open Source</category>
      <category>Security Vulnerabilities</category>
      <category>Large language models</category>
      <category>Google</category>
      <category>Agents</category>
      <category>Development</category>
      <category>AI, ML &amp; Data Engineering</category>
      <category>Architecture &amp; Design</category>
      <category>news</category>
      <pubDate>Sun, 06 Sep 2026 12:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/09/google-mantis-vulnerability-scan/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Sergio De Simone</dc:creator>
      <dc:date>2026-09-06T12:00:00Z</dc:date>
      <dc:identifier>/news/2026/09/google-mantis-vulnerability-scan/en</dc:identifier>
    </item>
  </channel>
</rss>
