<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>InfoQ</title>
    <link>https://www.infoq.com</link>
    <description>InfoQ feed</description>
    <item>
      <title>Java News Roundup: JobRunr 9, OpenXava 8, Quarkus, LangChain4j, JNoSQL, Introducing Lathe</title>
      <link>https://www.infoq.com/news/2026/10/java-news-roundup-sep28-2026/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/10/java-news-roundup-sep28-2026/en/headerimage/java-news-roundup-image-1791219262766.jpg"/&gt;&lt;p&gt;This week's Java roundup for September 28th, 2026, features news highlighting: the GA releases of JobRunr 9.0 and OpenXava 8.0; point releases for Quarkus, Micronaut, LangChain4j, Eclipse JNoSQL; ADK for Java and ADK for Kotlin; and introducing Lathe, a new Java language server.&lt;/p&gt; &lt;i&gt;By Michael Redlich&lt;/i&gt;</description>
      <category>JobRunr</category>
      <category>Eclipse JNoSQL</category>
      <category>Quarkus</category>
      <category>OpenXava</category>
      <category>Java</category>
      <category>Micronaut</category>
      <category>Google ADK for Java</category>
      <category>Jakarta EE</category>
      <category>JDK 28</category>
      <category>LangChain4j</category>
      <category>Lathe</category>
      <category>Google ADK for Kotlin</category>
      <category>Development</category>
      <category>Architecture &amp; Design</category>
      <category>news</category>
      <pubDate>Mon, 05 Oct 2026 17:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/10/java-news-roundup-sep28-2026/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Michael Redlich</dc:creator>
      <dc:date>2026-10-05T17:00:00Z</dc:date>
      <dc:identifier>/news/2026/10/java-news-roundup-sep28-2026/en</dc:identifier>
    </item>
    <item>
      <title>Akka Tests Spec-Driven AI Delivery Across 65 Open Source Projects</title>
      <link>https://www.infoq.com/news/2026/10/ai-spec-driven-delivery/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/10/ai-spec-driven-delivery/en/headerimage/generatedHeaderImage-1789859037002.jpg"/&gt;&lt;p&gt;Akka used 65 open-source projects to examine how specification structure, context, model selection, automated validation, and delivery guardrails affect AI assisted software porting. The experiment measured time, token use, code size, test parity, and performance, finding substantial variation across models, effort levels, and project types.&lt;/p&gt; &lt;i&gt;By Leela Kumili&lt;/i&gt;</description>
      <category>Automated testing</category>
      <category>Claude</category>
      <category>Benchmark</category>
      <category>AI Architecture</category>
      <category>Developer Experience</category>
      <category>AI coding agents</category>
      <category>Architecture &amp; Design</category>
      <category>Development</category>
      <category>AI, ML &amp; Data Engineering</category>
      <category>news</category>
      <pubDate>Mon, 05 Oct 2026 13:58:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/10/ai-spec-driven-delivery/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Leela Kumili</dc:creator>
      <dc:date>2026-10-05T13:58:00Z</dc:date>
      <dc:identifier>/news/2026/10/ai-spec-driven-delivery/en</dc:identifier>
    </item>
    <item>
      <title>Presentation: Building Reusable Evaluation Frameworks for Agentic AI Products</title>
      <link>https://www.infoq.com/presentations/elastic-ai-agent-evaluations/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/presentations/elastic-ai-agent-evaluations/en/mediumimage/susan-chang-medium-1790846586191.jpeg"/&gt;&lt;p&gt;Susan Chang explains how Elastic transitioned from siloed, ad-hoc AI agent evaluations to a unified, production-grade framework. She discusses balancing LLM-as-a-judge with deterministic rules, bridging Python data science evals with TypeScript production code, and implementing deep tracing to catch regressions across complex RAG and cybersecurity workloads while preserving domain context.&lt;/p&gt; &lt;i&gt;By Susan Chang&lt;/i&gt;</description>
      <category>Large language models</category>
      <category>Performance Evaluation</category>
      <category>Observability</category>
      <category>MLOps</category>
      <category>Agents</category>
      <category>Transcripts</category>
      <category>QCon AI Boston 2026</category>
      <category>ElasticSearch</category>
      <category>Retrieval-Augmented Generation</category>
      <category>Development</category>
      <category>Architecture &amp; Design</category>
      <category>AI, ML &amp; Data Engineering</category>
      <category>presentation</category>
      <pubDate>Mon, 05 Oct 2026 11:19:00 GMT</pubDate>
      <guid>https://www.infoq.com/presentations/elastic-ai-agent-evaluations/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Susan Chang</dc:creator>
      <dc:date>2026-10-05T11:19:00Z</dc:date>
      <dc:identifier>/presentations/elastic-ai-agent-evaluations/en</dc:identifier>
    </item>
    <item>
      <title>Article: The Platform Engineering Playbook for Production LLMs</title>
      <link>https://www.infoq.com/articles/platform-engineering-playbook-production-llms/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/articles/platform-engineering-playbook-production-llms/en/headerimage/platform-engineering-playbook-production-llms-header-1790763235683.jpg"/&gt;&lt;p&gt;In this article, author discusses his experience with AI agent hallucinations in an inventory recommendation system and how this problem was solved by treating the LLM stack as a platform infrastructure concern instead of as an application one. He makes a case for a shared LLM platform with common services like prompt registry &amp; versioning, schema enforcement and token cost attribution by request.&lt;/p&gt; &lt;i&gt;By Aditya Mulik&lt;/i&gt;</description>
      <category>Large language models</category>
      <category>Agentic AI Architecture</category>
      <category>Agents</category>
      <category>Artificial Intelligence</category>
      <category>AI, ML &amp; Data Engineering</category>
      <category>article</category>
      <pubDate>Mon, 05 Oct 2026 11:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/articles/platform-engineering-playbook-production-llms/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Aditya Mulik</dc:creator>
      <dc:date>2026-10-05T11:00:00Z</dc:date>
      <dc:identifier>/articles/platform-engineering-playbook-production-llms/en</dc:identifier>
    </item>
    <item>
      <title>Podcast: Future Cybersecurity: Hardware Memory Safety, Automated Governance and Post-Quantum Cryptography</title>
      <link>https://www.infoq.com/podcasts/future-cybersecurity-hardware-memory-safety/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/podcasts/future-cybersecurity-hardware-memory-safety/en/smallimage/infoq-podcast-500-1790672981256.jpg"/&gt;&lt;p&gt;In this episode, Chris Swan, engineer at Atsign and security track host at QCon London, reflects on the ideas shared during QCon London 2026 and teases topics of the future edition. The discussion explores how security engineering is shifting from relying on human vigilance toward automated, system-level defences across the entire application stack.&lt;/p&gt; &lt;i&gt;By Chris Swan&lt;/i&gt;</description>
      <category>Large language models</category>
      <category>The InfoQ Podcast</category>
      <category>Security</category>
      <category>Hardware</category>
      <category>DevOps</category>
      <category>podcast</category>
      <pubDate>Mon, 05 Oct 2026 11:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/podcasts/future-cybersecurity-hardware-memory-safety/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Chris Swan</dc:creator>
      <dc:date>2026-10-05T11:00:00Z</dc:date>
      <dc:identifier>/podcasts/future-cybersecurity-hardware-memory-safety/en</dc:identifier>
    </item>
    <item>
      <title>Aspire 13.6 Adds Persistent Dashboard Telemetry and First-Party Java and Rust Hosting</title>
      <link>https://www.infoq.com/news/2026/10/dotnet-aspire-13-6-release/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://www.infoq.com/styles/static/images/logo/logo_bigger.jpg"/&gt;&lt;p&gt;Microsoft has released Aspire 13.6. The dashboard now stores telemetry in SQLite and keeps up to ten completed runs per application. The release adds prerelease hosting packages for Java and Rust, portable volume paths, and new CLI options. Breaking changes include automatic TLS for local MongoDB resources and a new default Cosmos DB emulator image.&lt;/p&gt; &lt;i&gt;By Almir Vuk&lt;/i&gt;</description>
      <category>.NET</category>
      <category>.NET 11</category>
      <category>.NET Core</category>
      <category>.NET Aspire</category>
      <category>Cloud Native Architecture</category>
      <category>.NET 10</category>
      <category>Development</category>
      <category>news</category>
      <pubDate>Mon, 05 Oct 2026 09:39:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/10/dotnet-aspire-13-6-release/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Almir Vuk</dc:creator>
      <dc:date>2026-10-05T09:39:00Z</dc:date>
      <dc:identifier>/news/2026/10/dotnet-aspire-13-6-release/en</dc:identifier>
    </item>
    <item>
      <title>Cloudflare Fixes Cross-Tenant Data Exposure in Containers</title>
      <link>https://www.infoq.com/news/2026/10/cloudflare-cross-tenant-exposure/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/10/cloudflare-cross-tenant-exposure/en/headerimage/generatedHeaderImage-1790844732167.jpg"/&gt;&lt;p&gt;Cloudflare has disclosed a cross-tenant data exposure vulnerability in Containers and Sandboxes, caused by thin-provisioned storage pools configured to skip zeroing reused blocks. Researchers recovered directory structures, database pages and complete SQLite databases across four continents. Cloudflare remediated it and found no evidence of exploitation.&lt;/p&gt; &lt;i&gt;By Steef-Jan Wiggers&lt;/i&gt;</description>
      <category>Cloudflare</category>
      <category>Containers</category>
      <category>Storage</category>
      <category>Security</category>
      <category>Multi-tenancy</category>
      <category>Architecture</category>
      <category>Cloud</category>
      <category>Development</category>
      <category>Architecture &amp; Design</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Mon, 05 Oct 2026 08:48:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/10/cloudflare-cross-tenant-exposure/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Steef-Jan Wiggers</dc:creator>
      <dc:date>2026-10-05T08:48:00Z</dc:date>
      <dc:identifier>/news/2026/10/cloudflare-cross-tenant-exposure/en</dc:identifier>
    </item>
    <item>
      <title>Cloudflare Plans Public Certificate Authority to Issue Quantum-Safe TLS Certificates</title>
      <link>https://www.infoq.com/news/2026/10/postquatam-certificates/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/10/postquatam-certificates/en/headerimage/generatedHeaderImage-1791007674738.jpg"/&gt;&lt;p&gt;Cloudflare will operate a free public Certificate Authority to issue quantum-safe Transport Layer Security certificates. This initiative addresses challenges in migrating from classical public key cryptography to post-quantum methods. It utilizes Merkle Tree Certificates to reduce data payloads and maintain system efficiency, while also enhancing certificate transparency and revocation processes.&lt;/p&gt; &lt;i&gt;By Olimpiu Pop&lt;/i&gt;</description>
      <category>Cryptography</category>
      <category>Internet</category>
      <category>Encryption</category>
      <category>Development</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Mon, 05 Oct 2026 05:05:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/10/postquatam-certificates/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Olimpiu Pop</dc:creator>
      <dc:date>2026-10-05T05:05:00Z</dc:date>
      <dc:identifier>/news/2026/10/postquatam-certificates/en</dc:identifier>
    </item>
    <item>
      <title>Google's Android Security State Libraries Enable Component-Level Security Verification</title>
      <link>https://www.infoq.com/news/2026/10/android-security-state-libs/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/10/android-security-state-libs/en/headerimage/coder-agents-self-hosted-ai-1791130673838.jpeg"/&gt;&lt;p&gt;Google's AndroidX Security State libraries enables apps to verify security patch status at the individual component level, rather than relying on a single, device-wide security patch date.&lt;/p&gt; &lt;i&gt;By Sergio De Simone&lt;/i&gt;</description>
      <category>Mobile Security</category>
      <category>Mobile</category>
      <category>Google</category>
      <category>Android</category>
      <category>Development</category>
      <category>news</category>
      <pubDate>Sun, 04 Oct 2026 17:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/10/android-security-state-libs/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Sergio De Simone</dc:creator>
      <dc:date>2026-10-04T17:00:00Z</dc:date>
      <dc:identifier>/news/2026/10/android-security-state-libs/en</dc:identifier>
    </item>
    <item>
      <title>Pizza Bot: Open-Source Inbox for Background AI Agents</title>
      <link>https://www.infoq.com/news/2026/10/pizza-bot-ai-agents/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/10/pizza-bot-ai-agents/en/headerimage/generatedHeaderImage-1790332896027.jpg"/&gt;&lt;p&gt;A team of developers working at AWS recently open-sourced Pizza Bot, a self-hosted application designed to let AI agents run tasks in the background and return results through an inbox-style interface. Agents can perform scheduled or webhook-triggered work, delegate tasks to specialized workers, and pause for human approval when needed.&lt;/p&gt; &lt;i&gt;By Renato Losio&lt;/i&gt;</description>
      <category>Model Context Protocol (MCP)</category>
      <category>AI Coding</category>
      <category>Agents</category>
      <category>AWS</category>
      <category>Developer Experience</category>
      <category>AI coding agents</category>
      <category>Open Source</category>
      <category>Development</category>
      <category>AI, ML &amp; Data Engineering</category>
      <category>news</category>
      <pubDate>Sun, 04 Oct 2026 06:34:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/10/pizza-bot-ai-agents/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Renato Losio</dc:creator>
      <dc:date>2026-10-04T06:34:00Z</dc:date>
      <dc:identifier>/news/2026/10/pizza-bot-ai-agents/en</dc:identifier>
    </item>
    <item>
      <title>New Archestra's OpenAPPA Saturates Two Major Security Benchmarks with a 0% Attack Success Rate</title>
      <link>https://www.infoq.com/news/2026/10/open-APPA-zero-security-breach/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/10/open-APPA-zero-security-breach/en/headerimage/generatedHeaderImage-1791068760274.jpg"/&gt;&lt;p&gt;Archestra released OpenAPPA, an open-source security engine designed to stop data exfiltration caused by prompt injection or model hallucination. The team reports zero successful attacks when running security benchmarks Bench-Corp (20 multi-step enterprise workflows) and AgentThreatBench, versus 10% for Claude Code’s auto mode and 31% for Microsoft FIDES.&lt;/p&gt; &lt;i&gt;By Bruno Couriol&lt;/i&gt;</description>
      <category>Enterprise Architecture</category>
      <category>AI Security</category>
      <category>Development</category>
      <category>AI, ML &amp; Data Engineering</category>
      <category>news</category>
      <pubDate>Sat, 03 Oct 2026 23:41:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/10/open-APPA-zero-security-breach/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Bruno Couriol</dc:creator>
      <dc:date>2026-10-03T23:41:00Z</dc:date>
      <dc:identifier>/news/2026/10/open-APPA-zero-security-breach/en</dc:identifier>
    </item>
    <item>
      <title>GitLab Vulnerability under Active Exploitation Enables Unauthenticated Data Exfiltration</title>
      <link>https://www.infoq.com/news/2026/10/gitlab-critical-vulnerabilities/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/10/gitlab-critical-vulnerabilities/en/headerimage/gitlab-cloud-seed-preview-1791042234130.jpeg"/&gt;&lt;p&gt;CVE-2026-85706 is a critical GitLab path-traversal vulnerability that has moved beyond theoretical risk into confirmed exploitation. It affects self-managed GitLab CE/EE and could allow an unauthenticated remote attacker to read arbitrary files from the GitLab.&lt;/p&gt; &lt;i&gt;By Sergio De Simone&lt;/i&gt;</description>
      <category>Continuous Deployment</category>
      <category>Security Vulnerabilities</category>
      <category>Software Supply Chain</category>
      <category>Continuous Integration</category>
      <category>GitLab</category>
      <category>Development</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Sat, 03 Oct 2026 16:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/10/gitlab-critical-vulnerabilities/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Sergio De Simone</dc:creator>
      <dc:date>2026-10-03T16:00:00Z</dc:date>
      <dc:identifier>/news/2026/10/gitlab-critical-vulnerabilities/en</dc:identifier>
    </item>
    <item>
      <title>Presentation: Building GenAI Platform at DoorDash</title>
      <link>https://www.infoq.com/presentations/doordash-genai-platform-architecture/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/presentations/doordash-genai-platform-architecture/en/mediumimage/SiddharthKodwaniSwaroopChitlur-medium-1790246592519.jpg"/&gt;&lt;p&gt;Swaroop Chitlur and Sidd Kodwani share DoorDash’s journey building an internal GenAI platform. They discuss core architectural bets, transitioning from vendor-first setups to open-weights models, navigating LLM and agent gateways, and balancing accuracy, latency, and cost for over 5,000 internal users.&lt;/p&gt; &lt;i&gt;By Siddharth Kodwani, Swaroop Chitlur&lt;/i&gt;</description>
      <category>Large language models</category>
      <category>Machine Learning</category>
      <category>Transcripts</category>
      <category>Platform Engineering</category>
      <category>Infrastructure</category>
      <category>Architecture</category>
      <category>QCon AI Boston 2026</category>
      <category>Developer Experience</category>
      <category>Generative AI</category>
      <category>Development</category>
      <category>Architecture &amp; Design</category>
      <category>AI, ML &amp; Data Engineering</category>
      <category>presentation</category>
      <pubDate>Sat, 03 Oct 2026 11:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/presentations/doordash-genai-platform-architecture/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Siddharth Kodwani, Swaroop Chitlur</dc:creator>
      <dc:date>2026-10-03T11:00:00Z</dc:date>
      <dc:identifier>/presentations/doordash-genai-platform-architecture/en</dc:identifier>
    </item>
    <item>
      <title>Istio 1.31 Adds Agentgateway Waypoints and Moves Release Artifacts off Google Cloud</title>
      <link>https://www.infoq.com/news/2026/10/istio-1-31-agentgateway/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/10/istio-1-31-agentgateway/en/headerimage/header-1790887193946.jpeg"/&gt;&lt;p&gt;Istio 1.31 adds agentgateway waypoints in ambient mode, with a canary configuration fix included in 1.31.1. It also ends the publication of images and Helm charts to Google Cloud, requiring repository migration ahead of the 13 October outage test and signing-key updates for teams verifying images.&lt;/p&gt; &lt;i&gt;By Mark Silvester&lt;/i&gt;</description>
      <category>Cloud Native Computing Foundation</category>
      <category>Istio</category>
      <category>Kubernetes</category>
      <category>Service Mesh</category>
      <category>Development</category>
      <category>Architecture &amp; Design</category>
      <category>DevOps</category>
      <category>news</category>
      <pubDate>Sat, 03 Oct 2026 08:30:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/10/istio-1-31-agentgateway/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Mark Silvester</dc:creator>
      <dc:date>2026-10-03T08:30:00Z</dc:date>
      <dc:identifier>/news/2026/10/istio-1-31-agentgateway/en</dc:identifier>
    </item>
    <item>
      <title>AI Agents Are Disrupting Open Source Security Disclosure</title>
      <link>https://www.infoq.com/news/2026/10/open-source-ai-security/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</link>
      <description>&lt;img src="https://www.infoq.com/styles/static/images/logo/logo_bigger.jpg"/&gt;&lt;p&gt;A recent article by Anil Madhavapeddy argues that AI agents can turn publicly available clues about software vulnerabilities into working exploits, reducing the effectiveness of traditional disclosure embargoes in open source projects. The author highlights the need for faster patching and release processes as the time between vulnerability disclosure and exploitation shrinks.&lt;/p&gt; &lt;i&gt;By Renato Losio&lt;/i&gt;</description>
      <category>Common Vulnerabilities and Exposures</category>
      <category>Agents</category>
      <category>Application Security</category>
      <category>AI Security</category>
      <category>AI coding agents</category>
      <category>Open Source</category>
      <category>Development</category>
      <category>Architecture &amp; Design</category>
      <category>news</category>
      <pubDate>Sat, 03 Oct 2026 06:46:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/10/open-source-ai-security/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=global</guid>
      <dc:creator>Renato Losio</dc:creator>
      <dc:date>2026-10-03T06:46:00Z</dc:date>
      <dc:identifier>/news/2026/10/open-source-ai-security/en</dc:identifier>
    </item>
  </channel>
</rss>
