<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>InfoQ - DevSecOps</title>
    <link>https://www.infoq.com</link>
    <description>InfoQ DevSecOps feed</description>
    <item>
      <title>How Figma Uses AI Agents for Security</title>
      <link>https://www.infoq.com/news/2026/09/figma-security-agents/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=DevSecOps</link>
      <description>&lt;img src="https://res.infoq.com/news/2026/09/figma-security-agents/en/headerimage/generatedHeaderImage-1787900821229.jpg"/&gt;&lt;p&gt;The engineering team at software company Figma recently documented how they built AI agents to help their security team investigate alerts, search past incidents, check company systems, and even prepare code fixes. The agents learn from previous investigations, reducing repetitive work and helping engineers resolve complex alerts about 70% faster.&lt;/p&gt; &lt;i&gt;By Renato Losio&lt;/i&gt;</description>
      <category>Agents</category>
      <category>Application Security</category>
      <category>AI Security</category>
      <category>Security Assessment</category>
      <category>Cloud Security</category>
      <category>DevSecOps</category>
      <category>DevOps</category>
      <category>AI, ML &amp; Data Engineering</category>
      <category>news</category>
      <pubDate>Sun, 06 Sep 2026 06:59:00 GMT</pubDate>
      <guid>https://www.infoq.com/news/2026/09/figma-security-agents/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=DevSecOps</guid>
      <dc:creator>Renato Losio</dc:creator>
      <dc:date>2026-09-06T06:59:00Z</dc:date>
      <dc:identifier>/news/2026/09/figma-security-agents/en</dc:identifier>
    </item>
    <item>
      <title>Article: Eliminating Long-Lived Credentials in GCP with Workload Identity Federation</title>
      <link>https://www.infoq.com/articles/gcp-wif-scale/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=DevSecOps</link>
      <description>&lt;img src="https://res.infoq.com/articles/gcp-wif-scale/en/headerimage/gcp-wif-scale-header-1787838950646.jpg"/&gt;&lt;p&gt;Long-lived GCP service account keys are secrets that must be managed forever, are hard to rotate, and are easy to leak. Scaling Workload Identity Federation to 120+ production projects shows why it changes how machine identity is approached entirely: keys are secrets to manage, federated identities are trust relationships configured once, gated by attribute conditions.&lt;/p&gt; &lt;i&gt;By Shijin Nair&lt;/i&gt;</description>
      <category>Cloud</category>
      <category>Google Cloud</category>
      <category>Cloud Security</category>
      <category>Authentication</category>
      <category>DevSecOps</category>
      <category>Architecture &amp; Design</category>
      <category>DevOps</category>
      <category>article</category>
      <pubDate>Mon, 31 Aug 2026 11:00:00 GMT</pubDate>
      <guid>https://www.infoq.com/articles/gcp-wif-scale/?utm_campaign=infoq_content&amp;utm_source=infoq&amp;utm_medium=feed&amp;utm_term=DevSecOps</guid>
      <dc:creator>Shijin Nair</dc:creator>
      <dc:date>2026-08-31T11:00:00Z</dc:date>
      <dc:identifier>/articles/gcp-wif-scale/en</dc:identifier>
    </item>
  </channel>
</rss>
