{
  "id": 9339971,
  "title": "Cycode Extends DevSecOps Reach to Software Packages Developers Download",
  "url": "https://urgent.news/2026/09/23/cycode-extends-devsecops-reach-to-software-packages-developers",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-23T13:00:08.000Z",
  "source": {
    "name": "DevOps.com",
    "slug": "devops-com",
    "url": "https://devops.com/cycode-extends-devsecops-reach-to-software-packages-developers-download/"
  },
  "original_language": "en",
  "account": "Cycode has launched an early access program for a new extension to its platform designed to secure software supply chains. This extension, called Workstation Protection, safeguards developers from inadvertently downloading malicious or suspicious software packages onto their computers. Integrating into Cycode's existing platform, Workstation Protection employs two controls in real time to prevent the download of known malware and recent updates, ensuring the integrity of the software development process. The platform's agentic development lifecycle protection is aimed at developers who frequently download components from various repositories, with cybercriminals increasingly targeting these sources to inject malware. Devin Maguire, Cycode's senior product marketing manager, highlights the growing threat of malicious prompts and AI coding agents that can trick developers into downloading harmful software. Mitch Ashley, vice president and practice lead at The Futurum Group, emphasizes that coding agents inherently introduce risks to the software supply chain, making real-time control of package installations crucial. As cybersecurity teams increasingly focus on the software supply chain as a vulnerability, the extension acts as a proactive measure to secure applications before they reach production, ensuring that malicious components are never introduced.",
  "summary": "Cycode is adding workstation-level protection to stop developers and AI coding agents from downloading malicious or insufficiently vetted software packages.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}