Devlery - AI news for builders
Devlery blog
AI news for builders.
Agent 365 goes GA and prices agent governance at $15 per user
Microsoft Agent 365 is now generally available, turning AI agents into governed inventory across Entra, Defender, Purview, and Microsoft 365 admin.
OpenAI says AI evals need harnesses, tools, and budgets
OpenAI published a frontier governance framework and third-party evaluation playbook. Agent scores now need harnesses, tools, and budgets attached.
Mastra Agent Builder puts permissions at the center of internal agents
Mastra Agent Builder and its Temporal integration show how TypeScript agent platforms are moving toward RBAC, allow-lists, durable execution, and workflow traces.
Cursor and Endor Labs Put Security Gates Inside the Coding Agent Loop
Cursor and Endor Labs formalized a hooks-based security partnership for agentic coding, blocking package installs, MCP use, and risky commands inside the IDE loop.
Cognition’s $1B round puts Devin’s 89% code claim on trial
Cognition says Devin commits 89% of its internal code. The harder question is whether agent-written PRs come with reviewable test evidence.
Cursor agents run 2,000 times a week, and automation finds its next bottleneck
Faire says Cursor Cloud Agents doubled weekly PR throughput and now run 2,000+ times per week, shifting the bottleneck from models to environment, permissions, and workflow.
IBM and Red Hat Put $5B Behind Lightwell for AI-Era Patching
IBM and Red Hat introduced Project Lightwell, a $5B effort to turn AI-found open-source vulnerabilities into verified patches.
Sysdig Traces a 113-Second LLM-Agent Intrusion Into Postgres
Sysdig says an LLM-driven attacker chained a marimo RCE into AWS secrets, SSH bastions, and an internal PostgreSQL dump.
OpenRouter Raises $113M as Model Routing Becomes AI Infrastructure
OpenRouter raised $113M after reaching 25T weekly tokens, 8M+ developers, and 400+ models. The round turns model routing into an infrastructure question.
Anthropic sabotage report puts agent monitoring on trial
Anthropic’s Opus 4 sabotage risk report shows why coding agents need audit trails across logs, pull requests, security events, and external review.
OpenAI Sets ChatGPT Retirement Dates for o3 and GPT-4.5
OpenAI will remove GPT-4.5 and o3 from ChatGPT on separate sunset schedules. The API is unchanged, but teams should separate ChatGPT workflows from API model lifecycles.
NSA MCP guidance warns about GitHub scope, WhatsApp leaks, and agent runtime risk
NSA published MCP security design guidance for AI-driven automation, turning tool permissions, tokens, logs, sandboxing, DLP, and scans into deployment requirements.