Devlery

Devlery - AI news for builders

DEVLERYDEVLERYDEVLERY

Devlery blog

AI news for builders.

Agent 365 goes GA and prices agent governance at $15 per user

Agent 365 goes GA and prices agent governance at $15 per user

Microsoft Agent 365 is now generally available, turning AI agents into governed inventory across Entra, Defender, Purview, and Microsoft 365 admin.

OpenAI says AI evals need harnesses, tools, and budgets

OpenAI says AI evals need harnesses, tools, and budgets

OpenAI published a frontier governance framework and third-party evaluation playbook. Agent scores now need harnesses, tools, and budgets attached.

Mastra Agent Builder puts permissions at the center of internal agents

Mastra Agent Builder puts permissions at the center of internal agents

Mastra Agent Builder and its Temporal integration show how TypeScript agent platforms are moving toward RBAC, allow-lists, durable execution, and workflow traces.

Cursor and Endor Labs Put Security Gates Inside the Coding Agent Loop

Cursor and Endor Labs Put Security Gates Inside the Coding Agent Loop

Cursor and Endor Labs formalized a hooks-based security partnership for agentic coding, blocking package installs, MCP use, and risky commands inside the IDE loop.

Cognition’s $1B round puts Devin’s 89% code claim on trial

Cognition’s $1B round puts Devin’s 89% code claim on trial

Cognition says Devin commits 89% of its internal code. The harder question is whether agent-written PRs come with reviewable test evidence.

Cursor agents run 2,000 times a week, and automation finds its next bottleneck

Cursor agents run 2,000 times a week, and automation finds its next bottleneck

Faire says Cursor Cloud Agents doubled weekly PR throughput and now run 2,000+ times per week, shifting the bottleneck from models to environment, permissions, and workflow.

IBM and Red Hat Put $5B Behind Lightwell for AI-Era Patching

IBM and Red Hat Put $5B Behind Lightwell for AI-Era Patching

IBM and Red Hat introduced Project Lightwell, a $5B effort to turn AI-found open-source vulnerabilities into verified patches.

Sysdig Traces a 113-Second LLM-Agent Intrusion Into Postgres

Sysdig Traces a 113-Second LLM-Agent Intrusion Into Postgres

Sysdig says an LLM-driven attacker chained a marimo RCE into AWS secrets, SSH bastions, and an internal PostgreSQL dump.

OpenRouter Raises $113M as Model Routing Becomes AI Infrastructure

OpenRouter Raises $113M as Model Routing Becomes AI Infrastructure

OpenRouter raised $113M after reaching 25T weekly tokens, 8M+ developers, and 400+ models. The round turns model routing into an infrastructure question.

Anthropic sabotage report puts agent monitoring on trial

Anthropic sabotage report puts agent monitoring on trial

Anthropic’s Opus 4 sabotage risk report shows why coding agents need audit trails across logs, pull requests, security events, and external review.

OpenAI Sets ChatGPT Retirement Dates for o3 and GPT-4.5

OpenAI Sets ChatGPT Retirement Dates for o3 and GPT-4.5

OpenAI will remove GPT-4.5 and o3 from ChatGPT on separate sunset schedules. The API is unchanged, but teams should separate ChatGPT workflows from API model lifecycles.

NSA MCP guidance warns about GitHub scope, WhatsApp leaks, and agent runtime risk

NSA MCP guidance warns about GitHub scope, WhatsApp leaks, and agent runtime risk

NSA published MCP security design guidance for AI-driven automation, turning tool permissions, tokens, logs, sandboxing, DLP, and scans into deployment requirements.