Enterprise document management: The backbone of digital transformation

The evolution of document management began in 1898, and since Edwin Grenville Seibels invented the vertical file system, it has evolved. Today, the Association for Intelligent Information Management (AIIM) defines document management as the software that controls and organises documents throughout an organisation.

The importance of managing information and improving operational efficiency, effectiveness, and compliance have become areas of interest to organisations today. The...

EMERALDWHALE exploits vulnerable Git configuration files

A whale made of emerald illustrating the discovery of the EMERALDWHALE campaign by cyber security researchers that exploits Git configuration files and has leaked over 15,000 credentials.

Sysdig’s Threat Research Team (TRT) has uncovered a global operation known as EMERALDWHALE, which has stolen over 15,000 cloud service credentials by exploiting exposed Git configuration files.

EMERALDWHALE utilised multiple private tools to exploit several misconfigured web services, resulting in the theft of credentials from more than 10,000 private repositories.

Though the operation's primary targets appeared to be cloud service and email providers, the ultimate aim...

GitHub Copilot now supports multiple LLMs

Picture of a person with a digital brain with multiple coloured waves illustrating the GitHub Copilot AI software development assistant gaining accessing to multiple new LLMs (large language models)

GitHub is bringing more flexibility and choice to Copilot through the integration of multiple large language models (LLMs).

Since its inception, GitHub Copilot has utilised different LLMs for varied uses. The journey began with the deployment of Codex, an early iteration of OpenAI's GPT-3, that was fine-tuned specifically for coding tasks. The evolution continued with the launch of Copilot Chat in 2023, initially using GPT-3.5 and subsequently transitioning to GPT-4. As demands...

GitHub Copilot users gain access to Stack Overflow knowledge

Smartphone with glasses and a book illustrating the launch of a Stack Overflow extension for the GitHub Copilot AI assistant for developers, enabling users to access the vast knowledge platform to find solutions for software development problems.

Stack Overflow has launched an extension for GitHub Copilot that promises to improve how developers find solutions. The extension allows users to pose questions directly within the AI-driven coding assistant and receive summarised responses informed by Stack Overflow's extensive knowledge base.

GitHub and Stack Overflow’s partnership aims to aid developers in tackling their most challenging coding queries. The latest Stack Overflow Developer Survey reveals that 61% of developers...

GitLab releases critical security patches amid vulnerability streak

Person applying a band aid illustrating DevOps platform GitLab issuing new critical security patches following a streak of vulnerabilities that could impact organisations and software developers.

GitLab has released a new round of critical security patches for its Community Edition (CE) and Enterprise Edition (EE) products. The company strongly recommends that all self-managed GitLab installations be upgraded immediately to one of the latest versions: 17.4.2, 17.3.5, or 17.2.9.

These patch releases address several critical and high-severity vulnerabilities, including a critical flaw that could allow attackers to run pipelines on arbitrary branches. This latest security...

Low-code revolution: Mendix’s digital transformation masterstroke

Arjo van Oosten, Senior Vice President of Digital Transformation at Mendix, a Siemens business, discusses the low-code revolution and Mendix's role in enterprise digital transformation.

In the past businesses could afford to view digital transformation as a distant challenge, something they’d deal with only if they directly encountered it. But that’s no longer the case. Today, digital transformation is a driving force in the business landscape, continuously evolving and challenging...

GitHub begins offering data residency to EU developers

GitHub Octocat reading a newspaper after news that the company will offer data residency, starting with EU developers.

GitHub has announced that it will introduce data residency capabilities, beginning with EU developers on 29 October 2024. The new data residency feature for Enterprise Cloud will allow organisations to store their GitHub code and repository data in their preferred geographical region.

"We've heard for years from enterprises that being able to control where their data resides is critical for them," explained Jim Wang, VP of Engineering at GitHub. “With data residency,...

GitHub Enterprise Server 3.13.3 tackles critical SAML vulnerability

GitHub has released Enterprise Server 3.13.3, addressing several security vulnerabilities, including a critical flaw affecting instances using SAML single sign-on. 

Alongside security patches, the update delivers bug fixes, minor feature enhancements, and changes to the platform.

The most pressing issue tackled by this update is a critical vulnerability (CVE-2024-6800) impacting instances employing SAML SSO with specific Identity Providers...

CMA shelves app store probes to leverage digital market powers

Signalling its intent to leverage new powers granted by the Digital Markets, Competition, and Consumers Act (DMCCA), the Competition and Markets Authority (CMA) has closed its investigations into Google's Play Store and Apple's App Store.

The investigations – launched over concerns that both tech giants were unfairly leveraging their dominant market positions, to the detriment of UK app developers and consumers – focused primarily on rules mandating the use of proprietary...

Unit 42 researchers uncover critical GitHub Actions vulnerability

A new attack vector that could compromise GitHub repositories has been uncovered by researchers at Palo Alto Networks' Unit 42 team. The vulnerability, which exploits GitHub Actions artifacts generated during CI/CD workflows, could potentially grant high-level access to cloud environments.

The researchers found that a combination of misconfigurations and security flaws can cause artifacts to leak tokens, including those for third-party cloud services and GitHub itself. These...