As organizations grapple with AI-powered threats, supply chain vulnerabilities, and the challenges of securing cloud-native architectures, GitLab is positioning itself at the forefront of the DevSecOps revolution. The company’s comprehensive, intelligent DevSecOps platform enables security teams to collaborate directly with developers within existing workflows, improving operational efficiency while reducing security and compliance risks.
At Black Hat USA 2025, the GitLab team will be showcasing how the company’s singular platform approach is helping organizations ship secure software faster in an increasingly complex threat landscape.
Black Hat attendees shouldn’t miss picking up some of GitLab’s signature Tanuki swag at booth 5745, where they can get hands-on demos of the platform’s newest security enhancements and learn how GitLab’s AI copilot, Duo, is already helping security teams eliminate time-consuming work while democratizing security expertise for developers.
In our conversation, GitLab CISO Josh Lemos shares some practical solutions for the biggest cybersecurity challenges facing organizations in 2025 � from managing the “AI security arms race” to implementing zero-trust architectures that can handle the non-deterministic nature of agentic AI systems.
++
VMblog: How does GitLab help companies and where can attendees find GitLab during the show?
Josh Lemos: At GitLab, we’re building a comprehensive, intelligent DevSecOps platform that helps organizations ship secure software faster. Our singular platform approach enables security teams to collaborate directly with developers within workflows, improving operational efficiency and reducing security and compliance risk.
GitLab will be at booth 5745 on August 6 and 7, where attendees can demo our newest security enhancements to the platform. We encourage everyone to drop by and grab some of our signature GitLab Tanuki swag.
VMblog: With AI attacks, supply chain vulnerabilities, and cloud security challenges dominating headlines in 2025, where should companies focus their security efforts?
Lemos: These challenges are interconnected. Prioritizing software supply-chain security can help address all three by providing teams with greater visibility into their software stack and enabling them to respond more quickly to threats.
AI can exacerbate existing application security issues. Using strong security design patterns enabled through platform engineering can avoid common security pitfalls and identity security anti-patterns during the DevSecOps workflow.
In cloud-native architectures, this becomes even more critical as organizations must track not just application dependencies but also container images, cloud service APIs, and third-party SaaS integrations that underpin modern cloud supply chains.
VMblog: The “AI security arms race” is a hot topic this year. How is your company leveraging AI defensively, and what’s your take on the AI-powered threats we’re seeing emerge?
Lemos: AI has increased the frequency of attacks and lowered the effort required for execution. Sophisticated supply chain attacks can now exploit traditional multi-factor authentication (MFA) models, and bad actors are now much more efficient at scanning for vulnerabilities that exist as “low-hanging fruit” for exploitation.
However, AI also provides a productivity boost for defenders. Our security team already uses AI to incrementally eliminate time-consuming, non-strategic work. GitLab’s AI copilot, Duo, helps us summarize large amounts of information related to emerging security issues, allowing us to take action faster and freeing our team to focus on more in-depth work.
AI also helps us reduce vulnerabilities earlier in the software development lifecycle by enhancing collaboration between our team and developers by democratizing security expertise. For example, developers no longer have to wait to ask security to explain a vulnerability because they can gain that same context from GitLab Duo.
VMblog: What would you say to a CISO worried about their organization adopting AI too quickly?
Lemos: The emergence of new technology introducing security risks is nothing new.
Security often lags behind innovation, and the path forward requires striking a balance. AI security challenges should not stop security leaders from measured, responsible adoption.
Any organization that avoids agentic AI adoption altogether will miss out on all the benefits of this new technology while still being exposed to AI risks through vendors and shadow AI usage. Leaders who effectively balance AI innovation and risk will gain a true competitive advantage.
VMblog: Zero-trust architecture has evolved significantly since 2024. How has your approach to zero-trust implementation changed, and what practical advice do you have for organizations still in the planning stages?
Lemos: Zero-trust architecture must now evolve to reconsider security boundaries that may be challenged by the emergence of agentic AI. The non-deterministic nature of agents can cause them to behave in unexpected ways, which can challenge existing security frameworks that were originally developed to anticipate human behavior. CISOs can start adopting zero trust for AI by establishing frameworks and controls that track, audit, and attribute agentic behaviors across environments.
For example, comprehensive monitoring frameworks can help security teams track AI agent behavior across codebase activity, staging and production environments, databases, and all accessible applications. Composite identities, which link an agent’s identity with the responsible human user, can also ensure proper authentication and authorization before an AI accesses resources, thereby creating transparent accountability chains for agent behavior.
VMblog: What’s the biggest cybersecurity blind spot you’re seeing organizations struggle with in 2025?
Lemos: AI has dominated the industry discourse for the past four years, and for good reason. However, CISOs cannot overlook how common security frustrations within the software development lifecycle contribute to their team’s cognitive load and leave them at a disadvantage.
The ever-increasing complexity of organizations’ tech stacks creates a larger attack surface and generates more security scan findings for teams to sort through, prioritize, and address.
Approaching development through the lens of software minimization can help teams avoid complexity resulting from suboptimal design decisions, such as difficult-to-maintain code and redundant dependencies. This will enhance the security of the software supply chain, reduce scanner noise, and ease the burden on developers to fix non-critical issues.
VMblog: What should be at the top of every security leader’s priority list as we move through 2025?
Lemos: Leaders must begin adapting their teams, strategies, and frameworks today for tomorrow’s AI future. Organizations that are adaptable and see AI security as an extension of their existing programs are more likely to succeed. By focusing the core fundamentals of authentication and authorization of AI enabled workflows help narrow the potential impact of non-deterministic outputs. The rapid pace of change in AI necessitates proactive preparation to maintain a robust security posture.
VMblog: If you had to predict the cybersecurity conversation we’ll all be having at Black Hat 2026, what topic or challenge do you think will dominate the discourse?
Lemos: With the launch of protocols like Model Context Protocol and Agent2Agent, I expect more organizations to introduce agentic capabilities with enhanced interoperability. The conversation will shift beyond the security of individual AI agents towards how organizations manage risk for complex, multi-agent ecosystems.
It will become even more important to develop non-deterministic and AI-native security solutions for non-deterministic systems. For example, using “skeptical” agents to scale guardrails and help humans limit the behaviors of other agents within an ecosystem.
##






