Advertisement
VS Code Marketplace Abuse: Detecting Malicious Developer Extensions
Researchers identify malicious Visual Studio Code extensions exfiltrating source code and credentials. Learn how to secure your development environment.
AI-Generated Code Vulnerabilities: Framework Pairing is Key to Risk
AI-generated code introduces an average of 15 vulnerabilities per codebase. This analysis explores how framework choices significantly influence the actual security risk.
AI-Generated Workflows: Hidden Vulnerabilities & Control Gaps
Explore the silent security disaster of AI-generated workflows. Understand hidden vulnerabilities, control gaps, and the critical need for human oversight in AI-driven…
Claude Code Indirect Prompt Injection: Hijacking Developer Machines
Researchers demonstrate a new attack method leveraging indirect prompt injection in Claude Code, enabling the hijack of developer machines via malicious code in…
AI Agent Malware Evasion: Hidden Payloads via GitHub Repos
Novel technique exploits AI coding agents to execute undetectable malware from clean GitHub repositories, bypassing security scanners and human review.
Agentjacking: Tricking AI Coding Agents into Malicious Code Execution
Agentjacking is a new attack where crafted Sentry error reports trick AI coding agents into executing arbitrary code on developer systems, risking intellectual property…
Advertisement
IronWorm: Rust-Written Malware Hits npm Supply Chain Developers
Analysis of the Rust-written IronWorm malware targeting npm supply chain developers.
GitHub Repository Breach: 3,800 Repos Accessed via VS Code Extension
GitHub confirms a security incident where a malicious VS Code extension compromised an employee account, leading to the unauthorized access of 3,800 repos.
Shai-Hulud Worm Code Leak: How Clones Threaten Developer Environments
The release of Shai-Hulud worm source code triggers a surge in self-replicating clones, targeting software developers and automated CI/CD pipelines.
Developer Workstations: The New Front in Software Supply Chain Attacks
A surge in attacks targeting npm, PyPI, and Docker Hub highlights a shift toward stealing developer credentials and API keys from workstations and CI/CD pipelines.
Supply Chain Attack: Bitwarden CLI npm Package Compromised
Analysis of the Bitwarden CLI npm package compromise (version 2023.12.0) leading to developer credential theft and supply chain risk. Includes mitigation.
Cursor AI RCE via Indirect Prompt Injection — Mitigation Guide
Security researchers demonstrate how indirect prompt injection in Cursor AI could lead to full shell access on developer workstations. Patch immediately.
GitHub Malware Campaign: Fake VS Code Alerts Target Developers
Attackers exploit GitHub Discussions to push malware via fake VS Code security alerts. Learn the TTPs used to target developers and how to mitigate risk.
Anthropic Patches Claude Code Vulnerabilities Enabling Silent Hacking
Anthropic addressed flaws in Claude Code that allowed attackers to execute arbitrary commands on developer devices via malicious repository configurations.
Microsoft Warns of Fake Next.js Repos Delivering In-Memory Malware
Microsoft warns developers of a coordinated campaign using malicious Next.js repositories disguised as job assessments to deliver in-memory malware.
AI Code Generation Poses Supply Chain Risk to Developer Machines
Learn how AI-generated code, like from Anthropic's Claude, can introduce vulnerabilities and malicious payloads, compromising developer machines and software supply…