Muse Spark 1.1 enters U.S. public preview with lower-cost pricing for coding agents, a move that looks commercial on the surface but has workflow and governance implications for teams that adopt AI-assisted development.
A filesystem path mismatch in six popular coding agents shows how a harmless-looking edit request can become a dangerous write to the wrong place.
A proof-of-concept called Friendly Fire highlights a sharper risk in agentic security: the tool meant to inspect hostile code can be steered into executing it.
AI agents that write code and run commands can generate the same endpoint signals defenders watch for in real attacks, especially when they touch secrets or invoke native Windows binaries.
Security researchers have shown that malicious add-on skills for AI coding agents can be packed to look harmless at install time, exposing a trust gap in today’s plugin-style defenses.
A new supply-chain risk in LLM coding agents shows why install-time checks can miss malicious skill packages that only reveal their behavior once execution begins.
Decades-old Bash tricks are being used to test whether open-source AI coding agents can be pushed past their safety checks and into dangerous repository-driven workflows.
A research bypass aimed at open-source AI coding and computer-use agents shows how quickly a command safeguard can become a paper wall if shell behavior is not modeled correctly.
A seemingly harmless GitHub project can become dangerous the moment an agentic coding tool is told to clone it, set it up, and trust what comes next.
A 20-year AWS reflection turns into a hard lesson for security teams: autonomous coding agents are only useful when specs, tests, and telemetry keep them on a short leash.
A study of coding-agent instruction files shows that the quietest part of the stack - the project memory layer - can become a source of wasted tokens, confused priorities, and inconsistent code work.
A study of repo-level instruction files shows how redundant, stale, or contradictory guidance can waste context and make coding agents less reliable.
Security researchers have shown a new "Agentjacking" pattern in which a forged Sentry-style issue can persuade an AI coding agent to run code, exposing a trust problem at the heart of agentic developer tools.
The shift from low-code and no-code into AI-assisted orchestration is changing who can build software, but it is also changing what must be trusted, reviewed, and contained.
A newly disclosed attack class shows how an AI helper asked to investigate an error can be steered into executing malicious code, without phishing or server compromise.
A new agent-risk label is pushing a familiar security lesson into a more dangerous setting: if a coding assistant treats untrusted tool output like instructions, the boundary between data and action can collapse.
Researchers have described a new attack pattern that can steer coding agents toward dangerous actions by hiding malicious instructions inside trusted-looking error data.
A symlink trick aimed at AI-assisted development shows how repository content, agent permissions, and MCP extensibility can collide into a supply-chain risk.
A new credential model for OpenAI Codex spotlights a bigger security shift: coding agents should borrow access for a task, not keep secrets in their memory.
AI coding has shifted from helpful autocomplete to software agents that can plan, edit, test, and submit changes - and that turns code review into a security control, not a formality.