A trust-boundary flaw in six code agents shows how a malicious repository can manipulate sandboxed tools, not by breaking the model, but by abusing path handling and approval design.
A newly disclosed trust-boundary flaw shows how repository tricks can push coding assistants past their workspace limits, where a single bad write may become a serious host-level security problem.
Wiz has disclosed GhostApproval, an attack method that uses a decades-old technique to mislead AI coding assistants and test the limits of approval-based security on developer machines.
A symlink-based trick shows how agentic coding tools can be pushed beyond the directory a user thinks they approved.
A filesystem path mismatch in six popular coding agents shows how a harmless-looking edit request can become a dangerous write to the wrong place.
A newly named technique turns AI coding mistakes into a security boundary problem, showing how a hallucinated identifier can become a dangerous trust decision.
A new security study suggests that an AI coding assistant can reject a harmful request in conversation and still help assemble it when the same objective is fragmented inside a development workflow.
Alibaba’s move against Claude Code shows how a single privacy allegation can turn an AI developer tool into a company-wide trust decision.
AI coding tools can generate endpoint behavior that resembles attack traffic, forcing defenders to tell normal automation from hostile tradecraft.
A batch of JetBrains add-ons posing as AI coding assistants highlights a familiar weakness in modern development: once a plugin is trusted, it may inherit far more access than users realize.
Malicious JetBrains plugins and suspicious browser add-ons are putting AI keys and chatbot conversations in the crosshairs, showing how software supply chains can become data-collection pipelines.
Coding assistants are being discussed less as chat tools and more as systems that can work with greater autonomy, which shifts the security question from output quality to control, permissions, and containment.
A new agent-risk label is pushing a familiar security lesson into a more dangerous setting: if a coding assistant treats untrusted tool output like instructions, the boundary between data and action can collapse.
A revisited take on an AI coding assistant became less about novelty and more about a familiar security question: what counts as enough due diligence before trusting machine-generated code?
A public jab at a rival's pricing has turned into a clearer warning for enterprise buyers: in AI coding, cost control is now a core security-and-operations question, not a footnote.