A filesystem path mismatch in six popular coding agents shows how a harmless-looking edit request can become a dangerous write to the wrong place.
A reported flaw in Amazon Q Developer for Visual Studio Code shows how AI coding tools can inherit old-school workspace and symlink bugs, turning a convenience layer into a local compromise risk.
A malicious Hugging Face repository reportedly imitated OpenAI’s Privacy Filter project and appeared in the platform’s trending list while delivering infostealer malware to Windows users.