A coordinated disruption of GlassWorm-linked command-and-control infrastructure highlights how supply-chain malware can live closest to the people who build software, not just the systems that run it.
Counterfeit installers posing as Gemini CLI and Claude Code show how search manipulation can become a delivery channel for malware, even when the underlying products are not the target.
A new credential model for OpenAI Codex spotlights a bigger security shift: coding agents should borrow access for a task, not keep secrets in their memory.
AI coding has shifted from helpful autocomplete to software agents that can plan, edit, test, and submit changes - and that turns code review into a security control, not a formality.
Una lista de servicios de revisión de código seguro orientada a desarrolladores pone de relieve una verdad más amplia: las vulnerabilidades más difíciles suelen ser las que los escáneres no detectan.
A stealthy malware campaign is siphoning browser passwords, SSH keys, and crypto wallets from thousands of unsuspecting developers worldwide.
A fake TanStack npm package used a hidden script to steal secrets from unsuspecting developers in under 30 minutes.
A newly uncovered vulnerability in Cursor’s AI coding agent exposes developers to stealthy code execution attacks-no phishing required.
A supply chain hack on LiteLLM exposed just how vulnerable developer machines are-turning their convenience into a goldmine for cybercriminals.
Un ataque a la cadena de suministro en LiteLLM expuso cuán vulnerables son las máquinas de los desarrolladores-convirtiendo su conveniencia en una mina de oro para los ciberdelincuentes.
Cybercriminals deploy a deceptive Windsurf IDE extension, exploiting the Solana blockchain to stealthily harvest developer secrets.
Cybercriminals weaponize AI-powered exploits to silently steal credentials from developer environments through compromised VS Code tools.
A new wave of attacks uses seemingly harmless Next.js repositories to hijack developer systems and exfiltrate sensitive data.
Cybercriminals are planting malicious code in fake coding projects, tricking developers into opening the door to sophisticated, hard-to-detect attacks.
A brazen attack on the Open VSX Registry reveals how stolen publisher credentials transformed legitimate VS Code extensions into malware delivery vehicles, endangering thousands of unsuspecting developers.
Un audaz ataque al Open VSX Registry revela cómo credenciales robadas de un publicador transformaron extensiones legítimas de VS Code en vehículos de distribución de malware, poniendo en peligro a miles de desarrolladores desprevenidos.