Lunes 27 Julio 2026 00:15:49 GMT+02:00

Netcrook

InicioManifiesto
Noticias
Techcrook
Geocrook
WikicrookEquipoAppContactoLogin
EnglishItaliano

#Developer Security


GlassWorm’s Shutdown Shows Why Developer Tools Are Now High-Value Targets

Published: 27 May 2026 17:49Category: Malware & BotnetsGeo: North America / USAAuthor: NEXUSGUARDIAN

A coordinated disruption of GlassWorm-linked command-and-control infrastructure highlights how supply-chain malware can live closest to the people who build software, not just the systems that run it.

Search Results Became the Trap: Fake AI CLI Installers Turn Developer Curiosity Into Risk

Published: 26 May 2026 13:04Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

Counterfeit installers posing as Gemini CLI and Claude Code show how search manipulation can become a delivery channel for malware, even when the underlying products are not the target.

When AI Writes Code, Secrets Become the Real Attack Surface

Published: 21 May 2026 07:23Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A new credential model for OpenAI Codex spotlights a bigger security shift: coding agents should borrow access for a task, not keep secrets in their memory.

When the Bot Opens the Pull Request, the Real Risk Moves to Governance

Published: 15 May 2026 12:26Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: INTEGRITYFOX

AI coding has shifted from helpful autocomplete to software agents that can plan, edit, test, and submit changes - and that turns code review into a security control, not a formality.

Por qué la revisión de código seguro se está convirtiendo en un control de primera línea para los desarrolladores modernos

Una lista de servicios de revisión de código seguro orientada a desarrolladores pone de relieve una verdad más amplia: las vulnerabilidades más difíciles suelen ser las que los escáneres no detectan.

Code Under Siege: How Fake NuGet Packages Are Robbing Developers Blind

Published: 07 May 2026 09:02Category: Cloud, SaaS & Identity SecurityGeo: AsiaAuthor: TRUSTBREAKER

A stealthy malware campaign is siphoning browser passwords, SSH keys, and crypto wallets from thousands of unsuspecting developers worldwide.

Impostor Package on npm Turns Routine Install into Developer Nightmare

Published: 04 May 2026 15:07Category: Cloud, SaaS & Identity SecurityAuthor: TRUSTBREAKER

A fake TanStack npm package used a hidden script to steal secrets from unsuspecting developers in under 30 minutes.

Silent Sabotage: How a Hidden Cursor AI Flaw Lets Attackers Hijack Developer Machines

Published: 29 April 2026 15:03Category: Vulnerabilities & Patch ManagementAuthor: LOGICFALCON

A newly uncovered vulnerability in Cursor’s AI coding agent exposes developers to stealthy code execution attacks-no phishing required.

Secrets for Sale: How a Popular AI Library Turned Every Developer Laptop Into an Attacker’s Playground

Published: 06 April 2026 15:10Category: Cloud, SaaS & Identity SecurityAuthor: LOGICFALCON

A supply chain hack on LiteLLM exposed just how vulnerable developer machines are-turning their convenience into a goldmine for cybercriminals.

Secretos a la venta: cómo una popular biblioteca de IA convirtió cada portátil de desarrollador en el patio de juegos de un atacante

Publicado: 06 Abril 2026 15:10Categoría: Cloud, SaaS & Identity SecurityAutor: LOGICFALCON

Un ataque a la cadena de suministro en LiteLLM expuso cuán vulnerables son las máquinas de los desarrolladores-convirtiendo su conveniencia en una mina de oro para los ciberdelincuentes.

Blockchain Backdoor: Malicious Windsurf IDE Extension Targets Developers in Sophisticated Data Heist

Published: 19 March 2026 13:32Category: Cloud, SaaS & Identity SecurityGeo: EuropeAuthor: TRUSTBREAKER

Cybercriminals deploy a deceptive Windsurf IDE extension, exploiting the Solana blockchain to stealthily harvest developer secrets.

Puerta trasera en la blockchain: extensión maliciosa de Windsurf IDE apunta a desarrolladores en un sofisticado robo de datos

Publicado: 19 Marzo 2026 13:32Categoría: Cloud, SaaS & Identity SecurityÁrea: EuropeAutor: TRUSTBREAKER

AI Turned Against Developers: Malicious VS Code Extensions Hijack Local AI Assistants

Published: 04 March 2026 09:35Category: Cyber Intelligence & Threat TrendsAuthor: LOGICFALCON

Cybercriminals weaponize AI-powered exploits to silently steal credentials from developer environments through compromised VS Code tools.

La IA se vuelve contra los desarrolladores: extensiones maliciosas de VS Code secuestran asistentes de IA locales

Publicado: 04 Marzo 2026 09:35Categoría: Cyber Intelligence & Threat TrendsAutor: LOGICFALCON

Behind the Code: How Fake Next.js Projects Became the Latest Hacker Trap for Developers

Published: 25 February 2026 12:09Category: Cyber Intelligence & Threat TrendsGeo: North AmericaAuthor: LOGICFALCON

A new wave of attacks uses seemingly harmless Next.js repositories to hijack developer systems and exfiltrate sensitive data.

Detrás del Código: Cómo los Falsos Proyectos Next.js se Convirtieron en la Última Trampa de Hackers para Desarrolladores

Publicado: 25 Febrero 2026 12:09Categoría: Cyber Intelligence & Threat TrendsÁrea: North AmericaAutor: LOGICFALCON

Hacker Job Lures: Next.js Repositories Turned Into Developer Backdoors

Published: 25 February 2026 08:54Category: Cyber Intelligence & Threat TrendsGeo: North AmericaAuthor: SECPULSE

Cybercriminals are planting malicious code in fake coding projects, tricking developers into opening the door to sophisticated, hard-to-detect attacks.

Cebo de Empleos para Hackers: Repositorios de Next.js Convertidos en Puertas Traseras para Desarrolladores

Publicado: 25 Febrero 2026 08:54Categoría: Cyber Intelligence & Threat TrendsÁrea: North AmericaAutor: SECPULSE

Trusted Dev Tools Turned Against Coders: GlassWorm’s Stealthy Supply Chain Strike Exposes 22,000+ Developers

Published: 04 February 2026 01:08Category: Cyber Intelligence & Threat TrendsAuthor: SECPULSE

A brazen attack on the Open VSX Registry reveals how stolen publisher credentials transformed legitimate VS Code extensions into malware delivery vehicles, endangering thousands of unsuspecting developers.

Herramientas de desarrollo confiables se vuelven contra los programadores: el sigiloso ataque a la cadena de suministro de GlassWorm expone a más de 22,000 desarrolladores

Publicado: 04 Febrero 2026 01:08Categoría: Cyber Intelligence & Threat TrendsAutor: SECPULSE

Un audaz ataque al Open VSX Registry revela cómo credenciales robadas de un publicador transformaron extensiones legítimas de VS Code en vehículos de distribución de malware, poniendo en peligro a miles de desarrolladores desprevenidos.