OpenAI’s Codex Micro turns a desktop peripheral into a command surface for coding agents, and that shift carries real trust and configuration implications.
A wire-level analysis of Grok Build CLI v0.2.93 raises a sharper question than simple file access: what, exactly, did the agent package and transmit by default?
A Grok Build test exposed a deeper risk in AI-assisted coding: separate storage channels can move repository history and tracked secrets even when the model itself sees only a tiny slice of traffic.
June’s tech-posting uptick points to a recovery in software hiring, yet the strongest signals are in senior roles, AI-fluent work, and tighter security oversight.
A planned launch this week points to a new model partnership, but the real story for developers is how coding tools handle context, trust, and sensitive data.
A supply-chain campaign tied to PolinRider shows how package ecosystems can turn routine development work into a high-risk execution path.
A newly tracked flaw in an AI developer tool is less interesting as a single bug than as a sign that workspace trust, tool approval, and local command execution still lack a mature security model.
Three lookalike npm packages aimed at frontend developers underscore how package-name trust and installer-time execution can collide on a developer workstation.
A reported extension-based malware campaign puts VS Code ecosystems under a harsh spotlight: the real target is not just software, but the trust chain that delivers it.
The newest application-security pitch is not about choosing between static analysis and AI, but about wiring them together so one finds problems and the other helps developers fix them faster.
Coding assistants are being discussed less as chat tools and more as systems that can work with greater autonomy, which shifts the security question from output quality to control, permissions, and containment.
A PyPI poisoning wave tied to Hades shows how a few hidden startup lines inside package releases can turn ordinary installs into silent execution paths.
A phishing wave used recruiter-style and code-review lures to steer targets toward attacker-controlled repositories, showing how familiar developer workflows can become a malware delivery path.
A revisited take on an AI coding assistant became less about novelty and more about a familiar security question: what counts as enough due diligence before trusting machine-generated code?
A malicious npm campaign shows how routine dependency installs can become a secret-harvesting path into developer systems, with crypto and Web3 workflows carrying outsized risk.
A reported IronWorm campaign puts malicious npm packages, GitHub access, and developer credentials in the same attack path, with crypto and web3 teams in the crosshairs.
A search-led impersonation of Claude Code shows how modern social engineering can turn setup curiosity into an execution path for a reported .NET infostealer.
A newly published proof-of-concept tied to VS Code has pushed a familiar developer convenience into uncomfortable territory: if an authentication token can be reached through an editor workflow, the practical risk can be as serious as any password leak.
A reported weakness in Visual Studio Code’s webview layer raises a familiar but dangerous question: what happens when an editor boundary and a GitHub authorization token sit too close together?
A malicious npm package exposed its operator’s private GitHub token, underscoring supply-chain risks and the dangers of exposed credentials.