News
GitHub Gives Enterprises a Full Count of Who Holds the Keys
GitHub Enterprise Cloud now lets organizations export a full inventory of credentials, helping security teams identify stale, overprivileged and forgotten access across users, apps and automation ...
TeamPCP Supply Chain Attack Leads to CrowdSec Source Code Being Stolen
CrowdSec says attackers stole source code from about 170 private GitHub repositories after a TanStack npm supply chain attack exposed an OAuth token tied to a former employee ...
Cycode Extends DevSecOps Reach to Software Packages Developers Download
Cycode is adding workstation-level protection to stop developers and AI coding agents from downloading malicious or insufficiently vetted software packages ...
Your AI Coding Assistant Has the Keys to the Repo. Z.ai Just Showed Why That Matters
ZCode’s default-on indexing feature reportedly uploaded entire developer workspaces to cloud storage, highlighting why AI coding assistants should be treated as privileged software and closely monitored ...
New npm Threat Bypasses Install Script Protections
A malicious npm package that has been downloaded millions of times comes with a new way of spreading the malware that makes it easier to bypass security protections, say researchers with security ...
GitLab Tightens Rate Limits as Coding Agents Drive Demand
GitLab is introducing new rate limits for its cloud-based DevOps platform as growing demand from AI agents and automated development tools increases pressure on its infrastructure. The changes, which begin October 19, ...
Codex Sandbox Escapes Show Why Agent Guardrails Can’t Live Inside the Agent
Two patched OpenAI Codex vulnerabilities, Heapjack and Overpatch, exposed how coding agents can escape sandboxes and reach developer systems without approval prompts ...
Claude Code Adds AGENTS.md Fallback, Cutting Instruction File Sprawl
Claude Code now supports AGENTS.md, giving development teams a shared instruction format across multiple AI coding agents and reducing configuration drift ...
GitHub Separates Who Writes Code From Who Runs Your CI
GitHub’s new workflow execution protections let teams control who and what can trigger Actions workflows, reducing CI/CD attack paths and tightening pipeline security ...
US District Court Decision in AI’s Favor Worries Open-Source Developers
A federal appeals court handed GitHub, Microsoft, and OpenAI an important win in the first major appellate ruling over how AI coding tools can use open-source code. As we all know, all ...
Splunk Open Sources Token Meter Tool for Application Developers
Splunk’s open-source Token Meter gives developers real-time visibility into AI coding agent activity, token consumption and estimated costs across tools including Claude Code, Codex and Cursor ...
Anthropic Adds a Coordinator to Claude Projects for Running AI Work in Parallel
Anthropic’s redesigned Claude Projects coordinates parallel Claude Code sessions, delegates work across branches and brings the results back through familiar pull-request review workflows ...

