News
Broadcom Launches Trusted Artifact Service for Spring Framework
Broadcom launches TrueSource Trusted Artifacts to provide hardened Spring dependencies, secure open source packages and automated vulnerability remediation ...
VS Code 1.135 Gives AI Coding Agents a Second Opinion
VS Code 1.135 adds Rubber Duck AI review, persistent agent sessions, Agent Host infrastructure and clearer token usage as Microsoft builds a more agentic IDE ...
A Simple Website Summary Just Exposed the Limits of AI Coding Guardrails
Claude Code’s Auto Mode was bypassed in an attack chain that turned a routine webpage summary into remote code execution, highlighting the limits of AI agent guardrails ...
GitHub Tightens Copilot’s Billing and Governance Rules Ahead of a Busy Fall
GitHub Copilot is tightening enterprise controls with upfront seat billing, longer chat retention and a Balanced code review default ...
Report Shines Spotlight on 91 Vulnerabilities Fixed in Latest Update to Spring Framework
Sonatype says 91 Spring vulnerabilities affecting more than 209,000 software components highlight how AI is accelerating vulnerability discovery and creating a new patching challenge for DevSecOps teams ...
Dash0 Acquires Polar Signals for Continuous Profiling and GPU Visibility
Observability startup Dash0 announced this week that it acquired Berlin-based continuous profiling specialist Polar Signals. The deal adds continuous profiling to SignalStore, Dash0’s OpenTelemetry-native data platform. Continuous profiling has been part of ...
Hackers Target Popular arrayref Rust Crate in Supply-Chain Attack
Security researchers are sorting through a complex, stealthy, and fast-moving supply-chain attack aimed at pushing information-stealing malware by compromising the account of the maintainer of multiple Rust crates and introducing four more ...
Critical Flaw in isolated-vm Can Lead to Sandbox Escape, RCE Threat
Developers for years have been using vm2, an open-source Node.js library, to run untrusted JavaScript inside a secure and isolated sandbox environment. It uses Node.js’s built-in modules and JavaScript Proxies and lets ...
Cursor Launches Origin Code Hosting Platform as GitHub Rival
AI coding provider Cursor has launched Origin, a code hosting platform that puts source code and AI coding agents inside the Cursor development environment. The new coding platform expands the company into ...
Claude Code’s Temporary Usage Boost Expires Tonight. Here’s What Actually Changes
Anthropic’s temporary 50% increase to Claude Code weekly usage limits expires August 19, reducing available capacity for developers and DevOps teams without lowering subscription prices ...
Adronite Unveils AI Coding Tool Based on Embedded Context Engine
Adronite launches Codistry, an AI coding tool that uses a context engine to map codebases, reduce token usage and generate more production-ready code ...
Microsoft’s GitHub Hit by Major Outage as AI-Driven Demand Strains Infrastructure
GitHub, the Microsoft Corp.-owned code hosting platform serving more than 180 million developers, is still reeling from a widespread outage on Monday that severely disrupted software development pipelines globally. The hours-long incident ...

