Tag: AI security
GitHub’s Security Autofix Agent Now Remembers What It Fixed
GitHub’s agentic autofix now uses Copilot Memory to reuse repository-specific security fix patterns, helping Copilot apply lessons from past vulnerabilities across future alerts, reviews and coding workflows ...
Your AI Coding Assistant Has the Keys to the Repo. Z.ai Just Showed Why That Matters
ZCode’s default-on indexing feature reportedly uploaded entire developer workspaces to cloud storage, highlighting why AI coding assistants should be treated as privileged software and closely monitored ...
Why Shift Left is Dead
AI-driven development is exposing risks before code is written, forcing security teams to move beyond shift-left and govern agents, prompts, tools and data across the entire development lifecycle ...
Codex Sandbox Escapes Show Why Agent Guardrails Can’t Live Inside the Agent
Two patched OpenAI Codex vulnerabilities, Heapjack and Overpatch, exposed how coding agents can escape sandboxes and reach developer systems without approval prompts ...
Why MLOps Pipelines Need Security Audits
A practical SecMLOps experiment shows how Apache Airflow ML pipelines can adopt DevSecOps controls for secrets, validation, artifact integrity and auditable security evidence ...
Java 27 Tackles Post-Quantum Security and a Faster Patch Cadence
Java 27 strengthens enterprise security with monthly critical patch updates and post-quantum TLS 1.3 support, helping organizations prepare for AI-driven threats and future quantum risks ...
A Simple Website Summary Just Exposed the Limits of AI Coding Guardrails
Claude Code’s Auto Mode was bypassed in an attack chain that turned a routine webpage summary into remote code execution, highlighting the limits of AI agent guardrails ...
When AI Coding Agents Become Malware Delivery Systems
AI coding agents are becoming part of everyday development work. Developers use them to find libraries, configure projects, troubleshoot installation problems, and set up new tools. An agent can search GitHub, read ...
Why “Tokenmaxxing” Was Always the Wrong Way for Developers to Measure AI Productivity
The term "tokenmaxxing" left the developer lexicon just as quickly as it arrived, and like most viral technology concepts, it means different things depending on who's using it. In practice, the term ...
Critical Flaw in isolated-vm Can Lead to Sandbox Escape, RCE Threat
Developers for years have been using vm2, an open-source Node.js library, to run untrusted JavaScript inside a secure and isolated sandbox environment. It uses Node.js’s built-in modules and JavaScript Proxies and lets ...
What the Microservices Era Can Teach Us About AI
AI agents are not just microservices with LLMs attached. Their long-running, non-deterministic workflows demand durable execution, per-step identity, governance and observability ...
Anthropic Makes Claude Code’s Auto Mode the Default, Betting Automation Beats Manual Review
Anthropic is making Claude Code’s auto mode the default for Pro, Max and Team users, replacing constant permission prompts with classifier-based guardrails designed to catch risky actions without slowing developers down ...

