Tag: AI security
Critical Flaw in isolated-vm Can Lead to Sandbox Escape, RCE Threat
Developers for years have been using vm2, an open-source Node.js library, to run untrusted JavaScript inside a secure and isolated sandbox environment. It uses Node.js’s built-in modules and JavaScript Proxies and lets ...
What the Microservices Era Can Teach Us About AI
AI agents are not just microservices with LLMs attached. Their long-running, non-deterministic workflows demand durable execution, per-step identity, governance and observability ...
Anthropic Makes Claude Code’s Auto Mode the Default, Betting Automation Beats Manual Review
Anthropic is making Claude Code’s auto mode the default for Pro, Max and Team users, replacing constant permission prompts with classifier-based guardrails designed to catch risky actions without slowing developers down ...
Open Source Code Just as Secure as Proprietary Software—If You Manage It Right, Says CISA
Open source can be just as safe as proprietary software, though government agencies (and private enterprises) should take additional measures to secure it properly, according to a new guide published by the ...
‘GitLost’ Flaw Lets Attackers Trick GitHub AI Agent Into Leaking Private Repos
Noma researchers again show how easy it is to manipulate AI agents with malicious commands via indirect prompt injection attacks ...
From Phishing to Vishing: Why DevSecOps Must Rethink Communication Security
Key Takeaways: Vishing is the new frontline threat: Attackers are shifting from emails to phone-based scams, using AI and social engineering to bypass traditional security controls. DevSecOps must expand its scope: Securing ...
Still Using API Keys for Your AI Agent? Here’s When it’s Time to Upgrade
API keys got you here. They won’t get you where you’re going. OAuth isn’t a future upgrade. It’s the foundation your agents should have been built on from the start. ...
Agentic DevSecOps: AI Security Co-Pilots for Your CI/CD Pipeline
The emergence of AI has brought endless possibilities and innovative opportunities in today’s ever-changing, fast-paced technology landscape. AI is helping development teams produce software significantly faster than ever before. AI-enabled DevSecOps tools ...
LayerX: Anthropic’s Claude Code Can Easily Be Easily Weaponized
LayerX researchers were able to convince the popular AI coding tool to bypass its guardrails and execute malicious instructions ...
Lessons from 2025: The Year “Agent Mitigation” Became a Thing
Explore the emergence of agent mitigation as a formal discipline in response to 2025's AI failures, highlighting best practices for secure and reliable AI agent deployment ...
Surprise! Everybody Uses AI Tools for Software Development, Few Do So Securely
AI is generating code faster than teams can secure it, widening software supply chain risk and exposing major gaps in AppSec and governance ...
VS Code Pushes Hard on AI Agents While Quietly Killing Free Code Completion
Microsoft's VS Code update brings Agent HQ, TypeScript 7 preview, and kills free IntelliCode. What developers need to know about the latest changes ...

