Coding

AIのコードを誰が検証するのか? オープンソースの取り込みが直面する「規模」という課題 News

AIのコードを誰が検証するのか? オープンソースの取り込みが直面する「規模」という課題

ActiveState プロダクト責任者、ジョニー・リベラ 先週開催されたBlack Hatの展示会場で、私たちのチームがアプリケーションセキュリティ責任者、プラットフォームエンジニア、CISOと交わしたほぼすべての会話の中で、ある質問が繰...
Clean GitHub repo tricks AI coding agents into running malware News

Clean GitHub repo tricks AI coding agents into running malware

An agentic coding tool tasked with cloning and setting up a seemingly benign GitHub repository could execute a malicious...
GitHub adds AI-powered bug detection to expand security coverage News

GitHub adds AI-powered bug detection to expand security coverage

GitHub is adopting AI-based scanning for its Code Security tool to expand vulnerability detections beyond the CodeQL sta...
Fake Next.js job interview tests backdoor developer’s devices News

Fake Next.js job interview tests backdoor developer’s devices

A coordinated campaign targeting software developers with job-themed lures is using malicious repositories posing as leg...
New GlassWorm attack targets macOS via compromised OpenVSX extensions News

New GlassWorm attack targets macOS via compromised OpenVSX extensions

A new GlassWorm malware attack through compromised OpenVSX extensions focuses on stealing passwords, crypto-wallet data,...
Malicious AI extensions on VSCode Marketplace steal developer data News

Malicious AI extensions on VSCode Marketplace steal developer data

Two malicious extensions in Microsoft’s Visual Studio Code (VSCode) Marketplace that were collectively installed 1.5 mil...
University of Sydney suffers data breach exposing student and staff info News

University of Sydney suffers data breach exposing student and staff info

Hackers gained access to an online coding repository belonging to the University of Sydney and stole files with personal...
Glassworm malware returns in third wave of malicious VS Code packages News

Glassworm malware returns in third wave of malicious VS Code packages

The Glassworm campaign, which first emerged on the OpenVSX and Microsoft Visual Studio marketplaces in October, is now i...
Code beautifiers expose credentials from banks, govt, tech orgs News

Code beautifiers expose credentials from banks, govt, tech orgs

Thousands of credentials, authentication keys, and configuration data impacting organizations in sensitive sectors have ...
Open VSX rotates access tokens used in supply-chain malware attack News

Open VSX rotates access tokens used in supply-chain malware attack

The Open VSX registry rotated access tokens after they were accidentally leaked by developers in public repositories and...