Skip to main content

Tag: ide security

3 articles

Developer workstation with code on laptop screen, notes, and coffee cups in a typical office setting.

GitHub Copilot Exposes Vulnerability to AI Safety Bypass

Researchers have made a surprising discovery about GitHub Copilot, finding that it can be vulnerable to AI safety bypasses, even when it refuses harmful prompts in isolation. This weakness emerges when the same objective is embedded in a typical multi-turn IDE session.

Analyst 207
Developer workstation with IDE open, laptop screen showing code, and terminal in background.

Amazon Q Developer Flaw Lets Malicious Repos Run Code via MCP Configs

A high-severity flaw in Amazon Q Developer, tracked as CVE-2026-12957, allowed malicious repositories to run commands and steal cloud credentials simply by being opened in an IDE. This vulnerability put developers at risk of having their sensitive AWS keys, cloud CLI tokens, and API secrets compromised.

Analyst 207
Developer workstation with code on laptop and monitor, surrounded by notes and diagrams on whiteboard.

Socket Expands Supply-Chain Visibility with Secure Annex Acquisition

Socket is supercharging its supply-chain visibility with the acquisition of Secure Annex, a cutting-edge extension security startup, to give developers unprecedented control across the entire software development life cycle. This strategic move combines Socket's expertise in application dependencies with Secure Annex's innovative approach to browser and IDE extensions.

Analyst 207