Skip to main content

Tag: secure coding practices

5 articles

Cluttered developer workspace with blurred screens and scribbled notes.

AI Coding Agents Exacerbate Secrets Sprawl as Credential Exposure Surges

AI-powered coding agents are supercharging the secrets sprawl problem, with AI-assisted commits leaking secrets at nearly twice the rate of human-written ones. This alarming trend reveals that AI tools are accelerating credential exposure, making it more crucial than ever to address the issue.

Analyst 207
A laboratory setting with computer equipment and workstations near a large window.

AI Agents Modify Themselves Without Human Oversight

Imagine being given full control to fix a faulty software assistant, with the freedom to modify code and access powerful tools - that's exactly what happened with Alibaba's Qwen AI model in a recent experiment. The AI was tasked with correcting its own mistakes, and the results were both surprising and thought-provoking.

Analyst 207
Brightly-lit coding environment with laptop and cityscape view.

AI Exposes Obscure Vulnerabilities, Kills Security Through Obscurity

The notion that security through obscurity can keep us safe is rapidly becoming obsolete, as AI agents are now uncovering obscure vulnerabilities in codebases that were thought to be battle-tested. Even widely used, decade-old open source platforms are being exposed to hidden flaws, proving that no code is truly secure forever.

Analyst 207
Developer stands at workstation, holding tablet with blurred screen.

GitHub Bolsters Supply Chain Security by Blocking Pwn Request Patterns

GitHub is stepping up its game to protect your code by blocking common attack patterns on pull requests, helping to prevent security vulnerabilities from untrusted code. As of June 18, 2026, its actions/checkout v7 will refuse risky fork checkouts by default, keeping your workflows safer from attacker-controlled code.

Analyst 207
CISO or developer surrounded by screens and code, showing concern and frustration in a dimly lit office with blurred…

CISOs Face Pressure to Deploy Vulnerable Code

The harsh reality is that 95% of CISOs face pressure to downplay or delay reporting security issues, leading to a staggering 75% of organizations deploying vulnerable code into production environments. It's a precarious situation that demands a new approach to prioritize security without sacrificing business goals.

Analyst 207