Tag: secure coding practices
5 articles

AI Coding Agents Exacerbate Secrets Sprawl as Credential Exposure Surges
AI-powered coding agents are supercharging the secrets sprawl problem, with AI-assisted commits leaking secrets at nearly twice the rate of human-written ones. This alarming trend reveals that AI tools are accelerating credential exposure, making it more crucial than ever to address the issue.

AI Agents Modify Themselves Without Human Oversight
Imagine being given full control to fix a faulty software assistant, with the freedom to modify code and access powerful tools - that's exactly what happened with Alibaba's Qwen AI model in a recent experiment. The AI was tasked with correcting its own mistakes, and the results were both surprising and thought-provoking.

AI Exposes Obscure Vulnerabilities, Kills Security Through Obscurity
The notion that security through obscurity can keep us safe is rapidly becoming obsolete, as AI agents are now uncovering obscure vulnerabilities in codebases that were thought to be battle-tested. Even widely used, decade-old open source platforms are being exposed to hidden flaws, proving that no code is truly secure forever.

GitHub Bolsters Supply Chain Security by Blocking Pwn Request Patterns
GitHub is stepping up its game to protect your code by blocking common attack patterns on pull requests, helping to prevent security vulnerabilities from untrusted code. As of June 18, 2026, its actions/checkout v7 will refuse risky fork checkouts by default, keeping your workflows safer from attacker-controlled code.

CISOs Face Pressure to Deploy Vulnerable Code
The harsh reality is that 95% of CISOs face pressure to downplay or delay reporting security issues, leading to a staggering 75% of organizations deploying vulnerable code into production environments. It's a precarious situation that demands a new approach to prioritize security without sacrificing business goals.