Skip to main content

Tag: software development

144 articles

Cluttered developer workstation with code on laptop, notes, and documentation in a naturally lit office setting.

AI Coding Tools Exacerbate Open-Source Remediation Debt

AI coding tools are speeding up development, but at a hidden cost: they can quickly introduce a flood of new open-source components that security teams struggle to keep up with, multiplying remediation debt. This creates a downstream cycle of vulnerability assessments, licensing checks, and ownership questions that can be overwhelming.

Analyst 207
Software development team collaborating in a modern, open-plan office space with laptops and monitors.

AI-Driven Development Exposes Surge in Enterprise App Vulnerabilities

The rapid adoption of AI-driven software development has led to a staggering fivefold increase in application creation, but also a shocking 4.31 times more critical and high-severity vulnerabilities in enterprise apps. This surge in vulnerabilities outpaces the speed of fixes, posing a growing risk to businesses.

Analyst 207
Developers gather around a large screen in a bright, open workspace surrounded by laptops and coding gear.

GitLab Patches Flaw That Exposes Public Projects to Unauthenticated Deletion

GitLab has urgently patched a critical vulnerability that left public projects open to deletion by anyone, with no login required - a flaw that scored a near-perfect 9.4 on the severity scale. The fix addresses a GraphQL weakness that could let unauthenticated users remotely modify or delete public projects and user data.

Analyst 207
Laptop screen on a desk with a blurred background, surrounded by a smartphone and notebook.

AI Watermark Removers Proliferate, Claims Outpace Proof

The AI watermark remover scene is exploding, with a GitHub project racking up over 4,500 stars and claims of imperceptible mark removal flying fast and furious. Just days after Anthropic introduced hidden marks in its Claude writes, a tool from Guillaume Meyer emerged, now supporting watermarks from top AI players like OpenAI and Gemini.

Analyst 207
Laptop screen in a Mozilla office shows a blurred GitHub repository page with a private key representation.

Mozilla Revokes Firefox Signing Key After GitHub Exposure

Mozilla sprang into action after discovering a sensitive Firefox signing key had been mistakenly uploaded to a private GitHub repository, revoking the exposed key and implementing extra safeguards to prevent future mishaps. Fortunately, the company found no evidence that the key was compromised during its brief online exposure.

Analyst 207
Researcher looks concerned while examining laptop screen amidst coding tools and notes.

Researchers Warn of Security Gaps in AI Coding Tools

Researchers analyzed 1.1 million Reddit posts to uncover alarming security gaps in AI coding tools, revealing that developers are frequently complaining about security and privacy lapses. These flaws are leaving the door open for potential threats, putting users at risk.

Analyst 207
Developer workstation with laptop and monitor on a clean desk, code editor open on screen.

Open VSX Eradicates Malicious Extensions Exfiltrating Developer Data

A shocking discovery by Manifold Security revealed that 77 malicious extensions on Open VSX were secretly siphoning off sensitive data from developers' machines between July 26 and August 1, 2026. These fake extensions, masquerading as legitimate tools, were swiftly removed by Open VSX on August 3, 2026.

Analyst 207
Security researcher analyzing code in a cluttered office with city view.

Closed AI models hinder Linux bug research

Closed AI models are causing frustration for Linux bug researchers, with one expert likening them to a roadblock in the investigation process. Daniel Fox Franke, a principal security researcher, recently encountered repeated automated refusals while trying to track down a segmentation fault in ripgrep.

Analyst 207
Software development workspace with laptop, notebook, and papers on a desk in front of a blurred coding environment and a…

GitHub Targets Supply Chain Attacks with Dependabot Cooldown

GitHub's new Dependabot cooldown feature gives you a security boost by waiting at least three days after a release is published before updating dependencies, helping to prevent rapid adoption of malicious package releases. This brief pause allows time to catch poisoned or trojanized packages, keeping your projects safer.

Analyst 207
Developer workstation with laptop and notes in a bright, daytime office environment.

GitHub, PyPI Fortify Defenses Against Supply Chain Attacks

GitHub and PyPI are stepping up their game to shield against supply chain attacks, introducing time-based gates to slow down the release of potentially risky package updates. GitHub's Dependabot now delays updates for 72 hours, while PyPI will reject new files added to releases over 14 days old.

Analyst 207
A developer's clutter-free workstation with laptop, notebook, and coffee cup, set against a blurred background with a hint…

npm Package Infects Developers with Cryptocurrency Wallet Stealer

A malicious npm package, downloaded a staggering 50,000 times weekly, was briefly infected with code that stole cryptocurrency wallet private keys and sensitive seed phrases, putting countless developers at risk. The attack was launched after a contributor's GitHub account was compromised, allowing the hackers to spread the poisoned code across multiple projects.

Analyst 207
Developer workstation with laptop and notes, package manager interface on screen.

GitHub npm Tightens Security With Disabled Install Scripts

GitHub's latest npm update takes a giant leap in security by disabling install scripts by default, reducing supply-chain risks and giving developers more control. To adapt, plan to switch to trusted publishing or staged publishing with human approval for automated publishing.

Analyst 207
Person typing on laptop keyboard with blurred screen and natural light from a large window in the background.

GitHub Verified Commits Can Be Rewritten Without Breaking Signatures

A recent study revealed a surprising vulnerability in GitHub's verified commits, showing that signed commits can be rewritten without breaking their digital signatures. This means that tampered code can still be labeled as Verified, posing a significant risk to code security.

Analyst 207
Developer working at a desk with computer, keyboard, and coffee cup.

Developers Weaponize Code to Disrupt AI-Powered Malware

Meet Johannes Link, a self-proclaimed AI skeptic who's taking a stand against AI-powered coding agents by weaponizing his own code - specifically, the Java property-testing tool jqwik - to disrupt their operations. His latest software update includes a clever anti-AI clause designed to throw a wrench in the works.

Analyst 207
A clean and organized technology workspace with a laptop and development tools on a desk.

GitHub Disrupts Supply Chain Attacks by Blocking npm Install Scripts

GitHub is taking a bold step to safeguard the npm ecosystem by blocking install scripts from running by default, tackling the single largest code-execution surface in the ecosystem. This move, part of npm 12's release, aims to prevent supply chain attacks by requiring explicit permission for scripts to run.

Analyst 207
Software engineer working with AI coding tools at a desk with multiple laptops and notes.

AI Coding Adoption Outpaces Governance, Raises Security Risks

The rapid adoption of AI coding tools has outpaced governance, with 97% of teams using AI assistants, but only 30% having a fully governed approach to oversight, leaving a significant security risk gap. This disconnect raises concerns about where risks are accumulating and how work is getting done.

Analyst 207
CISO or developer surrounded by screens and code, showing concern and frustration in a dimly lit office with blurred…

CISOs Face Pressure to Deploy Vulnerable Code

The harsh reality is that 95% of CISOs face pressure to downplay or delay reporting security issues, leading to a staggering 75% of organizations deploying vulnerable code into production environments. It's a precarious situation that demands a new approach to prioritize security without sacrificing business goals.

Analyst 207
Cluttered developer's workstation with coding interface on screen.

Malicious NuGet Package Exfiltrates Sicoob Banking Credentials

A malicious NuGet package, masquerading as a C# SDK for a major Brazilian financial system, was designed to steal sensitive banking credentials, including client IDs, PFX passwords, and certificate bytes, from unsuspecting developers. This rogue package, downloaded nearly 500 times, put automation and security at risk.

Analyst 207
Ruggedized laptop on a ship's command center console, surrounded by navigation and communication equipment.

US Navy Rethinks Risk in Software Development for Edge Operations

The Department of the Navy is shaking up its approach to software development, redefining risk to deliver mission-critical data at breakneck speeds. By recalibrating its tolerance for risk, the Navy aims to accelerate the flow of vital information to where it's needed most, when it's needed most.

Analyst 207
Developer interacts with laptop in bright office, emphasizing secure package management.

GitHub Enhances npm with 2FA-Gated Publishing to Thwart Supply Chain Attacks

GitHub's new staged publishing feature on npm adds an extra layer of security, requiring maintainers to approve package releases after completing a two-factor authentication challenge, effectively preventing unauthorized publishes and reducing the risk of supply chain attacks. This human gate ensures proof of presence for every package release, safeguarding the integrity of the npm ecosystem.

Analyst 207
Developer workstation with VS Code on laptop and monitor, subtle security threat hinted in background.

GitHub Breach Exposes 3800 Repositories via Poisoned VS Code Extension

A malicious Visual Studio Code extension, Nx Console, was briefly listed on official registries and used to breach GitHub, exposing approximately 3,800 internal repositories to unauthorized access. The popular extension, with 2.2 million installs, was compromised for just 18 minutes, but long enough to cause significant damage.

Analyst 207
Blurred developer workstation with laptop, smartphone, and tablet nearby.

GitHub Breach Exposes 3,800 Repos to TanStack Supply-Chain Attack

A single malicious Visual Studio Code extension, Nx Console version 18.95.0, was enough to spark a GitHub breach that exposed 3,800 internal repositories to a TanStack supply-chain attack. The poisoned extension was live on marketplaces for just 54 minutes, but long enough to steal credentials from a developer's machine.

Analyst 207
Brightly-lit tech workspace with rows of workstations and a few developers in the background.

GitHub Breach Exposes Internal Repositories

GitHub has confirmed a cyber incident that exposed its internal repositories, sparking concerns about the security of code and sensitive data. The breach raises questions about the potential impact on users and the measures being taken to prevent future incidents.

Analyst 207
Blurred office scene with employees working, a faintly glowing laptop in the foreground.

GitHub Probes Internal Breach Claimed by TeamPCP Hackers

GitHub is investigating a possible internal breach after a hacking group claimed unauthorized access to its repositories. The company says it has no evidence that customer data has been compromised so far.

Analyst 207