Tag: programming
-
NIST Issues New Guidance to Protect SSO and API Tokens From Theft and Forgery
The National Institute of Standards and Technology (NIST) has published new implementation guidance to safeguard identity tokens, access tokens, and assertions used in single sign-on, cloud federation, and application programming interface (API) environments. Released on September 15, 2026, NIST Internal Report 8587, titled >>Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for…
-
Malicious actors already using critical GitLab flaw, CISA and others warn
The vulnerability could let unauthenticated users access sensitive files from software-development environments. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/gitlab-vulnerability-exploitation-cisa-kev/830278/
-
PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation.The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download.”These are Regular Maintenance Releases (MR) that First…
-
AI Agents Hijacked German Wiki to Cheat, OpenAI Delayed Disclosure
AI agents secretly took over a 25-year-old German wiki for two months to cheat on tests, and OpenAI sat on the news until reporters found it first OpenAI finally admitted this weekend that a swarm of its own AI agents hijacked a German programming wiki earlier this year, turning it into a private message board…
-
OpenAI’s German Wiki Hack Is Less About “Rogue AI” Than Failed Agent Containment
OpenAI’s latest foul-up was not a Hollywood-style AI “escape.” Instead, researchers say a swarm of OpenAI agents apparently found a way to turn web read access into write access on DseWiki, a collaboratively editable German programming wiki. The takeover of a German programming wiki, DseWiki, by agents linked to OpenAI is not evidence that AI..…
-
Download: The Agentic Software Development Guide
AI makes it easy to ship more code. It does not make that code easier to trust. Most teams don’t fail because their developers can’t use AI. They fail because the dev’s job … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/02/download-the-agentic-software-development-guide/
-
The Toolchain Is the Target: Securing Software Development in the Agentic Era
JFrog finds AI development tools are expanding the software supply chain and creating new attack paths for organizations. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/the-toolchain-is-the-target-securing-software-development-in-the-agentic-era/
-
Your Coding Assistant Is Shipping Security Vulnerabilities
Tags: access, ai, api, application-security, authentication, compliance, credentials, email, endpoint, framework, github, governance, LLM, programming, risk, service, tool, vulnerabilityYour Coding Assistant Is Shipping Security Vulnerabilities. Here’s How to Fix That. AI coding assistants have gotten remarkably good at writing functional code. Syntax correctness rates are approaching 100%. Developers are more productive than ever. And yet the security picture tells a very different story. Veracode recently evaluated over 150 large language models across vendors…
-
What Is MCP in Software Development and Why Does It Matter
What MCP is in software development, how it connects AI models to tools and data, and why it matters for building scalable AI-powered applications. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/what-is-mcp-in-software-development-and-why-does-it-matter/
-
Using OWASP SAMM to measure secure development maturity
For many UK SMEs, secure development starts with a familiar pattern: a few coding standards, some security testing, and perhaps a checklist for releases. That is a useful foundation, but it does not tell you whether your software development capability is improving in a structured way. This is where OWASP SAMM, the Software Assurance Maturity……
-
From Traditional Development to AI-Native Engineering: ISHIR’s AI Software Engineering Maturity Spectrum
Software development is going through a more fundamental change than adding another productivity tool to the developer stack. The question for CEOs, CIOs, CTOs, and…Read More First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2026/08/from-traditional-development-to-ai-native-engineering-ishirs-ai-software-engineering-maturity-spectrum/
-
TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore
Tags: attack, cybersecurity, exploit, flaw, kaspersky, programming, russia, software, threat, vulnerabilityThe threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors.Russian cybersecurity vendor Kaspersky said it detected the attacks in July 2026.The activity involves exploiting a vulnerability chain First seen on thehackernews.com…
-
Secure design reviews and architecture checkpoints in the SDLC
Secure design reviews and architecture checkpoints in the SDLC For many UK SMEs, security work becomes most effective when it is built into the way software is designed and delivered, rather than added at the end. A secure design review is one of the most useful points in the software development lifecycle (SDLC) to catch……
-
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer’s computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it.A third flaw could expose sensitive data and control-plane details through application programming…
-
Defining Community Open Source Is Harder Than It Looks
<div cla Exemptions sound relatively simple until you try to make them fair. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/07/defining-community-open-source-is-harder-than-it-looks/
-
Apiiro CEO: Coding Agents Are the New Enterprise Perimeter
Idan Plotnik: AI Development Tools Have Become Enterprises’ Newest Attack Surface. Apiiro CEO Idan Plotnik says AI coding agents have become the enterprise’s newest security perimeter, prompting organizations to shift from application security posture management to automated protection as AI accelerates both software development and vulnerability exploitation. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/apiiro-ceo-coding-agents-are-new-enterprise-perimeter-a-32314
-
Anthropic Launches Claude Security Plugin to Scan Codebases for Vulnerabilities Before Commit
Anthropic has launched the Claude Security plugin for Claude Code in beta, enhancing its AI-assisted development platform with security scanning capabilities designed to identify vulnerabilities earlier in the software development lifecycle. The company stated that developers can scan code changes before committing them or initiate comprehensive security reviews across an entire codebase directly from the…
-
Malware is targeting AI tools in software development environments
The worm blends in with thousands of other commands occurring daily in any given environment, yet its intent and origins remain unknown. First seen on cyberscoop.com Jump to article: cyberscoop.com/sandworm-mode-malware-ai-supply-chain-crowdstrike/
-
Critical JetBrains Flaws Impact IntelliJ IDEA, TeamCity, and YouTrack Users
JetBrains has released security updates for IntelliJ IDEA, TeamCity, and YouTrack that address six vulnerabilities, including a critical path traversal issue that could enable code execution in IntelliJ IDEA. The fixes affect core developer tooling, CI/CD infrastructure, and issue-tracking environments, making prompt patching important for organizations that use JetBrains products in software development workflows. The…
-
Why programming true randomness in emulators is a developer worst nightmare
Asking a deterministic machine to behave indeterministically is the cleanest paradox in software engineering, and emulator developers live inside it every working day. The job description sounds reasonable until you read it twice: recreate, with mathematical precision, a piece of silicon that was never mathematically precise to begin with, reproducing on commodity hardware the analog…
-
GitHub Copilot IDE Coding Agents Vulnerable to Workflow-Level Jailbreak Attacks
GitHub Copilot’s new coding agents, which are integrated into IDEs, are susceptible to a specific type of >>workflow-level<< jailbreak attacks. These attacks can bypass chat refusals, allowing agents to generate harmful code while performing standard software development tasks unwittingly. According to Arxiv, researchers who studied Copilot in Visual Studio Code discovered that models that successfully…
-
Software Is Now Written at the Speed of Thought. Security Isn’t.
Every evolution in software development has reduced the friction between an idea and a deployable application. AI may remove the final barrier, but it also removes many of the moments where security decisions have traditionally taken place. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/software-is-now-written-at-the-speed-of-thought-security-isnt/
-
Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique
Tags: ai, attack, chatgpt, cybercrime, LLM, malicious, malware, programming, ransomware, software, toolesearch by:Alexey Bukhteyev Key Takeaways Introduction Over the past several years, large language models have reshaped software development, and malware development has followed the same path. Check Point Research has documented this trend from early experiments showing that AI systems could generate offensive components, to cases of cybercriminals using ChatGPT to create malicious tools, and…
-
Mystery hackers use novel SharkLoader dropper against governments, software devs
Kaspersky researchers have uncovered a previously unknown cyberattack campaign that has compromised government organizations and software development companies in multiple … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/26/sharkloader-dropper-governments-software-developers/
-
Fable 5 AI Model Builds Bootable Windows Kernel in Rust in Just 38 Minutes
A newly released AI model, Claude Fable 5, has made a significant advancement in autonomous systems programming by generating a bootable Windows NT-style kernel in Rust in just 38 minutes. The project, titled ntoskrnl-rs, began as an empty repository and evolved into a functioning x86_64 kernel that boots in QEMU and passes all internal self-tests.…
-
LG and Samsung Smart TV Apps Found Monetizing Users’ IP Addresses via Proxy SDKs
A large-scale analysis of smart TV applications has revealed that thousands of apps available on LG webOS and Samsung Tizen platforms are covertly transforming consumer devices into residential proxy nodes, raising significant security and privacy concerns. Researchers scanned 6,038 smart TV applications and identified 2,058 apps that embed proxy software development kits, monetizing users’ internet…
-
Over 2,000 LG and Samsung Smart TV Apps Found Running Residential Proxy SDKs
A large-scale analysis of smart TV applications has revealed that thousands of apps available on LG webOS and Samsung Tizen platforms are covertly transforming consumer devices into residential proxy nodes, raising significant security and privacy concerns. Researchers scanned 6,038 smart TV applications and identified 2,058 apps that embed proxy software development kits, monetizing users’ internet…
-
Novo Nordisk Breach Highlights Software Development Pipeline Risk
A leaked GitHub token underscores what most organizations get wrong: Treating secrets management as a tooling problem rather than an identity problem. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/novo-nordisk-breach-exposes-dev-pipeline-risk
-
Novo Nordisk Breach Highlights Software Development Pipeline Risk
A leaked GitHub token underscores what most organizations get wrong: Treating secrets management as a tooling problem rather than an identity problem. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/novo-nordisk-breach-exposes-dev-pipeline-risk
-
Novo Nordisk Breach Exposes Software Development Pipeline Risk
A leaked GitHub token underscores what most organizations get wrong: Treating secrets management as a tooling problem rather than an identity problem. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/novo-nordisk-breach-exposes-dev-pipeline-risk

