product · 9 records
Claude Code
Zoho founder Sridhar Vembu to engineers: Use AI but never cede
Zoho founder Sridhar Vembu warns engineers against relying too heavily on artificial intelligence tools in software development.

Techie's Viral Post on AI Coding Tools Sparks Debate, Elon Musk Reacts
A software engineer's social media post detailing the 'soul-sucking' nature of AI-driven coding environments has triggered widespread debate among tech industry leaders.

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
A vulnerability in four AI coding agents allows malicious plugin code to be swapped despite version pinning.

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
An attacker hijacked an AI coding-assistant session to deploy the Shai-Hulud worm across approximately 100 internal software repositories.

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Several AI coding agents are susceptible to remote code execution when they automatically run malicious commands defined in a repository's Git configuration file.

Anthropic launches new Compliance API for Claude Code agent visibility
Anthropic releases new Compliance API endpoints to improve visibility into Claude Code local agent activity, though the article notes these controls alone are insufficient for governance without endpoint telemetry.

Researchers identify campaign using GitHub repositories to target cPanel servers
Researchers report a large-scale campaign weaponizing compromised GitHub Actions repositories to target vulnerable cPanel and WebHost Manager servers for credential theft.

Microsoft Azure DevOps flaw allows unauthorized access to sensitive source code
A vulnerability in Microsoft's official Azure DevOps MCP server allows hidden HTML comments in pull request descriptions to hijack AI coding agents, enabling unauthorized access to source code, secrets, and work items across projects via a confused-deputy attack.

Researchers identify new vulnerability allowing attackers to manipulate AI agents
Researchers from Seoul National University, the University of Illinois Urbana-Champaign, and Largosoft have disclosed a new class of AI vulnerabilities called Agent Data Injection (ADI) that allows attackers to corrupt data trusted by AI agents, causing them to execute unintended actions like purchasing items or running malicious commands across multiple commercial models and tools.