#developer-security
31 stories taggeddeveloper-security.

UK Government Tests Found AI Models Creating Fake Identities and Attempting to Break Into GitHub
Britain's AI safety watchdog caught two artificial intelligence systems going rogue during routine testing, with one building fake online profiles to trick real software developers.

77 fake developer tools on Open VSX quietly mapped coders' machines for a week
The counterfeit extensions copied real names from AMD, Azure, Salesforce and others, then phoned home to a domain registered days earlier.

Five Major AI Coding Tools Keep Inventing the Same Fake Software Packages
A researcher found 127 made-up package names shared across ChatGPT, Claude, Gemini, and DeepSeek, and 53 of those names are still free for criminals to register today.

AI Coding Assistants Can Slip Past Their Own Security Cages Without Breaking Them
New research from Pillar Security shows that the sandboxes meant to contain AI coding agents have a fundamental blind spot: the agent never needs to escape if it can simply hand a poisoned file to something that already has permission to run it.

SleeperGem: Three Booby-Trapped Ruby Packages Slip Onto RubyGems
Researchers say the malicious gems sat quietly on the official Ruby package registry, waiting to pull down further attacker code onto developer laptops.

Two Popular Coding Tools Poisoned With Malware in Back-to-Back Supply Chain Attacks
Criminals hijacked developer credentials to slip malicious code into widely used JavaScript packages, putting any computer that installed them at serious risk.

Popular AI Code Editor Cursor Has an Unpatched Flaw That Runs Malicious Files Automatically
A security firm disclosed the bug seven months ago. Cursor has still not patched it, leaving more than seven million developers exposed.

Popular AI Coding Tool Cursor Runs Malicious Files Automatically, Researcher Warns
A security firm reported the flaw seven months ago. Cursor has yet to patch it.

Poisoned Developer Tool Downloaded Nearly 1,500 Times Before Anyone Noticed
Criminals hijacked the publishing credentials for a widely used JavaScript security package and slipped malware into four releases over a single weekend. Developers who installed any of those versions may have handed over passwords, crypto-wallet keys, and cloud access tokens without knowing it.

The Hidden Cost of AI Coding Tools: Security Gaps, Leaked Secrets, and a Bill That Keeps Growing
Businesses are rushing to adopt AI coding assistants, but new research shows the tools leak sensitive credentials at twice the normal rate, routinely produce flawed code, and may cost more than a developer's salary within three years.

HalluSquatting: How AI Hallucinations Are Being Turned Into a Doorway for Malware
Security researchers have found a way to turn a known quirk of AI chatbots into a method for delivering malicious software directly to developers' computers, without hacking the AI itself.

AI Coding Assistants Fooled by Decades-Old File Trick to Attack Developer Machines
A technique as old as Unix itself let researchers plant hidden traps inside innocent-looking code projects, then watch AI tools quietly rewrite the wrong files while developers clicked 'approve'.

Criminals Are Using GitHub's Own Public Tools to Map Your Company Before They Strike
Researchers at Datadog tracked months of quiet, automated snooping across GitHub that blends perfectly into normal traffic, and most organisations never notice it happening.

HalluSquatting: When AI Coding Helpers Invent Fake Software, Criminals Register It First
Researchers show how attackers can predict the fake package names AI assistants make up, then publish real malware under those names, waiting for developers to install the trap.

Researchers Show How a Fake GitHub Comment Can Trick AI Tools Into Leaking Secret Code
A crafted public comment on GitHub can manipulate AI-powered automation into handing over data from private repositories, no password required.