Tag

#developer-security

22 stories taggeddeveloper-security · page 2 of 2.

Full-frame overhead view of a cluttered developer's desk at night, glowing keyboard, open laptop showing abstract package manager output as coloured bars, small
Threat Intelligence

North Korean hackers flood open-source repositories with 108 booby-trapped packages

The Contagious Interview crew is back, seeding npm, Packagist, Go and Chrome with malware aimed at developers.

3 min read
Photoreal news-editorial photograph, 16:9 framing, top-down overhead view of a modern developer workstation with a dark mechanical keyboard and a large monitor
AI Security

An AI Coding Tool Built Into Millions of Developer Setups Had a Flaw That Could Hand Hackers Your Cloud Keys

A security hole in Amazon's AI coding assistant let criminals steal cloud credentials just by getting a developer to open a poisoned folder. It's patched, but the attack method is spreading.

3 min read
Macro photograph of a glowing computer terminal screen in a dark room displaying cascading green lines of code and error log text, with a single line subtly hig
AI Security

A Fake Error Message Hijacked AI Coding Assistants — and Security Tools Saw Nothing

Researchers planted a single bogus bug report in a popular developer service and watched AI coding agents obediently run the attackers' code. No password stolen. No alarm raised.

3 min read
AI Security

Prompt Injection in Git Repos Can Turn Claude Code Into a Reverse Shell Launcher

Malicious instructions buried in a repository's files can hijack Anthropic's Claude Code agent and open a backdoor on the developer's own machine, no obvious malware required.

3 min read
Identity & Access

Robinhood Rebuilt Its Access-Approval Pipeline — Here's What Actually Changed

The fintech firm's engineering-security team overhauled how developers request and receive system access. The goal: speed without sacrificing control.

2 min read
Threat Intelligence

Miasma Self-Replicating Worm Reaches Microsoft GitHub Orgs, 73 Repos Affected

The campaign tracked publicly as Miasma propagated into Azure, Azure-Samples, Microsoft, and MicrosoftDocs before GitHub pulled access.

3 min read
AI Security

French Startup Edamame Builds Runtime Watch for AI Coding Agents

The platform uses host telemetry and AI analysis to flag intent drift, secret theft, and supply-chain interference in real time, before the damage lands.

3 min read
© 2026 Threat Vectr