#developer tools
14 stories taggeddeveloper tools.

AI Coding Tool Was Quietly Uploading Your Entire Codebase to China
Z.ai's ZCode assistant packaged developers' full project histories by default and sent them to Alibaba Cloud servers. The company has disabled the feature, deleted the stored data, and opened its source code for review.

DeepSeek's Coding Agent Could Switch Off Its Own Safety Cage
A flaw in DeepSeek Harness let an AI agent escape the sandbox meant to keep it away from the rest of a developer's computer.

Poisoned Git Configs Trick Claude, Codex and Cursor Into Running Attacker Code
Manifold Security found eight flaws in seven command-line AI coding assistants that let a booby-trapped repository run commands on a developer's machine without asking permission.

Amazon's Kiro AI Coding Tool Can Be Tricked Into Leaking Your Secrets
Researchers show how a hidden instruction in a project file can turn Amazon's agentic coding assistant into a data-exfiltration channel.

This Week's Security Grab Bag: AI Hijacks, Fake Fixes, and a Cursor Bug
A roundup week: nothing catastrophic on its own, but the patterns are the story.

Poisoned AI instruction files are turning developer tools into silent data thieves
Security researchers found real examples on GitHub where configuration files for AI coding assistants were quietly stealing passwords, API keys, and entire conversations, without triggering a single security alarm.

The Security Scanners Protecting Your Code Could Be the Way Hackers Get In
A researcher found that five unnamed security vendors' own scanning tools could be tricked into handing over cloud passwords, production databases, and developer credentials, just by feeding them a rigged code repository.

Two Clicks to Own a Developer's Machine: The Cursor AI Flaw You Should Know About
Researchers found they could smuggle a malicious installation command into the most popular AI code editor by hiding it inside what looked like a routine code-review link.

Cursor on Windows Runs Rogue git.exe From Any Opened Repo, No Warning
A flaw in the AI code editor lets a booby-trapped repository execute code on a developer's machine the moment the folder is opened.

Grok's Coding Assistant Was Quietly Shipping Whole Git Repos to xAI
A researcher caught version 0.2.93 of Grok Build uploading entire repositories, private history included, to a Google Cloud bucket run by xAI.

AI Coding Assistants Can Be Tricked Into Running the Very Malware They Were Asked to Find
A proof-of-concept from the AI Now Institute shows Claude Code and OpenAI's Codex executing attacker-supplied code when asked to review it in autonomous mode.

A trick in six AI coding helpers lets a poisoned project hijack your laptop
Researchers at Wiz found that popular AI coding assistants, including Amazon Q Developer and Claude Code, can be fooled into writing to sensitive files while asking permission for a harmless one.

Researchers Show AI Coding Agent 'Skills' Can Hide Malware From Every Scanner Tested
A Hong Kong team's packing trick beat static scanners more than 90% of the time. Their own runtime checker caught most of it.

Popular AI Coding Tool Cursor Has Flaws That Could Let Attackers Run Code on Your Computer
Security researchers found two vulnerabilities in the Cursor AI code editor that could allow an attacker to silently take control of a developer's machine, no click required.