Tag

#developer tools

12 stories taggeddeveloper tools.

Full-frame photoreal editorial shot of a developer workstation at night, two large monitors filled with code and a security dashboard showing red alert badges,
AI Security

Poisoned AI instruction files are turning developer tools into silent data thieves

Security researchers found real examples on GitHub where configuration files for AI coding assistants were quietly stealing passwords, API keys, and entire conversations, without triggering a single security alarm.

5 min read
Macro photograph of smooth river stones arranged in a row on a wooden surface, each stone casting a soft shadow, warm neutral tones, shallow depth of field, edi
Vulnerabilities

The Security Scanners Protecting Your Code Could Be the Way Hackers Get In

A researcher found that five unnamed security vendors' own scanning tools could be tricked into handing over cloud passwords, production databases, and developer credentials, just by feeding them a rigged code repository.

4 min read
Full-frame photoreal editorial shot of a modern developer workstation at dusk, two large monitors glowing with abstract code editor windows, a small permission
AI Security

Two Clicks to Own a Developer's Machine: The Cursor AI Flaw You Should Know About

Researchers found they could smuggle a malicious installation command into the most popular AI code editor by hiding it inside what looked like a routine code-review link.

3 min read
Photoreal editorial shot of a developer's dark home office desk at night, a laptop open showing an abstract code editor interface with warning-red highlights on
Vulnerabilities

Cursor on Windows Runs Rogue git.exe From Any Opened Repo, No Warning

A flaw in the AI code editor lets a booby-trapped repository execute code on a developer's machine the moment the folder is opened.

4 min read
Photoreal editorial shot of a developer's dimly lit desk at night, glowing terminal window on a laptop screen showing abstract lines of code, a subtle stream of
AI Security

Grok's Coding Assistant Was Quietly Shipping Whole Git Repos to xAI

A researcher caught version 0.2.93 of Grok Build uploading entire repositories, private history included, to a Google Cloud bucket run by xAI.

3 min read
Full-frame overhead shot of a developer's dark wooden desk, a laptop screen glowing with abstract lines of code, a small red warning icon reflected on the keybo
AI Security

AI Coding Assistants Can Be Tricked Into Running the Very Malware They Were Asked to Find

A proof-of-concept from the AI Now Institute shows Claude Code and OpenAI's Codex executing attacker-supplied code when asked to review it in autonomous mode.

3 min read
Full-frame photoreal editorial shot of a modern developer workstation at dusk, two large monitors glowing with abstract code editor windows, a small permission
AI Security

A trick in six AI coding helpers lets a poisoned project hijack your laptop

Researchers at Wiz found that popular AI coding assistants, including Amazon Q Developer and Claude Code, can be fooled into writing to sensitive files while asking permission for a harmless one.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of a modern developer workstation at dusk, two large monitors glowing with abstract code, a translucent s
AI Security

Researchers Show AI Coding Agent 'Skills' Can Hide Malware From Every Scanner Tested

A Hong Kong team's packing trick beat static scanners more than 90% of the time. Their own runtime checker caught most of it.

3 min read
A close-up top-down view of a mechanical keyboard on a dark desk, its keys softly lit by the cool blue glow of a monitor displaying abstract cascading lines of
Vulnerabilities

Popular AI Coding Tool Cursor Has Flaws That Could Let Attackers Run Code on Your Computer

Security researchers found two vulnerabilities in the Cursor AI code editor that could allow an attacker to silently take control of a developer's machine — no click required.

3 min read
AI Security

Poisoned Repos Can Trick Claude Code Into Opening a Reverse Shell

Researchers show that prompt injection hidden inside a repository's files is enough to turn Anthropic's agentic coding tool against the developer running it.

2 min read
AI Security

Agentjacking: Poisoned Sentry Error Reports Hijack AI Coding Assistants

Researchers describe a prompt-injection class that turns developer error-tracking pipelines into a remote code execution path against AI coding agents.

3 min read
Threat Intelligence

Microsoft Bakes a Two-Hour Quarantine Into VS Code Extension Auto-Updates

The delay is a soft tripwire against marketplace supply chain attacks — buying defenders a window to flag malicious updates before they propagate.

3 min read
© 2026 Threat Vectr