developer-tools
44 articles with this tag
HIGH
INFO
MEDIUM
HIGH
INFO
MEDIUM
CRITICAL
INFO
HIGH
INFO
MEDIUM
INFO
HIGH
CRITICAL
MEDIUM
INFO
HIGH
INFO
HIGH
INFO
INFO
HIGH
HIGH
HIGH
INFO
CRITICAL
INFO
INFO
HIGH
HIGH
HIGH
HIGH
LOW
HIGH
INFO
INFO
INFO
MEDIUM
CRITICAL
HIGH
INFO
HIGH
INFO
INFO
NCSC-2026-0351 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Developer Tools
YOLO Mode: Agent Autonomy Without the Guardrails
NCSC-2026-0285 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Developer Tools
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default
77 malicious extensions found on Open VSX marketplace
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
Google gives developers an AI bug hunter that also writes patches
Unpatched Cursor Vulnerability Exposes Users to Code Execution
Rust-proof your code with our new Testing Handbook chapter
AI coding tool hole illustrates a big problem with human in the loop
WSL containers now build and run Linux workloads on Windows
Supply chain analysis: Kickbacks.ai VS Code extension. Empty pubkey, CSP relaxation, 90-second unsigned self-update, 60-second reassertion loop
Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT
Open-source CI/CD abuse detector guards against stolen credential attacks
AI is code – and can't be prompted into being smarter
Cybercriminals Use Fake AI Guides and Dev Tools to Spread AsyncRAT Malware
RHSA-2026:25089: Important: HawtIO 4.4.0 for Red Hat build of Apache Camel 4 Release and security update.
Claude Code has an MCP security problem — and your developers are already using it
Microsoft's Coreutils project brings Linux commands to Windows
From Kubernetes Dashboard to Headlamp: Understanding the Transition
Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries
TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO
Laravel Lang packages hijacked to deploy credential-stealing malware
Securing The AI Revolution How Snyk And Our Partners Are Scaling For The Future
GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension
Warp open sources its AI terminal client
Visual Studio Code 1.118 adds auto model selection to Copilot CLI
SAP npm package attack highlights risks in developer tools and CI/CD pipelines
Malicious pgserve, automagik developer tools found in npm registry
Another npm supply chain worm is tearing through dev environments
NCSC-2026-0114 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Developer tools
Android developers just got a new verification layer
An AI gateway designed to steal your data
How Ceros Gives Security Teams Visibility and Control in Claude Code
Backslash adds cross-product support to secure AI skills in developer environments
Java 26 released
Open VSX extensions hijacked: GlassWorm malware spreads via dependency abuse
GlassWorm Supply-Chain Attack Abuses 72 Open VSX Extensions to Target Developers
Fake Claude Code Install Guides Spread Amatera Infostealer in New “InstallFix” Malvertising Campaign
Apple Xcode 26.3 adds coding agent support from OpenAI and Anthropic
GlassWorm Malware Returns to Shatter Developer Ecosystems
OpenAI releases Codex macOS app for agent-based software development
Building vertical microfrontends on Cloudflare’s platform