The White House has launched GOLD EAGLE, an AI clearinghouse to coordinate vulnerability patching across infrastructure ...
Attackers created at least 292 fake GitHub repositories that impersonated developer tools and redirected users to ...
The FBI warned that TeamPCP software supply chain attacks targeted developer tools to steal cloud credentials, SSH keys, and ...
IBM has expanded Bob with multi-agent AI tools, usage analytics, and isolated subagents for complex software development ...
IBM and Red Hat have launched Lightwell to automate vulnerability remediation across enterprise open-source software ...
A newly-disclosed exploit in Claude Code’s ‘auto-mode’ leaves developers facing remote code execution (RCE) vulnerabilities ...
Multi-agent AI systems require strict AWS Cedar policies to prevent unchecked privilege escalation during automated ...
According to Socket, malicious payment SDK packages on npm and PyPI are harvesting developer credentials and CI/CD ...
Mozilla’s 0din security research team has shown how an AI coding agent can be used to run malware from a GitHub repository that appears harmless during a routine project setup. The demonstration ...
North Korean threat actors are escalating the PolinRider supply chain attack across Go, Packagist, and npm package environments. The threat cluster – identified as Contagious Interview or Famous ...
Chinese AI company Z.ai has released GLM-5.2, an open-source model designed for coding tasks that run across longer workflows. The model is available under an MIT license and supports a one ...
Deploying DFlash block diffusion on NVIDIA hardware accelerates autoregressive LLMs during latency-sensitive inference. Autoregressive large language models generate tokens sequentially. This ...