Security researchers at Tenet Security showed that a public Sentry credential is enough to inject malicious instructions into AI coding agents. Claude Code, Cursor, and Codex all fell for it with an 85% success rate.
Two Copilot CLI updates from this week: a new /settings command that consolidates scattered configuration options into one place, and a /security-review slash command now in public preview that runs a security scan on your code changes from the terminal.
Claude Code 2.1.166, released June 6, lets you define up to three fallback models for when your primary is overloaded, adds glob support to deny rules, and hardens cross-session messaging security.
Claude Code's June 2 release adds security prompts before the agent writes to shell startup files or build-tool configs that grant code execution, renames the dynamic workflow trigger to 'ultracode', and clears a stack of Windows and session bugs.
Version 1.0.51 of the GitHub Copilot CLI adds session resumption with a --session-id flag, an experimental /security-review command for scanning code changes, and extended secret scanning into commit messages and PR descriptions.
A trojanized Nx Console extension was live on the VS Code Marketplace for 11 minutes on May 18. It stole GitHub tokens, AWS keys, npm credentials, 1Password vaults, and Claude Code configuration files from over 6,000 developer machines.
Gemini CLI v0.41.0 shipped on May 5 with a /voice command for real-time spoken interaction, experimental Gemma 4 support, mandatory workspace trust in headless environments, and over 40 bug fixes.
Snyk integrated Anthropic's Claude models into its AI Security Platform on May 8, using Claude to power vulnerability discovery, automated remediation, and a new product that red-teams AI agents for prompt injection and data exfiltration.
Novee researchers disclosed a high-severity RCE vulnerability in Cursor IDE on April 28. A crafted Git repository with a hidden pre-commit hook can trigger arbitrary code execution when Cursor's AI agent runs routine git operations. Cursor patched it in February 2026.
Cursor Security Review enters beta on Teams and Enterprise plans with two always-on agents: a Security Reviewer that comments on every PR, and a Vulnerability Scanner that runs scheduled codebase sweeps.
Security researcher Aonan Guan found that AI agents running in GitHub Actions can be compromised by injecting malicious instructions into PR titles, issue bodies, and comments. All three vendors paid bug bounties but assigned no CVEs and published no advisories.
A 59.8 MB source map file shipped in the npm package exposed 512,000 lines of Claude Code's TypeScript source. The findings include hidden agents, anti-distillation defenses, an AI pet system, and an undercover mode for Anthropic employees.
On February 20, Anthropic announced Claude Code Security had found over 500 previously unknown vulnerabilities in open-source codebases. CrowdStrike, Cloudflare, and others dropped by up to 9%. Here's what happened and what it means.
ESC
Start typing to search across tools, news articles, and reviews
No results found
Optional analytics and social embeds help us improve the site. It works fully without them.
Privacy
Privacy Settings
Choose which optional features you want to enable.
Your browser sent a global privacy opt-out signal. We respect that by default.