Cisco open-sources Antares AI models for vulnerability detection
Cisco has released two open-weight security models designed to search software repositories for files linked to known vulnerability categories. Antares-350M and Antares-1B […]
models escaped via package proxy
Criminals did not run the autonomous agent that compromised Hugging Face’s production infrastructure last week. OpenAI disclosed on Tuesday that the campaign was driven […]
Hugging Face confirms AI agent breached production systems
Hugging Face confirmed attackers used an autonomous AI agent to breach its production infrastructure and steal cloud credentials. The platform, which hosts […]
SleeperGem RubyGems attack evades CI to hit developer laptops
Three malicious RubyGems packages published in July 2026 evaded CI detection by targeting developer laptops directly, researchers say. Security researchers at Aikido […]
White House launches AI clearinghouse for vulnerability patching
The White House has launched GOLD EAGLE, an AI clearinghouse to coordinate vulnerability patching across infrastructure sectors. The administration says it has […]
Fake GitHub repositories exploit developer trust to spread malware
A campaign involving at least 292 impersonation repositories shows that securing the software supply chain requires developers to verify where tools, binaries, […]
Four AsyncAPI npm packages carry Miasma botnet loader
Socket has identified a software supply chain attack involving compromised AsyncAPI npm packages distributing a Miasma botnet loader. According to the company’s […]
Why Enterprise Teams Are Moving Beyond Pure Headless to Hybrid CMS
Developer Tech’s own coverage of the CMS space has tracked this tension for a while without quite naming it. The site’s breakdown […]
Developers face RCE via Claude Code ‘auto-mode’ exploit
A newly-disclosed exploit in Claude Code’s ‘auto-mode’ leaves developers facing remote code execution (RCE) vulnerabilities during third-party library reviews. The AI Now […]
IBM Bob adds multi-agent AI and legacy modernisation tools
IBM has expanded its Bob software development platform with new multi-agent capabilities, built-in AI usage and cost analytics, and pre-built workflows for […]
IBM and Red Hat automate open-source vulnerability remediation
IBM and Red Hat have launched Lightwell to automate vulnerability remediation across enterprise open-source software deployments. The commercial release introduces Lightwell Network […]
PyPI and npm payment SDK malware compromises CI/CD
According to Socket, malicious payment SDK packages on npm and PyPI are harvesting developer credentials and CI/CD environment variables. Socket’s scanning infrastructure […]