Four AsyncAPI npm packages carry Miasma botnet loader
Socket has identified a software supply chain attack involving compromised AsyncAPI npm packages distributing a Miasma botnet loader. According to the company’s […]
Why Enterprise Teams Are Moving Beyond Pure Headless to Hybrid CMS
Developer Tech’s own coverage of the CMS space has tracked this tension for a while without quite naming it. The site’s breakdown […]
Developers face RCE via Claude Code ‘auto-mode’ exploit
A newly-disclosed exploit in Claude Code’s ‘auto-mode’ leaves developers facing remote code execution (RCE) vulnerabilities during third-party library reviews. The AI Now […]
IBM Bob adds multi-agent AI and legacy modernisation tools
IBM has expanded its Bob software development platform with new multi-agent capabilities, built-in AI usage and cost analytics, and pre-built workflows for […]
IBM and Red Hat automate open-source vulnerability remediation
IBM and Red Hat have launched Lightwell to automate vulnerability remediation across enterprise open-source software deployments. The commercial release introduces Lightwell Network […]
PyPI and npm payment SDK malware compromises CI/CD
According to Socket, malicious payment SDK packages on npm and PyPI are harvesting developer credentials and CI/CD environment variables. Socket’s scanning infrastructure […]
Securing multi-agent AI systems with AWS Cedar policies
Multi-agent AI systems require strict AWS Cedar policies to prevent unchecked privilege escalation during automated delegation. Software engineers deploying multi-agent AI architectures […]
Microsoft finds costs multiply during some AI model upgrades
Microsoft has found that developers upgrading to some new AI models face unpredictable token consumption and escalating costs. The company recently evaluated […]
FBI warns developers over TeamPCP software supply chain attacks
The Federal Bureau of Investigation has warned that TeamPCP carried out software supply chain attacks targeting developer and security tools used in […]
How AI Is Changing Automated Code Review Workflows
Automated code reviews powered by AI are streamlining software engineering processes, offering practical benefits while introducing new technical and ethical challenges for […]
Godot blocks automated code to protect governance
Administrators of the open-source game engine Godot have blocked automated code submissions to protect repository governance and fix review backlogs. The foundation […]
PolinRider supply chain attack expands to Packagist ecosystem
North Korean threat actors are escalating the PolinRider supply chain attack across Go, Packagist, and npm package environments. The threat cluster – […]