News

SpaceXAI’s Grok 4.5 Undercuts Anthropic and OpenAI on Coding Agent Pricing
SpaceXAI's Grok 4.5 undercuts Opus 4.8 on price, matching it on key coding benchmarks, and adds new safeguards against cybersecurity risks ...

GhostApproval Flaw Featuring Decades-Old Feature Found in Six AI Coding Tools
A security flaw found in six popular AI coding agents can let attackers abuse a decades-old feature in Unix to trick an AI agent into giving them control of a developer’s system ...

GitHub Copilot Bills Hit $800: Visual Studio’s June Update Adds Real-Time Usage Alerts and MCP Trust Checks
Visual Studio's June update adds real-time Copilot usage alerts and MCP server trust checks, responding to billing and agent security concerns ...

North Korea Expands the Reach of PolinRider Supply Chain Attack Campaign
The North Korean-sponsored threat groups behind the long-running fake interview scams targeting developers are expanding the PolinRider supply chain campaign that has escalated over the past several months. Reports from cybersecurity vendors ...

‘GitLost’ Flaw Lets Attackers Trick GitHub AI Agent Into Leaking Private Repos
Noma researchers again show how easy it is to manipulate AI agents with malicious commands via indirect prompt injection attacks ...

Mistral Releases Leanstral 1.5, an Open Model That Solved 587 of 672 Putnam Math Problems
Mistral's open Leanstral 1.5 model solved 587 of 672 Putnam math problems and is already finding real bugs in open-source code ...

Z.ai Debuts ZCode to Compete With GitHub Copilot, Cursor and Anthropic
Chinese AI developer Z.ai has introduced ZCode, a desktop application that automates software development tasks, positioning the platform to compete with established coding platforms from Anthropic, GitHub and Cursor. The company built ...

Anthropic Adds Enterprise Gateway to Simplify Claude Code Access on AWS and Google Cloud
Anthropic's new Claude apps gateway brings SSO, central policy, and spend caps to Claude Code on Amazon Bedrock and Google Cloud ...

Mozilla Shows the Danger of Indirect Prompt Injections in AI Coding Agents
A clean GitHub repository that contains no malicious code can launch an attack and fully compromise a developer’s systems by using indirect prompt injections to trick AI-powered coding agents like Anthropic’s Claude ...

Attackers Exploit SimpleHelp Flaw to Steal Info from AI Coding Assistants, Clouds
Threat actors are exploiting a known security flaw in the SimpleHelp remote monitoring and management (RMM) software to drop two previously unknown pieces of malware that can compromise a broad range of ...

Akrites: The Latest Attempt to Protect Open-Source From AI Attacks Has Arrived
Akrites, a new Linux Foundation initiative backed by many of the world’s largest tech and financial firms, is the industry’s latest attempt to get ahead of AI‑accelerated software supply chain risks by ...

Qodo Extends Reach and Scope of AI Code Review Platform
Qodo this week extended its platform for managing code quality and governance to enable an artificial intelligence (AI) agent to review code spanning multiple repositories. Additionally, version 2.8 of the Qodo platform ...

