Anthropic now lets developers customize Claude Code with mods, event-driven TypeScript functions that rewrite prompts, tool ...
Graphalgo-linked malware hid in Terraform providers and Go packages, targeting developers and cloud infrastructure.
Next.js ImageResponse flaw can lead to server code execution when attacker-controlled values reach generated SVG.
Researchers escaped OpenAI's Codex sandbox two ways, one running commands on a developer's machine from its most locked-down mode. OpenAI has patched both.
Brevo supply-chain attack injected malicious JavaScript into 100,000+ sites, targeting WordPress admins and visitors with ClickFix prompts.