Sign in

DevDefender

@devdefender.net
17 followers 109 following 11 posts

Building real-time alerting for developers: protect your dev environment from AI-enhanced threats. devdefender.net get@devdefender.net

PostsRepliesMedia
DevDefender @devdefender.net · 02/07/2026
devdefender.net
How binding.gyp can be exploited
000
DevDefender @devdefender.net · 02/07/2026
devdefender.net
Released: Security Digest v0.1.2
100
Reposted by DevDefender
Liran Tal @lirantal.com · 06/03/2026
look at the last column and your favorite LLM for how likely they are to produce correct code (which for you seems fine), yet insecure code (which is great for attackers), that's from #baxbench project
021
DevDefender @devdefender.net · 04/03/2026
Introducing the DevDefender Security Digest: a collection of relevant news, security threats, and vulnerability reports that affect developers, software pipelines, IDEs, and dev environments.
devdefender.net
DevDefender Security Digest — 2026-03-03
Relevant news, security threats, and vulnerability reports that affect developers, software pipelines, IDEs, and dev environments.
011
DevDefender @devdefender.net · 26/02/2026
Versions prior to 2026.1.14 of mcp-server-git are vulnerable to data exfiltration through relative path traversal, allowing paths outside the repository to be added to the repo and exfiltrated by committing and pushing the repository.
devdefender.net
Relative path traversal in git MCP Server: data exfiltration using 'git_add'
Versions prior to 2026.1.14 of mcp-server-git are vulnerable to data exfiltration through relative path traversal, allowing paths outside the repository to be added to the repo and exfiltrated by committing and pushing the repository.
010
DevDefender @devdefender.net · 26/02/2026
There is no foolproof method of preventing all prompt injection attacks, but there are some ways to limit the scope of such an attack. This is not one of those ways.
devdefender.net
'Clinejection': spread a payload by opening an issue
There is no foolproof method of preventing all prompt injection attacks, but there are some ways to limit the scope of such an attack. This is not one of those ways.
000
DevDefender @devdefender.net · 24/02/2026
SANDWORM_MODE is a supply chain worm that has similarities to Shai-Hulud and poisons AI Agents using an innocuous-looking MCP server installed on the developer machine.
devdefender.net
SANDWORM_MODE: npm Worm Poisoning AI Toolchains
Socket’s Threat Research Team dropped an incredibly detailed report on a Shai-Hulud-like supply chain worm that affects 19+ malicious npm packages. NPM Worm Credential Harvesting From their announc...
111
DevDefender @devdefender.net · 24/02/2026
OX Security has found four new vulnerable extensions in VSCode with 128M collective downloads: RCE and remote & local exfil.
devdefender.net
128M Downloads: Four New VSCode Extension Vulnerabilities
OX Security announced four new CVEs on VSCode extensions February 17, 2026. These four extensions had been downloaded 128M times.
000
DevDefender @devdefender.net · 24/02/2026
Zed LSP without Restricted Mode enabled allows a project's settings configuration to load arbitrary code when a repository is opened.
devdefender.net
Zed LSP Arbitrary Code Execution
A vulnerability in the AI editor Zed allows for an attacker to modify the zed settings.json file to add an arbitrary script as an Language Server Protocol. When the malicious LSP is triggered, the cod...
000
DevDefender @devdefender.net · 24/02/2026
VSCode, Cursor, and any other editor based on Visual Studio Code are vulnerable to an auto-exec vulnerability that is triggered by a simple, everyday task: opening a folder.
devdefender.net
Exploit Cursor Agents to create persistent, distributed threats
Simply opening a folder can give an attacker a foothold into all the code bases a developer maintains.
000
DevDefender @devdefender.net · 24/02/2026
A little #intro - we're building an open-source #EDR for Developers. The dev environment is getting more and more hostile. We build tools and tutorials to help you defend your code from your own dev environment: #malicious configurations, extensions, and more. Test our pre-alpha: devdefender.net
010