Reposted by DevDefenderLiran Tal @lirantal.com · 06/03/2026look at the last column and your favorite LLM for how likely they are to produce correct code (which for you seems fine), yet insecure code (which is great for attackers), that's from #baxbench project 021
DevDefender @devdefender.net · 04/03/2026Introducing the DevDefender Security Digest: a collection of relevant news, security threats, and vulnerability reports that affect developers, software pipelines, IDEs, and dev environments.devdefender.netDevDefender Security Digest — 2026-03-03Relevant news, security threats, and vulnerability reports that affect developers, software pipelines, IDEs, and dev environments. 011
DevDefender @devdefender.net · 26/02/2026Versions prior to 2026.1.14 of mcp-server-git are vulnerable to data exfiltration through relative path traversal, allowing paths outside the repository to be added to the repo and exfiltrated by committing and pushing the repository.devdefender.netRelative path traversal in git MCP Server: data exfiltration using 'git_add'Versions prior to 2026.1.14 of mcp-server-git are vulnerable to data exfiltration through relative path traversal, allowing paths outside the repository to be added to the repo and exfiltrated by committing and pushing the repository. 010
DevDefender @devdefender.net · 26/02/2026There is no foolproof method of preventing all prompt injection attacks, but there are some ways to limit the scope of such an attack. This is not one of those ways.devdefender.net'Clinejection': spread a payload by opening an issueThere is no foolproof method of preventing all prompt injection attacks, but there are some ways to limit the scope of such an attack. This is not one of those ways. 000
DevDefender @devdefender.net · 25/02/2026shoutout to the @socket.dev team for the incredible report. 021
DevDefender @devdefender.net · 24/02/2026SANDWORM_MODE is a supply chain worm that has similarities to Shai-Hulud and poisons AI Agents using an innocuous-looking MCP server installed on the developer machine.devdefender.netSANDWORM_MODE: npm Worm Poisoning AI ToolchainsSocket’s Threat Research Team dropped an incredibly detailed report on a Shai-Hulud-like supply chain worm that affects 19+ malicious npm packages. NPM Worm Credential Harvesting From their announc... 111
DevDefender @devdefender.net · 24/02/2026OX Security has found four new vulnerable extensions in VSCode with 128M collective downloads: RCE and remote & local exfil.devdefender.net128M Downloads: Four New VSCode Extension VulnerabilitiesOX Security announced four new CVEs on VSCode extensions February 17, 2026. These four extensions had been downloaded 128M times. 000
DevDefender @devdefender.net · 24/02/2026Zed LSP without Restricted Mode enabled allows a project's settings configuration to load arbitrary code when a repository is opened.devdefender.netZed LSP Arbitrary Code ExecutionA vulnerability in the AI editor Zed allows for an attacker to modify the zed settings.json file to add an arbitrary script as an Language Server Protocol. When the malicious LSP is triggered, the cod... 000
DevDefender @devdefender.net · 24/02/2026VSCode, Cursor, and any other editor based on Visual Studio Code are vulnerable to an auto-exec vulnerability that is triggered by a simple, everyday task: opening a folder.devdefender.netExploit Cursor Agents to create persistent, distributed threatsSimply opening a folder can give an attacker a foothold into all the code bases a developer maintains. 000
DevDefender @devdefender.net · 24/02/2026A little #intro - we're building an open-source #EDR for Developers. The dev environment is getting more and more hostile. We build tools and tutorials to help you defend your code from your own dev environment: #malicious configurations, extensions, and more. Test our pre-alpha: devdefender.net 010