Coding assistants
Model-based tools that write, review or run code inside editors, terminals and pipelines.
- All items
- 160
- Last 90 days
- 44
- Change
- -10%vs 49 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 1 |
| Jul 2025 | 0 |
| Aug 2025 | 4 |
| Sep 2025 | 2 |
| Oct 2025 | 3 |
| Nov 2025 | 4 |
| Dec 2025 | 4 |
| Jan 2026 | 3 |
| Feb 2026 | 17 |
| Mar 2026 | 16 |
| Apr 2026 | 12 |
| May 2026 | 16 |
| Jun 2026 | 18 |
| Jul 2026 | 19 |
| Aug 2026 | 13 |
| Sep 2026 | 14 |
| Oct 2026 | 3 |
160 items
Microsoft is giving Copilot more control over Windows and your files
Oct 7, 2026InfoNewsIndustryPrivacyAt a Windows and Surface event, Microsoft showed an upgraded Copilot that can access local files on a PC and take actions across the operating system. The feature is part of what Microsoft calls "Hybrid Intelligence," in which apps rely on a mix of local and cloud AI models. A stage demo had Jacob Andreou, Microsoft's EVP of Copilot, asking the Autopilot tool to help file taxes.
The Verge (AI)Encrypted instructions trick Copilot CLI into spilling developer secrets
Oct 7, 2026MediumNewsSecuritySafetyAdversa AI researchers described Cryptographic Context Injection (CCI), a technique that hides malicious instructions inside encrypted content so GitHub Copilot CLI treats them as trusted context. In a demonstration, Copilot read a ".env.prod" file and sent its contents to an attacker-controlled endpoint in 28 seconds without confirmation. The attack requires autopilot mode and a model willing to execute the decrypted instructions, and GitHub declined to treat it as a vulnerability.
CSO OnlineGitHub Copilot CLI vulnerability: Cryptographic Context Injection steals developer secrets
Oct 6, 2026MediumNewsSecurityResearchGitHub Copilot CLI can be made to read a developer's local files and send them to an attacker from a single web page. The attack, Cryptographic Context Injection (CCI), hides instructions as ciphertext that the agent decrypts in its own shell and trusts as its own, and the researchers say one attacker-controlled URL fetched in autopilot mode was enough to exfiltrate a .env.prod file in 28 seconds.
Adversa AI BlogFrom SELECT to SYSADMIN with SQL Copilot (CVE-2026-65669)
Sep 30, 2026MediumNewsSecurityA researcher presented at BlueHat Asia 2026 in Singapore on Microsoft's Copilot in SQL Server Management Studio (SSMS). The talk covered CVE-2026-65669, a SQL Server Elevation of Privilege Vulnerability that Microsoft rated critical.
Fix: So, make sure your installations are up-to-date.
Embrace The RedMicrosoft thinks its new Copilot ‘super app’ will be as influential as Office
Sep 25, 2026InfoNewsIndustryMicrosoft is officially unveiling a redesigned Copilot app that bundles chat, coding, and agent capabilities into a single interface. The app has three tabs, Home, Code, and Autopilot, with Home combining Copilot Chat and Cowork. Microsoft is also renaming Scout, the AI personal assistant it unveiled at Build, as Autopilot.
The Verge (AI)What’s new in Microsoft Security: September 2026
Sep 24, 2026InfoNewsSecurityIndustryMicrosoft's September 2026 security update, published as a news item, describes new features across Microsoft Defender, Microsoft Security Copilot, Microsoft Purview and Microsoft Entra. Updates include AI-generated email detonation summaries, network-layer blocking of sensitive data sent to unsanctioned AI tools, expanded auto-labeling for large environments, and eDiscovery and archiving changes for Copilot-created content.
Microsoft Security BlogZ.ai disables coding assistant feature after flaw exposed enterprise code upload risk
Sep 22, 2026MediumNewsSecurityPrivacyZ.ai disabled several features of its ZCode coding assistant after a default setting was found sending users' local code repositories to Alibaba Cloud servers in China without consent. An independent blogger, Ferstar, reported that the client packaged full workspaces, including .git history and global app configs, and uploaded them to Aliyun OSS. The company removed the feature from its latest release and said it had deleted the associated cloud storage.
Fix: Z.ai disabled the repository upload mechanism, deleted the associated cloud storage infrastructure, and implemented changes in the ZCode v3.14.0 client. It also removed the Repo Wiki entry point and the associated generation workflow, and asked CAICT and NSFOCUS to conduct security assessments.
CSO OnlineCVE-2026-85887: M365 Copilot incorrect permission assignment allows information disclosure
Sep 17, 2026HighVulnerabilitySecurityPrivacyCVE-2026-85887CVE-2026-85887 is an incorrect permission assignment for a critical resource in M365 Copilot. An authorized attacker can exploit it over a network to disclose information.
NVD/CVE DatabaseCVE-2026-85885: M365 Copilot command injection allows privilege elevation over a network
Sep 17, 2026CriticalVulnerabilitySecurityCVE-2026-85885CVE-2026-85885 is an improper neutralization of special elements used in a command ('command injection') flaw in M365 Copilot. An authorized attacker can exploit it over a network to elevate privileges.
NVD/CVE DatabaseCVE-2026-78501: Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business…
Sep 17, 2026HighVulnerabilitySecurityPrivacyCVE-2026-78501CVE-2026-78501 is an improper neutralization of special elements used in a command ('command injection') flaw in Microsoft 365 Copilot's Business Chat. An unauthorized attacker can exploit it over a network to disclose information.
NVD/CVE DatabaseCVE-2026-55946: Microsoft Copilot command injection allows unauthorized information disclosure
Sep 17, 2026MediumVulnerabilitySecurityCVE-2026-55946CVE-2026-55946 is an improper neutralization of special elements used in a command ('command injection') flaw in Microsoft Copilot. An unauthorized attacker can exploit it over a network to disclose information.
NVD/CVE DatabaseMicrosoft says Copilot buttons still missing in classic Outlook
Sep 16, 2026LowNewsIndustrySecurityMicrosoft is still investigating a known issue that makes the Copilot and Copilot Chat buttons disappear in classic Outlook for some Windows users with a Copilot Chat (Basic) license or a paid M365 Copilot (Premium) account. Microsoft says the problem occurs after upgrading classic Outlook for Windows to build 20026.20182 and higher, because Outlook cannot locate the MAPI property PR_PROFILE_USER_SMTP_EMAIL_ADDRESS_W within the null profile section. Copilot remains available through Outlook on the web and the Microsoft 365 Copilot standalone app or web experience.
Fix: Temporary workaround: in classic Outlook, select File, then Options, go to Advanced, and check "Show Apps in Outlook" under "Outlook panes." Affected users can also create a new Outlook profile or use the new Outlook email client or Outlook Web Access (OWA), which Microsoft says are not affected.
BleepingComputerUpdate your firewall rules: Teams and Copilot are changing address
Sep 11, 2026InfoNewsIndustryMicrosoft is changing the destination addresses of M365 and Teams web users to copilot.cloud.microsoft and teams.cloud.microsoft, announced in MessageCenter posts MC1465764 and MC1462915. Redirects should be completed by early October, and limited Teams exceptions are possible until Dec. 31, 2026.
Fix: Microsoft advises customers to review configurations on client devices, proxies, firewalls, secure web gateways, or other enterprise network controls to confirm users can connect to the new addresses. Companies blocking the new Copilot address to keep employees off personal Microsoft accounts can use Microsoft's TenantRestrictions control instead. Companies that cannot meet the deadline should contact their account representative.
CSO OnlineCVE-2026-81381: GitHub Copilot and Visual Studio Code credential exposure over network
Sep 8, 2026MediumVulnerabilitySecurityCVE-2026-81381CVE-2026-81381 describes insufficiently protected credentials in GitHub Copilot and Visual Studio Code. An unauthorized attacker can exploit this over a network to disclose information.
NVD/CVE DatabaseCVE-2026-81380: Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio…
Sep 8, 2026MediumVulnerabilitySecurityCVE-2026-81380CVE-2026-81380 is a command injection flaw (CWE-77 style wording: improper neutralization of special elements used in a command) affecting GitHub Copilot and Visual Studio Code. An unauthorized attacker can exploit it over a network to disclose information.
NVD/CVE DatabaseMicrosoft says virtually nobody was grabbing NYT articles through its chatbot
Sep 4, 2026InfoNewsPolicyIndustryMicrosoft says in new legal filings that its Copilot rarely reproduces even full sentences from news articles and books, let alone substantive chunks that could substitute for the originals. The company is contesting copyright claims from publishers including The New York Times and book authors, and it provided 8.2 million Copilot chat logs to an expert hired by the news publishers during discovery.
The Verge (AI)CVE-2026-80098: Copilot Studio improper signature verification allows privilege elevation
Sep 3, 2026CriticalVulnerabilitySecurityCVE-2026-80098CVE-2026-80098 is an improper verification of cryptographic signature flaw in Copilot Studio. An unauthorized attacker can exploit it over a network to elevate privileges.
NVD/CVE DatabaseCVE-2026-58616: Copilot Chat (Microsoft Edge) race condition allows info disclosure
Aug 28, 2026MediumVulnerabilitySecurityPrivacyCVE-2026-58616CVE-2026-58616 is a race condition (CWE-362, improper synchronization of a shared resource) in Copilot Chat in Microsoft Edge. An authorized attacker can exploit it over a network to disclose information.
NVD/CVE DatabaseCVE-2026-69855: Microsoft Copilot in Azure SSRF allows information disclosure
Aug 20, 2026HighVulnerabilitySecurityCVE-2026-69855CVE-2026-69855 is a server-side request forgery (SSRF) flaw in Microsoft Copilot in Azure, classified as CWE-918. An authorized attacker can exploit it over a network to disclose information. The source gives no CVSS score, as NVD has not yet provided an assessment.
NVD/CVE DatabaseSlack is launching collaborative vibe coding channels
Aug 20, 2026InfoNewsIndustrySlack is introducing dedicated Slack Code channels where teams can vibe code together with AI agents rather than switching between tools. The launch includes open, project-specific code channels with dedicated user tabs, plus features to compare code changes and preview HTML output before shipping.
The Verge (AI)
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.