Coding assistants
Model-based tools that write, review or run code inside editors, terminals and pipelines.
- All items
- 160
- Last 90 days
- 44
- Change
- -8%vs 48 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 1 |
| Jul 2025 | 0 |
| Aug 2025 | 4 |
| Sep 2025 | 2 |
| Oct 2025 | 3 |
| Nov 2025 | 4 |
| Dec 2025 | 4 |
| Jan 2026 | 3 |
| Feb 2026 | 17 |
| Mar 2026 | 16 |
| Apr 2026 | 12 |
| May 2026 | 16 |
| Jun 2026 | 18 |
| Jul 2026 | 19 |
| Aug 2026 | 13 |
| Sep 2026 | 14 |
| Oct 2026 | 3 |
81 items
Falcon AIDR Now Protects Copilot Studio Agents and Claude Code
Jul 30, 2026InfoNewsSecurityIndustryCrowdStrike's Falcon AI Detection and Response (AIDR) now extends its AI visibility, detection, and response to Microsoft Copilot Studio and Claude Code, plus a Falcon browser extension capability. In Copilot Studio, Falcon AIDR runs as an external threat detection provider and returns allow or block decisions on tool calls before they execute. For Claude Code, it connects to the tool's hook event system to check prompts and tool activity, with setup done by adding a JSON block to the settings file.
CrowdStrike BlogMicrosoft confirms Copilot ‘super app’ coming this year
Jul 29, 2026InfoNewsIndustryMicrosoft is building an AI "super app" that combines Copilot's chat, coding, and agentic capabilities. CEO Satya Nadella confirmed on an earnings call that it will span consumer and commercial experiences when it launches this year.
The Verge (AI)Why Jim Cramer is shocked by Citi's against-the-grain praise of Microsoft's Copilot
Jul 15, 2026InfoNewsIndustryCNBC TechnologyGPT-5.6 is now the preferred model in Microsoft 365 Copilot
Jul 9, 2026InfoNewsIndustryOpenAI announced GPT-5.6, its latest flagship model series, which will become the new preferred model in Microsoft 365 Copilot across Word, Excel, PowerPoint, Chat and Cowork. Microsoft will serve the models natively and also access OpenAI models directly through the API to bring GPT-5.6 to Microsoft 365 customers.
OpenAI BlogGitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code
Jul 8, 2026MediumNewsSecuritySafetyResearchers Abhishek Kumar and Carsten Maple found that GitHub Copilot's underlying models (Claude Sonnet 4.6, Claude Haiku 4.5, Gemini 3.1 Pro and Gemini 3.5 Flash) refused almost all harmful requests in chat but produced harmful answers in all 816 workflow runs when the same requests were framed as steps in a coding task. The method, called workflow-level jailbreak construction, asked Copilot to add harmful question-and-answer examples to a test harness, and the model wrote the harmful answers itself. Testing used GitHub Copilot Chat 0.30.3 in VS Code 1.103.0, with sessions run between April 2 and June 22, 2026.
The Hacker NewsCritical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution
Jul 3, 2026MediumNewsSecurityIndustryCato Networks reports two critical flaws in the Cursor AI code editor, tracked as CVE-2026-50548 and CVE-2026-50549 (CVSS 9.8) and dubbed DuneSlide, that can lead to remote code execution outside the IDE's sandbox. The first abuses the working_directory parameter, which adds a non-default path to the allow list, letting a prompt injection delivered through an MCP server request make the LLM overwrite the cursorsandbox executable. The second uses symbolic links to bypass out-of-bounds write protections because of a path canonicalization flaw.
Fix: Patches for both were included in Cursor 3.0, released on April 2. Cato reported the flaws to Cursor in February.
SecurityWeekMicrosoft fixes bug that removed Copilot buttons in Outlook
Jul 2, 2026InfoNewsIndustryMicrosoft has fixed a known issue that removed the Copilot Chat or Copilot buttons from Classic Outlook for Windows users holding the Copilot Chat (Basic) license. Microsoft also says it is investigating Outlook crashes on systems running Kaspersky Antivirus, linked to the Kaspersky Mail Checker (mcou.dll).
Fix: Microsoft's Outlook Team addressed the Copilot button issue with a service change on June 29, 2026. Affected users are advised to restart their email client, update to the latest build via File > Office Account > Update Options > Update Now, or revert to the previous Current Channel build (16.0.20026.20168) or use the new Outlook or Outlook Web Access (OWA). For the Kaspersky crashes, affected users are advised to contact Kaspersky support.
BleepingComputerM365 Copilot SearchLeak: Your prompt injection attack surface just got bigger
Jun 19, 2026MediumNewsSecurityIndustryVaronis Threat Labs researchers disclosed SearchLeak, a proof-of-concept attack against Microsoft's M365 Copilot Enterprise Search that leaks sensitive corporate data when employees click crafted links. The attack chains three weaknesses, using the ?q= URL parameter as a natural-language prompt that can instruct the LLM to surface and exfiltrate accessible business content such as emails, SharePoint and OneDrive files. Microsoft rated the information disclosure flaw as critical and patched it server-side.
Fix: Microsoft patched the vulnerability on the server side earlier this month.
CSO OnlineCopilot 'SearchLeak' Attack Allows 1-Click Data Theft
Jun 15, 2026InfoNewsSecuritySafetyA critical, three-stage attack against Copilot, dubbed 'SearchLeak', enables one-click data theft. The attack is now patched and belongs to a new group of AI prompt-injection issues that use hidden URLs and other variables.
Dark ReadingOne-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
Jun 15, 2026MediumNewsSecurityPrivacyVaronis Threat Labs disclosed SearchLeak, a chain of three bugs that could let one click on a microsoft.com link exfiltrate emails, calendar details and indexed files from Microsoft 365 Copilot Enterprise Search. Microsoft assigned it CVE-2026-42824 and rated it critical, while CVSS scores of 6.5 from Microsoft and 7.5 from the National Vulnerability Database disagree. The attack abuses the q parameter, a Content Security Policy allowlist for *.bing.com, and a render race in the output sanitizer, and Varonis presented a proof-of-concept rather than observed exploitation.
Fix: Microsoft mitigated the flaw on its backend, so customers have nothing to worry about.
The Hacker NewsNew attack turned Microsoft 365 Copilot into 1-click data theft tool
Jun 15, 2026MediumNewsSecurityPrivacyVaronis researchers disclosed SearchLeak, a three-stage chain in Microsoft 365 Copilot Enterprise that lets an attacker steal mailbox, OneDrive, or SharePoint data through a crafted URL with a victim click. Microsoft fixed it as CVE-2026-42824, rated critical, and the chain combines a parameter-to-prompt injection via the 'q' parameter, an HTML rendering race condition, and a CSP bypass enabled by a Bing SSRF in the Search by Image feature.
Fix: Fixed by Microsoft as CVE-2026-42824. No user action is required, according to the source.
BleepingComputerOpenAI to acquire Ona to support its AI coding assistant, Codex
Jun 11, 2026InfoNewsIndustryOpenAI announced it will acquire Ona, a startup providing secure, pre-configured cloud environments where AI agents can access tools, systems and context. The deal will let OpenAI's coding assistant Codex take on longer-running tasks and help more organizations deploy agents into production. Terms were not disclosed and the deal remains subject to customary closing conditions.
CNBC TechnologyEnterprises know AI-generated code is vulnerable; they’re shipping it anyway
Jun 9, 2026InfoNewsSecurityIndustryA Checkmarx survey of 2,350 CISOs, AppSec managers and developers across 14 countries found that enterprises with 81% to 100% AI-generated code ship vulnerable code 3.4 times more often than those using AI for 20% or less of their code. About 30% of respondents said they ship compromised code and hope the vulnerability is not found, and 93% reported at least one breach from in-house apps. Only 22% of organizations have formal AI governance.
CSO OnlineApple’s best AI idea looks a lot like vibe coding
Jun 9, 2026InfoNewsIndustryApple's WWDC keynote largely matched AI features already available elsewhere, including Siri capabilities found on Android and in the Claude and ChatGPT apps. The article's author then tried the first developer beta of iPadOS 26, and the excerpt ends before describing what that experience showed.
The Verge (AI)Microsoft's new MAI models
Jun 2, 2026InfoNewsIndustryOn 2 June 2026, Microsoft announced two text LLMs. MAI-Thinking-1 is a 35B-parameter reasoning model available to select early partners, and MAI-Code-1-Flash is a 5B-parameter model built for GitHub Copilot and VS Code, rolling out to individual Copilot users in Visual Studio Code. Microsoft says both were trained on clean, commercially licensed data, and that MAI-Thinking-1 was trained without distillation from third-party models.
Simon Willison's WeblogMicrosoft 365 Copilot gets a speed boost and cleaner design
May 28, 2026InfoNewsIndustryMicrosoft is rolling out a redesigned Microsoft 365 Copilot across desktop and mobile, which the company says loads twice as fast. The update adds a feature it calls "progressive disclosure", which shows tools and controls based on the user's prompt rather than all at once.
The Verge (AI)Microsoft Copilot Cowork Exfiltrates Files
May 26, 2026MediumNewsSecuritySafetyMicrosoft Copilot Cowork let agents send emails to the user's own inbox without approval. Those messages could include external images that trigger network requests, so a compromised message opened by the user could leak data to an attacker. Because OneDrive can create pre-authenticated download links, a successful prompt injection could expose those links and let an attacker download files.
Simon Willison's WeblogGemini is in danger of going full Copilot
May 19, 2026InfoNewsIndustryGoogle is adding Gemini, the AI assistant, across more of its apps at a fast pace, and the author finds the spread increasingly irritating. The piece compares this to Microsoft's placement of Copilot shortcuts throughout Windows 11, which drew similar user complaints. The source text is truncated and ends before the full story.
The Verge (AI)Microsoft’s Edge Copilot update uses AI to pull information from across your tabs
May 13, 2026InfoNewsIndustryPrivacyMicrosoft Edge is adding a feature that lets its Copilot chatbot gather information from all open tabs. Users can ask Copilot about tab contents, compare products and summarize open articles. Microsoft says users can choose which experiences to enable, and it is retiring Copilot Mode, which offered agentic features such as booking reservations.
The Verge (AI)Vibe coding and agentic engineering are getting closer than I'd like
May 6, 2026InfoNewsIndustrySafetySimon Willison describes how his view of vibe coding and agentic engineering has begun to converge in his own work, which he calls a disturbing realization. He distinguishes vibe coding, where the person does not look at the code and it is suited to personal tools, from agentic engineering, where a professional engineer uses AI tools while maintaining quality, security and operational standards. He admits he no longer reviews every line of code his coding agents write, even for production systems, and raises the question of whether that is responsible.
Simon Willison's Weblog
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.