Coding assistants
Model-based tools that write, review or run code inside editors, terminals and pipelines.
- All items
- 160
- Last 90 days
- 44
- Change
- -10%vs 49 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 1 |
| Jul 2025 | 0 |
| Aug 2025 | 4 |
| Sep 2025 | 2 |
| Oct 2025 | 3 |
| Nov 2025 | 4 |
| Dec 2025 | 4 |
| Jan 2026 | 3 |
| Feb 2026 | 17 |
| Mar 2026 | 16 |
| Apr 2026 | 12 |
| May 2026 | 16 |
| Jun 2026 | 18 |
| Jul 2026 | 19 |
| Aug 2026 | 13 |
| Sep 2026 | 14 |
| Oct 2026 | 3 |
160 items
Enterprises know AI-generated code is vulnerable; they’re shipping it anyway
Jun 9, 2026InfoNewsSecurityIndustryA Checkmarx survey of 2,350 CISOs, AppSec managers and developers across 14 countries found that enterprises with 81% to 100% AI-generated code ship vulnerable code 3.4 times more often than those using AI for 20% or less of their code. About 30% of respondents said they ship compromised code and hope the vulnerability is not found, and 93% reported at least one breach from in-house apps. Only 22% of organizations have formal AI governance.
CSO OnlineCVE-2026-45482: GitHub Copilot and Visual Studio Code path traversal flaw
Jun 9, 2026HighVulnerabilitySecurityCVE-2026-45482CVE-2026-45482 is a path traversal flaw (CWE-22) in GitHub Copilot and Visual Studio Code. The source says it allows an unauthorized attacker to bypass a security feature locally. NIST has not yet provided an NVD assessment, and Microsoft Corporation is the listed source.
NVD/CVE DatabaseApple’s best AI idea looks a lot like vibe coding
Jun 9, 2026InfoNewsIndustryApple's WWDC keynote largely matched AI features already available elsewhere, including Siri capabilities found on Android and in the Claude and ChatGPT apps. The article's author then tried the first developer beta of iPadOS 26, and the excerpt ends before describing what that experience showed.
The Verge (AI)CVE-2026-47644: Copilot Chat in Microsoft Edge injection flaw allows information disclosure
Jun 4, 2026MediumVulnerabilitySecurityCVE-2026-47644CVE-2026-47644 is an improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge), classified as CWE-74. The source states that it allows an unauthorized attacker to disclose information over a network. The NVD assessment has not yet been provided.
NVD/CVE DatabaseCVE-2026-45497: Microsoft Copilot command injection allowing remote code execution
Jun 4, 2026HighVulnerabilitySecurityCVE-2026-45497CVE-2026-45497 is a command injection flaw (CWE-77) in Microsoft Copilot, classified as Improper Neutralization of Special Elements used in a Command. The source says an authorized attacker can execute code over a network. NVD has not yet provided an assessment, and the record was published and last modified on 06/04/2026.
NVD/CVE DatabaseCVE-2026-42824: M365 Copilot command injection allows unauthorized information disclosure
Jun 4, 2026MediumVulnerabilitySecurityCVE-2026-42824CVE-2026-42824 is an improper neutralization of special elements used in a command ('command injection') flaw, classified as CWE-77, in M365 Copilot. The source states that an unauthorized attacker can disclose information over a network. The record was published and last modified on 06/04/2026, with the CVE attributed to Microsoft Corporation and no NVD assessment yet provided.
NVD/CVE DatabaseMicrosoft's new MAI models
Jun 2, 2026InfoNewsIndustryOn 2 June 2026, Microsoft announced two text LLMs. MAI-Thinking-1 is a 35B-parameter reasoning model available to select early partners, and MAI-Code-1-Flash is a 5B-parameter model built for GitHub Copilot and VS Code, rolling out to individual Copilot users in Visual Studio Code. Microsoft says both were trained on clean, commercially licensed data, and that MAI-Thinking-1 was trained without distillation from third-party models.
Simon Willison's WeblogMicrosoft 365 Copilot gets a speed boost and cleaner design
May 28, 2026InfoNewsIndustryMicrosoft is rolling out a redesigned Microsoft 365 Copilot across desktop and mobile, which the company says loads twice as fast. The update adds a feature it calls "progressive disclosure", which shows tools and controls based on the user's prompt rather than all at once.
The Verge (AI)Microsoft Copilot Cowork Exfiltrates Files
May 26, 2026MediumNewsSecuritySafetyMicrosoft Copilot Cowork let agents send emails to the user's own inbox without approval. Those messages could include external images that trigger network requests, so a compromised message opened by the user could leak data to an attacker. Because OneDrive can create pre-authenticated download links, a successful prompt injection could expose those links and let an attacker download files.
Simon Willison's WeblogGemini is in danger of going full Copilot
May 19, 2026InfoNewsIndustryGoogle is adding Gemini, the AI assistant, across more of its apps at a fast pace, and the author finds the spread increasingly irritating. The piece compares this to Microsoft's placement of Copilot shortcuts throughout Windows 11, which drew similar user complaints. The source text is truncated and ends before the full story.
The Verge (AI)Microsoft’s Edge Copilot update uses AI to pull information from across your tabs
May 13, 2026InfoNewsIndustryPrivacyMicrosoft Edge is adding a feature that lets its Copilot chatbot gather information from all open tabs. Users can ask Copilot about tab contents, compare products and summarize open articles. Microsoft says users can choose which experiences to enable, and it is retiring Copilot Mode, which offered agentic features such as booking reservations.
The Verge (AI)CVE-2026-45033: GitHub Copilot CLI code execution via nested malicious bare git repository
May 13, 2026HighVulnerabilitySecurityCVE-2026-45033A flaw in GitHub Copilot CLI before 1.0.43 allows arbitrary code execution when the agent runs git operations inside a project containing a malicious nested bare git repository. Git's automatic bare repository discovery during directory traversal lets an attacker set core.fsmonitor or other executable config keys, such as core.hookspath, diff.external and merge.tool, which git runs during status, diff or rev-parse without user awareness or approval.
Fix: Fixed in 1.0.43.
NVD/CVE DatabaseCVE-2026-42893: M365 Copilot command injection allowing network tampering
May 12, 2026HighVulnerabilitySecurityCVE-2026-42893CVE-2026-42893 is classified as CWE-77, Improper Neutralization of Special Elements used in a Command ('Command Injection'), in M365 Copilot. The source states that an unauthorized attacker can perform tampering over a network. NVD had not yet provided an assessment at the time of the record.
NVD/CVE DatabaseCVE-2026-41614: M365 Copilot for Desktop improper access control allows local spoofing
May 12, 2026MediumVulnerabilitySecurityCVE-2026-41614CVE-2026-41614 is an improper access control flaw (CWE-284) in M365 Copilot for Desktop. It allows an unauthorized attacker to perform spoofing, but only locally. NIST has not yet provided an NVD assessment, and the source is Microsoft Corporation, published 05/12/2026.
NVD/CVE DatabaseCVE-2026-41109: GitHub Copilot and Visual Studio injection flaw bypasses security feature
May 12, 2026HighVulnerabilitySecurityCVE-2026-41109CVE-2026-41109 is an improper neutralization of special elements in output used by a downstream component ('injection'), classified as CWE-74, in GitHub Copilot and Visual Studio. The source states that an unauthorized attacker can bypass a security feature over a network. NVD published the entry on 05/12/2026, and NIST has not yet provided an assessment.
NVD/CVE DatabaseCVE-2026-41100: M365 Copilot improper access control allows local spoofing
May 12, 2026MediumVulnerabilitySecurityCVE-2026-41100CVE-2026-41100 is an improper access control flaw (CWE-284) in M365 Copilot. The source states that an authorized attacker can perform spoofing locally. NVD had not yet provided an assessment when the record was published on 05/12/2026.
NVD/CVE DatabaseCVE-2026-42869: SOCFortress CoPilot hardcoded JWT signing secret allows forged admin tokens
May 11, 2026CriticalVulnerabilitySecurityCVE-2026-42869CVE-2026-42869 affects SOCFortress CoPilot before 0.1.57. The backend ships a hardcoded JWT signing secret as a fallback in backend/app/auth/utils.py:28 and repeats it in .env.example. Deployments that leave JWT_SECRET unset, including the default Docker Compose setup, sign every authentication token with this public value, letting an unauthenticated attacker forge admin-scoped JWTs and take full control of the application and the security tools it manages.
Fix: Fixed in 0.1.57.
NVD/CVE DatabaseCVE-2026-33111: Copilot Chat (Microsoft Edge) command injection allowing information disclosure
May 7, 2026HighVulnerabilitySecurityCVE-2026-33111CVE-2026-33111 is a command injection flaw (CWE-77) in Copilot Chat for Microsoft Edge. Per the source, an unauthorized attacker can exploit it over a network to disclose information. NIST has not yet provided an NVD assessment, and the entry was published and last modified on 05/07/2026.
NVD/CVE DatabaseCVE-2026-26164: M365 Copilot injection flaw allows unauthorized information disclosure
May 7, 2026HighVulnerabilitySecurityCVE-2026-26164CVE-2026-26164 is an improper neutralization of special elements in output used by a downstream component ('injection'), classified as CWE-74, in M365 Copilot. The source states that an unauthorized attacker can disclose information over a network. NVD has not yet provided an assessment, and the record was published and last modified on 05/07/2026.
NVD/CVE DatabaseCVE-2026-26129: M365 Copilot improper neutralization enables information disclosure
May 7, 2026HighVulnerabilitySecurityCVE-2026-26129CVE-2026-26129 is a vulnerability in M365 Copilot, classified under CWE-138 (Improper Neutralization of Special Elements). An unauthorized attacker can exploit it over a network to disclose information. NVD had not yet provided an assessment at publication, and the record was published and last modified on 05/07/2026 with Microsoft Corporation as the source.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.