Coding assistants
Model-based tools that write, review or run code inside editors, terminals and pipelines.
- All items
- 160
- Last 90 days
- 44
- Change
- -8%vs 48 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 1 |
| Jul 2025 | 0 |
| Aug 2025 | 4 |
| Sep 2025 | 2 |
| Oct 2025 | 3 |
| Nov 2025 | 4 |
| Dec 2025 | 4 |
| Jan 2026 | 3 |
| Feb 2026 | 17 |
| Mar 2026 | 16 |
| Apr 2026 | 12 |
| May 2026 | 16 |
| Jun 2026 | 18 |
| Jul 2026 | 19 |
| Aug 2026 | 13 |
| Sep 2026 | 14 |
| Oct 2026 | 3 |
81 items
Raycast’s Glaze is an all-in-one vibe coding app platform
Mar 4, 2026InfoNewsIndustryRaycast, the launcher app popular among Mac users, is launching Glaze, a new product for building, using, sharing, and discovering vibe-coded software. It is currently available only for Mac. The source text is truncated before the full story.
The Verge (AI)Microsoft’s Copilot Tasks AI uses its own computer to get things done
Feb 26, 2026InfoNewsIndustryMicrosoft is previewing Copilot Tasks, an AI system that handles routine work in the background. It runs on its own cloud-based computer and browser, so it can take on jobs such as scheduling appointments or generating study plans while the user does something else. Users describe tasks in natural language and assign them as recurring, scheduled, or one-time jobs, and Copilot Tasks reports back when it finishes.
The Verge (AI)RoguePilot Flaw in GitHub Codespaces Enabled Copilot to Leak GITHUB_TOKEN
Feb 24, 2026LowNewsSecuritySafetyOrca Security disclosed RoguePilot, an AI-driven flaw in GitHub Codespaces that let attackers embed hidden instructions in a GitHub issue. When a user launched a Codespace from that issue, the built-in GitHub Copilot processed the instructions and could be made to leak the privileged GITHUB_TOKEN to an external server. Microsoft patched the issue following responsible disclosure.
Fix: Microsoft patched the vulnerability following responsible disclosure.
The Hacker NewsMicrosoft adds Copilot data controls to all storage locations
Feb 24, 2026LowNewsSecurityPrivacyMicrosoft is extending Microsoft Purview DLP controls so Microsoft 365 Copilot cannot process confidential Word, Excel, and PowerPoint files stored locally, not only those in SharePoint or OneDrive. The change ships through the AugLoop Office component between late March and late April 2026 and is enabled automatically for organizations with DLP policies blocking Copilot from sensitivity-labeled content. It follows a bug that let Copilot Chat summarize confidential emails in Sent Items and Drafts for nearly a month, first discovered on January 21.
Fix: Microsoft is deploying the AugLoop change between late March and late April 2026, so Office clients provide the sensitivity label directly and DLP enforcement applies to local files; no administrative action is required for organizations with the relevant DLP policies configured.
BleepingComputerGitHub Issues Abused in Copilot Attack Leading to Repository Takeover
Feb 24, 2026MediumNewsSecurityIndustryAttackers can place malicious instructions inside a GitHub Issue. Copilot automatically processes those instructions when a Codespace is launched from that issue, which can lead to repository takeover.
SecurityWeekMicrosoft error sees confidential emails exposed to AI tool Copilot
Feb 19, 2026LowNewsSecurityPrivacyMicrosoft acknowledged a bug in which Microsoft 365 Copilot Chat returned content from emails labelled confidential that were stored in users' Draft and Sent Items folders in Outlook desktop. The issue reportedly persisted even where a sensitivity label and a data loss prevention policy were configured, and Microsoft says it first became aware of the error in January.
Fix: Microsoft says it has deployed a configuration update worldwide for enterprise customers, and that it addressed the issue.
BBC TechnologyHackers can turn Grok, Copilot into covert command-and-control channels, researchers warn
Feb 19, 2026MediumNewsSecurityIndustryCheck Point Research describes a technique that abuses web-browsing and URL-fetch features of Grok and Microsoft Copilot to relay command-and-control traffic for malware on an infected machine. The channel requires neither an API key nor an authenticated account, and it blends into routine HTTPS traffic to AI domains that organizations often allow by default with limited inspection.
Fix: Security leaders should not block AI outright. Analysts recommend applying the same governance discipline used for other high-risk SaaS platforms, starting with a comprehensive inventory of all AI tools in use and a clear policy framework for approving and enabling them. The source text is cut off before it completes the list of AI-specific controls.
CSO OnlineMicrosoft says Office bug exposed customers’ confidential emails to Copilot AI
Feb 18, 2026LowNewsSecurityPrivacyMicrosoft confirmed a bug that let Copilot Chat in Microsoft 365 summarize customers' confidential emails for weeks, even where data loss prevention policies were meant to block ingestion. The flaw, tracked by admins as CW1226324, affected draft and sent emails carrying a confidential label since January. Microsoft did not say how many customers were affected.
Fix: Microsoft said it began rolling out a fix for the bug earlier in February.
TechCrunch (Security)Microsoft says bug causes Copilot to summarize confidential emails
Feb 18, 2026LowNewsSecurityPrivacyMicrosoft says a bug in Microsoft 365 Copilot has caused the "work tab" Copilot Chat feature to summarize confidential emails since late January, bypassing data loss prevention (DLP) policies. Tracked as CW1226324 and first detected on January 21, the bug incorrectly processes messages in Sent Items and Drafts folders even when confidentiality labels are applied. Microsoft attributes it to an unspecified code error, began rolling out a fix in early February, and has not disclosed how many users were affected.
Fix: Microsoft began rolling out a fix in early February and is monitoring the deployment while reaching out to a subset of affected users to verify it works. No final remediation timeline has been provided.
BleepingComputerFigma partners with Anthropic to turn AI-generated code into editable designs
Feb 17, 2026InfoNewsIndustryFigma is partnering with Anthropic to launch Code to Canvas, a feature that converts code generated by AI tools such as Claude Code into fully editable designs on Figma's canvas. Users can then refine the designs, compare options side by side and align on design decisions. Figma's stock has fallen about 85% from its August 52-week high of $142.92 amid a broader software sell-off.
CNBC TechnologyResearchers Show Copilot and Grok Can Be Abused as Malware C2 Proxies
Feb 17, 2026MediumNewsSecurityIndustryCheck Point researchers disclosed a technique, codenamed AI as a C2 proxy, that abuses AI assistants with web browsing or URL fetching, demonstrated against Microsoft Copilot and xAI Grok. Malware already on a compromised host can send specially crafted prompts that make the assistant fetch attacker-controlled URLs and return responses, creating a bidirectional command-and-control channel. The method works without an API key or registered account, so key revocation or account suspension would not stop it.
The Hacker NewsCopilot Studio agent security: Top 10 risks you can detect and prevent
Feb 12, 2026InfoNewsSecurityIndustryMicrosoft describes ten common Copilot Studio agent misconfigurations observed in real environments, including agents shared too broadly, agents exposed without authentication, risky HTTP Request actions, and agents with excessive privileges. The post maps each risk to detections in Microsoft Defender Advanced Hunting using Community Hunting Queries in the AI Agent folder.
Fix: Detect each misconfiguration with the Advanced Hunting Community Queries listed for it in the AI Agents folder of the Security portal, and follow the mitigations described in each section of the post.
Microsoft Security BlogGLM-5: From Vibe Coding to Agentic Engineering
Feb 11, 2026InfoNewsIndustryResearchZ.ai has released GLM-5, a 754B-parameter model under the MIT license, available on Hugging Face at 1.51TB. That is about twice the size of GLM-4.7, which had 368B parameters and 717GB. The post also notes Z.ai's framing of professional software engineers building with LLMs as "Agentic Engineering," a term the author has seen from Andrej Karpathy and Addy Osmani.
Simon Willison's WeblogCross-Agent Privilege Escalation: When Agents Free Each Other
Sep 24, 2025MediumNewsSecurityResearchJohann Rehberger describes a design flaw in agentic systems that lets one coding agent rewrite another agent's configuration, freeing it from its sandbox. In his demo, a prompt-injected GitHub Copilot writes a malicious MCP server into Claude Code's config, which then runs arbitrary code. The post notes that Claude can reciprocate by modifying Copilot's configuration.
Fix: Mitigations and Recommendations: the source states that vendors should adopt secure defaults and that users should be aware of several points, including isolating the agent's configuration so it is less accessible to others and not automatically overwriting or creating files. The remainder of the mitigation text is cut off in the source.
Embrace The RedGitHub Copilot: Remote Code Execution via Prompt Injection (CVE-2025-53773)
Aug 12, 2025MediumNewsSecurityIndustryThis post describes a prompt injection flaw in GitHub Copilot and VS Code, tracked as CVE-2025-53773, that leads to full system compromise of the developer's machine. The attack places Copilot into YOLO mode by modifying the project's settings.json file. The author notes that agents able to write files and alter their own configuration or security-relevant settings can reach remote code execution, a pattern similar to one recently described for Amp.
Embrace The RedGitHub Copilot Custom Instructions and Risks
Apr 6, 2025LowNewsSecurityIndustryGitHub Copilot can be augmented with custom instructions from the current repo, read from the .github/copilot-instructions.md file. Pillar Security highlighted the risks of such rules files, using custom Cursor rules in ./cursor/rules ending in .mdc, and included a GitHub Copilot demo that uses copilot-instructions.md. GitHub then changed its Web UI to highlight invisible Unicode characters, citing the Pillar Security post and a post about ASCII Smuggling.
Fix: GitHub made a product change that highlights invisible Unicode characters in the Web UI.
Embrace The RedMicrosoft 365 Copilot Generated Images Accessible Without Authentication -- Fixed!
Jan 2, 2025MediumNewsSecurityIndustryThe author compares system prompt changes in Microsoft 365 Copilot (BizChat) over time and notes that a single enterprise_search tool used to exist. The tool was previously used in the Copirate ASCII Smuggling exploit to search a user's inbox for MFA codes.
Embrace The RedMicrosoft Copilot: From Prompt Injection to Exfiltration of Personal Information
Aug 26, 2024MediumNewsSecurityPrivacyJohann Rehberger describes an exploit chain against Microsoft 365 Copilot that let an attacker steal a user's emails and personal information. The chain combines prompt injection delivered through a malicious email or shared document, automatic tool invocation to pull in other emails and documents, and ASCII Smuggling to hide data inside clickable hyperlinks to an attacker-controlled domain. Rehberger first reported parts of the exploit to Microsoft in January 2024 and the full chain in February 2024, and disclosed it after MSRC approval.
Embrace The RedProtect Your Copilots: Preventing Data Leaks in Copilot Studio
Jul 30, 2024InfoNewsSecurityPrivacyMicrosoft's Copilot Studio, a low-code platform for building chatbots, is the subject of this post. It covers data leak and unauthorized access risks, including how external adversaries can find and interact with misconfigured Copilots. The post highlights Data Loss Prevention (DLP) as a control that is currently off by default.
Fix: Enable Data Loss Prevention (DLP), which is currently off by default, to protect your organization's data.
Embrace The RedGitHub Copilot Chat: From Prompt Injection to Data Exfiltration
Jun 15, 2024MediumNewsSecurityIndustryA prompt injection flaw in the GitHub Copilot Chat VS Code extension allowed data exfiltration when the extension analyzed untrusted source code. The extension sends source code and user questions to a large language model, and the post describes how that input path could be abused. The source text does not give further technical detail in this excerpt.
Embrace The Red
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.