Coding assistants
Model-based tools that write, review or run code inside editors, terminals and pipelines.
- All items
- 160
- Last 90 days
- 44
- Change
- -10%vs 49 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 1 |
| Jul 2025 | 0 |
| Aug 2025 | 4 |
| Sep 2025 | 2 |
| Oct 2025 | 3 |
| Nov 2025 | 4 |
| Dec 2025 | 4 |
| Jan 2026 | 3 |
| Feb 2026 | 17 |
| Mar 2026 | 16 |
| Apr 2026 | 12 |
| May 2026 | 16 |
| Jun 2026 | 18 |
| Jul 2026 | 19 |
| Aug 2026 | 13 |
| Sep 2026 | 14 |
| Oct 2026 | 3 |
160 items
Vibe coding and agentic engineering are getting closer than I'd like
May 6, 2026InfoNewsIndustrySafetySimon Willison describes how his view of vibe coding and agentic engineering has begun to converge in his own work, which he calls a disturbing realization. He distinguishes vibe coding, where the person does not look at the code and it is suited to personal tools, from agentic engineering, where a professional engineer uses AI tools while maintaining quality, security and operational standards. He admits he no longer reviews every line of code his coding agents write, even for production systems, and raises the question of whether that is responsible.
Simon Willison's WeblogMicrosoft gives up on Xbox Copilot AI
May 5, 2026InfoNewsIndustryXbox is winding down Copilot on mobile and will stop developing Copilot on console, new Xbox CEO Asha Sharma announced on Tuesday. The decision came alongside a reorganization of the Xbox platform team that added executives from Microsoft's CoreAI team to the Xbox side of the company.
The Verge (AI)Copirate 365 at DEF CON: Plundering in the Depths of Microsoft Copilot (CVE-2026-24299)
May 4, 2026MediumNewsSecuritySafetyThe author's DEF CON Singapore talk describes a chain of vulnerabilities across the Microsoft Copilot family, including data exfiltration via the HTML preview feature, Delayed Tool Invocation, memory hijacking, and a persistent backdoor. Microsoft assigned CVE-2026-24299 after the issues were disclosed, and the source states they are now patched.
Fix: Microsoft has patched the issues; the source does not describe the specific fix or version.
Embrace The RedMicrosoft now lets admins uninstall Copilot on enterprise devices
Apr 24, 2026InfoNewsIndustryPolicyMicrosoft says IT administrators can now uninstall the Microsoft Copilot app from enterprise Windows devices using the RemoveMicrosoftCopilotApp policy setting, available as a Policy CSP and Group Policy after the April 2026 Patch Tuesday updates. The policy applies only to Windows 11 25H2 devices where both Microsoft 365 Copilot and Microsoft Copilot are installed, the user did not install the Microsoft Copilot app, and it has not been launched in 28 days.
Fix: Enable the RemoveMicrosoftCopilotApp policy setting, found at /User/Vendor/MSFT/Policy/Config/WindowsAI/RemoveMicrosoftCopilotApp or /Device/Vendor/MSFT/Policy/Config/WindowsAI/RemoveMicrosoftCopilotApp, after deploying this month's Windows security updates on endpoints managed via Microsoft Intune or System Center Configuration Manager (SCCM).
BleepingComputerCVE-2026-33102: M365 Copilot open redirect to untrusted site allows privilege elevation
Apr 23, 2026CriticalVulnerabilitySecurityCVE-2026-33102CVE-2026-33102 is an open redirect (CWE-601) in M365 Copilot, a hosted service. The flaw is a URL redirection to an untrusted site, which allows an unauthorized attacker to elevate privileges over a network. NVD has not yet provided an assessment; Microsoft Corporation is the source, and NVD published the entry on 04/23/2026.
NVD/CVE DatabaseCVE-2026-6874: ericc-ch copilot-api reliance on reverse DNS in /token Host handling
Apr 22, 2026MediumVulnerabilitySecurityCVE-2026-6874CVE-2026-6874 affects ericc-ch copilot-api up to 0.7.0. A manipulated Host argument sent to the /token endpoint of the Header Handler component can lead to reliance on reverse DNS resolution (CWE-350). The attack can be performed remotely, the exploit has been publicly disclosed, and the vendor did not respond to early contact. CVSS 4.0 base score is 5.3 (MEDIUM), assessed by VulDB; NIST has not yet provided an assessment.
NVD/CVE DatabaseChanges to GitHub Copilot Individual plans
Apr 21, 2026InfoNewsIndustryPolicyGitHub has announced changes to Copilot Individual plans that tighten usage limits, pause signups for individual plans, and restrict Claude Opus 4.7 to the $39/month Pro+ plan while dropping the previous Opus models. The changes add token-based usage limits per session and per week, replacing the per-request charging model that the author says made agentic requests erode GitHub's margins. The author notes the announcement does not clearly say which of the many Copilot-branded products are affected, though the linked plans page suggests Copilot CLI, the Copilot cloud agent, code review, and the IDE features in VS Code, Zed and JetBrains.
Simon Willison's WeblogCVE-2026-6662: ericc-ch copilot-api permissive cross-domain policy in CORS handling
Apr 20, 2026HighVulnerabilitySecurityCVE-2026-6662CVE-2026-6662 affects ericc-ch copilot-api up to 0.7.0. A flaw in the function cors of src/server.ts, in the Token Endpoint component, produces a permissive cross-domain policy that accepts untrusted domains. The attack can be launched remotely, and public exploit code exists. VulDB scores it CVSS 4.0 6.9 (MEDIUM), with weaknesses CWE-346 and CWE-942.
NVD/CVE DatabaseCopilot & Agentforce offen für Prompt-Injection-Tricks
Apr 20, 2026MediumNewsSecurityIndustryCapsule Security researchers found prompt-injection flaws in Microsoft Copilot Studio and Salesforce Agentforce that let attackers slip malicious instructions through seemingly harmless input, such as a SharePoint form comment or a public lead form. A compromised Copilot Studio agent could read connected SharePoint lists, extract customer data and email it out, and Microsoft rated the flaw CVSS 7.5 of 10. Salesforce acknowledged the injection problem but called the exfiltration vector configuration-specific and pointed to optional human-in-the-loop controls, a position the researchers dispute.
Fix: Microsoft has released a patch that fixes the Copilot Studio issue, and no further user action is required. For both platforms the source recommends treating all external input as untrusted, filtering to separate data from instructions, and enforcing input validation, least-privilege access and strict controls, though the source does not give Salesforce-specific fix details.
CSO OnlineClaude Code, Gemini CLI, GitHub Copilot Agents Vulnerable to Prompt Injection via Comments
Apr 16, 2026MediumNewsSecuritySafetyA researcher has disclosed details of an AI attack method he calls 'Comment and Control'. The method reportedly enables prompt injection through comments in Claude Code, Gemini CLI and GitHub Copilot Agents.
SecurityWeekCopilot and Agentforce fall to form-based prompt injection tricks
Apr 15, 2026MediumNewsSecurityPrivacyCapsule Security researchers disclosed prompt-injection flaws in Microsoft Copilot Studio and Salesforce Agentforce that let crafted input override agent instructions and exfiltrate data. In the Microsoft case, a payload in a SharePoint form field leaks customer records from connected SharePoint Lists by email, and the flaw was assigned CVE-2026-21520 with a CVSS score of 7.5. In the Salesforce case, a malicious public lead form causes an agent to pull CRM records via the "GetLeadsInformation" function and email them externally, and Salesforce called the vector "configuration-specific" and pointed to optional human-in-the-loop controls.
Fix: Microsoft patched the issue following disclosure; the mitigation was carried out internally and no further action is required from users. For the broader issue, the source says both disclosures converge on treating all external inputs as untrusted, using filters that separate data from instructions, enforcing input validation, least-privilege access, and strict controls on actions like outbound email.
CSO OnlineCVE-2026-23653: GitHub Copilot and Visual Studio Code command injection flaw
Apr 14, 2026MediumVulnerabilitySecurityCVE-2026-23653CVE-2026-23653 is a command injection flaw (CWE-77) in GitHub Copilot and Visual Studio Code. The source states that an authorized attacker can use it to disclose information over a network. NIST has not yet provided an NVD assessment, and the CVE was published on 04/14/2026.
NVD/CVE DatabaseMicrosoft is testing OpenClaw-like AI bots for Copilot
Apr 13, 2026InfoNewsIndustryMicrosoft is reportedly testing ways to integrate OpenClaw-style features into its Copilot AI assistant, according to The Information. The goal is to let Microsoft 365 Copilot run autonomously around the clock while completing tasks for users. Omar Shahine, Microsoft's corporate vice president, confirmed the company is exploring OpenClaw-like technologies in an enterprise context.
The Verge (AI)Microsoft starts removing Copilot buttons from Windows 11 apps
Apr 10, 2026InfoNewsIndustryMicrosoft has started removing Copilot buttons from Windows 11 apps, as part of a plan to reduce what it calls unnecessary Copilot entry points. The latest Windows Insider build of Notepad replaces its Copilot button with a writing tools menu, and the Snipping Tool no longer shows a Copilot button when capturing an area. The underlying AI features are expected to remain.
The Verge (AI)Microsoft executive touts Copilot sales traction as AI anxiety weighs on stock
Apr 2, 2026InfoNewsIndustryMicrosoft executive Judson Althoff told employees that sales of the Microsoft 365 Copilot add-on have gained traction after criticism of low adoption. Microsoft reported 15 million seats in January, representing 3% of standard bundle seats, and its stock fell 23% in the first quarter. Althoff said the company revamped its sales strategy after analyst feedback and was confident in its June quarter targets.
CNBC TechnologyAddressing the OWASP Top 10 Risks in Agentic AI with Microsoft Copilot Studio
Mar 30, 2026InfoNewsSecurityIndustryMicrosoft's blog post discusses the OWASP Top 10 for Agentic Applications (2026), which outlines risks for autonomous systems that act across workflows using real identities, data access and tools. The post explores the list's key findings and highlights practical mitigations grounded in Agent 365 and foundational capabilities in Microsoft Copilot Studio. Microsoft AI Red Team members helped review the list before publication.
Fix: Practical mitigations are referenced as grounded in Agent 365 and foundational capabilities in Microsoft Copilot Studio, but the source text provided is truncated before the specific mitigations are described.
Microsoft Security BlogThere are more AI health tools than ever—but how well do they work?
Mar 30, 2026InfoNewsIndustrySafetyMicrosoft launched Copilot Health, letting users connect medical records and ask health questions inside its Copilot app, while Amazon widened access to its LLM-based Health AI tool. These launches join ChatGPT Health from OpenAI and Anthropic's Claude, which can read health records when permitted. Researchers argue these tools need rigorous evaluation by independent experts before wide release.
MIT Technology ReviewNew CrowdStrike Innovations Secure AI Agents and Govern Shadow AI Across Endpoints, SaaS, and Cloud
Mar 23, 2026InfoNewsSecurityIndustryCrowdStrike announced new Falcon platform capabilities that extend AI detection and response (AIDR) to endpoints, SaaS and cloud environments. On endpoints, Falcon AIDR will extend runtime threat detection beyond the browser to desktop AI applications such as ChatGPT, Gemini, Claude, DeepSeek, Microsoft Copilot, GitHub Copilot and Cursor, and is currently in pre-beta with general availability planned for Q2.
CrowdStrike BlogCVE-2026-26137: Microsoft 365 Copilot Business Chat server-side request forgery over the network
Mar 19, 2026HighVulnerabilitySecurityCVE-2026-26137CVE-2026-26137 is a server-side request forgery (CWE-918) in Microsoft 365 Copilot's Business Chat. According to the description, an authorized attacker over a network can use it to elevate privileges. NVD has not yet provided an assessment, and the record was published on 03/19/2026.
NVD/CVE DatabaseCVE-2026-26136: Microsoft Copilot command injection allows unauthorized information disclosure
Mar 19, 2026MediumVulnerabilitySecurityCVE-2026-26136CVE-2026-26136 is a command injection weakness (CWE-77) in Microsoft Copilot, reported by Microsoft Corporation. The source describes it as an improper neutralization of special elements used in a command, which allows an unauthorized attacker to disclose information over a network. The NVD has not yet provided an assessment, and the record was published and last modified on 03/19/2026.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.