Coding assistants
Model-based tools that write, review or run code inside editors, terminals and pipelines.
- All items
- 160
- Last 90 days
- 44
- Change
- -10%vs 49 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 1 |
| Jul 2025 | 0 |
| Aug 2025 | 4 |
| Sep 2025 | 2 |
| Oct 2025 | 3 |
| Nov 2025 | 4 |
| Dec 2025 | 4 |
| Jan 2026 | 3 |
| Feb 2026 | 17 |
| Mar 2026 | 16 |
| Apr 2026 | 12 |
| May 2026 | 16 |
| Jun 2026 | 18 |
| Jul 2026 | 19 |
| Aug 2026 | 13 |
| Sep 2026 | 14 |
| Oct 2026 | 3 |
160 items
CVE-2026-24299: M365 Copilot command injection allows unauthorized information disclosure
Mar 19, 2026MediumVulnerabilitySecurityCVE-2026-24299CVE-2026-24299 is an improper neutralization of special elements used in a command (CWE-77, command injection) in M365 Copilot. An unauthorized attacker can exploit it over a network to disclose information. NIST has not yet provided an NVD assessment, and Microsoft Corporation is the listed source.
NVD/CVE DatabaseMicrosoft shakes up Copilot AI leadership team, freeing up Suleyman to build new models
Mar 17, 2026InfoNewsIndustryMicrosoft is consolidating the engineering groups behind its commercial and consumer Copilot assistants, which have yet to gain broad adoption. Jacob Andreou, a former Snap executive, becomes executive vice president in charge of the Copilot experience and reports to CEO Satya Nadella, freeing Mustafa Suleyman to focus on building new models.
CNBC TechnologyMicrosoft appoints a new Copilot boss after AI leadership shake-up
Mar 17, 2026InfoNewsIndustryMicrosoft is reorganizing its engineering of the Copilot assistant by unifying parts of the consumer and commercial teams. Under the change, Microsoft AI CEO Mustafa Suleyman will focus on building Microsoft's own AI models rather than the assistant-like features of Copilot for consumers.
The Verge (AI)Microsoft stops force-installing the Microsoft 365 Copilot app
Mar 17, 2026InfoNewsIndustryPolicyMicrosoft has temporarily disabled automatic installation of the Microsoft 365 Copilot app on Windows devices outside the EEA that run Microsoft 365 desktop apps, a rollout planned for December 2025. The company has not said why it halted the change, and existing installations are unaffected.
Fix: Admins can deploy the app via other methods. Admins who want to opt out of automatic installation can clear the "Enable automatic installation of Microsoft 365 Copilot app" check box under Customization > Device Configuration > Modern App Settings in the Microsoft 365 Apps admin center.
BleepingComputerCVE-2026-26133: M365 Copilot AI command injection allows information disclosure
Mar 16, 2026HighVulnerabilitySecurityCVE-2026-26133CVE-2026-26133 describes an AI command injection flaw in M365 Copilot. The source states that an unauthorized attacker can exploit it over a network to disclose information. NVD has not yet provided an assessment, and the vulnerability was published on 03/16/2026.
NVD/CVE DatabaseMicrosoft’s Copilot AI assistant is coming to current-gen Xbox consoles this year
Mar 13, 2026InfoNewsIndustryMicrosoft plans to bring its Gaming Copilot AI assistant to current-generation Xbox consoles this year, according to a GamesRadar report. Sonali Yadav, Xbox's product manager for gaming AI, said at a Game Developers Conference (GDC) panel that the assistant will also expand to more services players use. The assistant is already in beta on the Xbox mobile app, Windows 11 and Xbox Ally handhelds.
The Verge (AI)Microsoft’s Copilot Health can connect to your medical records and wearables
Mar 12, 2026InfoNewsIndustryPrivacyMicrosoft announced Copilot Health, a separate, secure space within Copilot for questions about lab results and medical records, provider searches, analysis of wearable data and other health chats. The feature rolls out in phases, and users can join a waitlist for access. Microsoft says it does not replace a doctor and is not intended for diagnosis or treatment.
The Verge (AI)Anthropic launches code review tool to check flood of AI-generated code
Mar 9, 2026InfoNewsIndustrySecurityAnthropic launched Code Review, an AI reviewer that checks pull requests for logic errors inside Claude Code, first available to Claude for Teams and Claude for Enterprise customers in research preview. It integrates with GitHub, leaves comments with suggested fixes, and labels issues red, yellow or purple by severity. Anthropic says each review costs $15 to $25 on average.
TechCrunchMicrosoft adds higher-priced Office tier with Copilot as it tries to juice sales with AI
Mar 9, 2026InfoNewsIndustryPolicyMicrosoft is adding a higher-priced Microsoft 365 E7 tier that costs $99 per user per month, compared with $60 for E5, to push enterprise customers toward its Copilot AI add-on. E7 bundles Copilot ($30), Entra identity tools ($12) and Agent 365 ($15) for managing AI agents, and it becomes available on May 1. Copilot Cowork, built with Anthropic, enters research preview this month for Frontier program clients.
CNBC TechnologyGHSA-g8r9-g2v8-jv6f: GitHub Copilot CLI Dangerous Shell Expansion Patterns Enable Arbitrary Code Execution
Mar 6, 2026HighVulnerabilitySecurityCVE-2026-29783GitHub Copilot CLI's shell tool contains a vulnerability in which crafted bash parameter expansion patterns (such as ${var@P}, assignment forms like ${var=value}, indirect ${!var}, and nested $(cmd) inside ${...}) can hide command execution inside commands the safety assessment classifies as read-only. An attacker who can influence the commands the agent runs, for example through prompt injection in repository files, MCP server responses, or user instructions, could achieve arbitrary code execution on the user's workstation, even in modes that require approval for write operations. The issue affects versions prior to 0.0.423.
Fix: Fixed in 0.0.423. The fix adds parse-time detection that downgrades commands containing dangerous ${...} expansion operators or nested command/process substitutions from read-only to write-capable, and unconditionally blocks such commands at the tool execution layer regardless of permission mode, including --yolo / autopilot.
GitHub Advisory DatabaseRaycast’s Glaze is an all-in-one vibe coding app platform
Mar 4, 2026InfoNewsIndustryRaycast, the launcher app popular among Mac users, is launching Glaze, a new product for building, using, sharing, and discovering vibe-coded software. It is currently available only for Mac. The source text is truncated before the full story.
The Verge (AI)Microsoft’s Copilot Tasks AI uses its own computer to get things done
Feb 26, 2026InfoNewsIndustryMicrosoft is previewing Copilot Tasks, an AI system that handles routine work in the background. It runs on its own cloud-based computer and browser, so it can take on jobs such as scheduling appointments or generating study plans while the user does something else. Users describe tasks in natural language and assign them as recurring, scheduled, or one-time jobs, and Copilot Tasks reports back when it finishes.
The Verge (AI)RoguePilot Flaw in GitHub Codespaces Enabled Copilot to Leak GITHUB_TOKEN
Feb 24, 2026LowNewsSecuritySafetyOrca Security disclosed RoguePilot, an AI-driven flaw in GitHub Codespaces that let attackers embed hidden instructions in a GitHub issue. When a user launched a Codespace from that issue, the built-in GitHub Copilot processed the instructions and could be made to leak the privileged GITHUB_TOKEN to an external server. Microsoft patched the issue following responsible disclosure.
Fix: Microsoft patched the vulnerability following responsible disclosure.
The Hacker NewsMicrosoft adds Copilot data controls to all storage locations
Feb 24, 2026LowNewsSecurityPrivacyMicrosoft is extending Microsoft Purview DLP controls so Microsoft 365 Copilot cannot process confidential Word, Excel, and PowerPoint files stored locally, not only those in SharePoint or OneDrive. The change ships through the AugLoop Office component between late March and late April 2026 and is enabled automatically for organizations with DLP policies blocking Copilot from sensitivity-labeled content. It follows a bug that let Copilot Chat summarize confidential emails in Sent Items and Drafts for nearly a month, first discovered on January 21.
Fix: Microsoft is deploying the AugLoop change between late March and late April 2026, so Office clients provide the sensitivity label directly and DLP enforcement applies to local files; no administrative action is required for organizations with the relevant DLP policies configured.
BleepingComputerGitHub Issues Abused in Copilot Attack Leading to Repository Takeover
Feb 24, 2026MediumNewsSecurityIndustryAttackers can place malicious instructions inside a GitHub Issue. Copilot automatically processes those instructions when a Codespace is launched from that issue, which can lead to repository takeover.
SecurityWeekMicrosoft error sees confidential emails exposed to AI tool Copilot
Feb 19, 2026LowNewsSecurityPrivacyMicrosoft acknowledged a bug in which Microsoft 365 Copilot Chat returned content from emails labelled confidential that were stored in users' Draft and Sent Items folders in Outlook desktop. The issue reportedly persisted even where a sensitivity label and a data loss prevention policy were configured, and Microsoft says it first became aware of the error in January.
Fix: Microsoft says it has deployed a configuration update worldwide for enterprise customers, and that it addressed the issue.
BBC TechnologyHackers can turn Grok, Copilot into covert command-and-control channels, researchers warn
Feb 19, 2026MediumNewsSecurityIndustryCheck Point Research describes a technique that abuses web-browsing and URL-fetch features of Grok and Microsoft Copilot to relay command-and-control traffic for malware on an infected machine. The channel requires neither an API key nor an authenticated account, and it blends into routine HTTPS traffic to AI domains that organizations often allow by default with limited inspection.
Fix: Security leaders should not block AI outright. Analysts recommend applying the same governance discipline used for other high-risk SaaS platforms, starting with a comprehensive inventory of all AI tools in use and a clear policy framework for approving and enabling them. The source text is cut off before it completes the list of AI-specific controls.
CSO OnlineMicrosoft says Office bug exposed customers’ confidential emails to Copilot AI
Feb 18, 2026LowNewsSecurityPrivacyMicrosoft confirmed a bug that let Copilot Chat in Microsoft 365 summarize customers' confidential emails for weeks, even where data loss prevention policies were meant to block ingestion. The flaw, tracked by admins as CW1226324, affected draft and sent emails carrying a confidential label since January. Microsoft did not say how many customers were affected.
Fix: Microsoft said it began rolling out a fix for the bug earlier in February.
TechCrunch (Security)Microsoft says bug causes Copilot to summarize confidential emails
Feb 18, 2026LowNewsSecurityPrivacyMicrosoft says a bug in Microsoft 365 Copilot has caused the "work tab" Copilot Chat feature to summarize confidential emails since late January, bypassing data loss prevention (DLP) policies. Tracked as CW1226324 and first detected on January 21, the bug incorrectly processes messages in Sent Items and Drafts folders even when confidentiality labels are applied. Microsoft attributes it to an unspecified code error, began rolling out a fix in early February, and has not disclosed how many users were affected.
Fix: Microsoft began rolling out a fix in early February and is monitoring the deployment while reaching out to a subset of affected users to verify it works. No final remediation timeline has been provided.
BleepingComputerFigma partners with Anthropic to turn AI-generated code into editable designs
Feb 17, 2026InfoNewsIndustryFigma is partnering with Anthropic to launch Code to Canvas, a feature that converts code generated by AI tools such as Claude Code into fully editable designs on Figma's canvas. Users can then refine the designs, compare options side by side and align on design decisions. Figma's stock has fallen about 85% from its August 52-week high of $142.92 amid a broader software sell-off.
CNBC Technology
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.