Coding assistants
Model-based tools that write, review or run code inside editors, terminals and pipelines.
- All items
- 160
- Last 90 days
- 44
- Change
- -10%vs 49 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 1 |
| Jul 2025 | 0 |
| Aug 2025 | 4 |
| Sep 2025 | 2 |
| Oct 2025 | 3 |
| Nov 2025 | 4 |
| Dec 2025 | 4 |
| Jan 2026 | 3 |
| Feb 2026 | 17 |
| Mar 2026 | 16 |
| Apr 2026 | 12 |
| May 2026 | 16 |
| Jun 2026 | 18 |
| Jul 2026 | 19 |
| Aug 2026 | 13 |
| Sep 2026 | 14 |
| Oct 2026 | 3 |
160 items
Researchers Show Copilot and Grok Can Be Abused as Malware C2 Proxies
Feb 17, 2026MediumNewsSecurityIndustryCheck Point researchers disclosed a technique, codenamed AI as a C2 proxy, that abuses AI assistants with web browsing or URL fetching, demonstrated against Microsoft Copilot and xAI Grok. Malware already on a compromised host can send specially crafted prompts that make the assistant fetch attacker-controlled URLs and return responses, creating a bidirectional command-and-control channel. The method works without an API key or registered account, so key revocation or account suspension would not stop it.
The Hacker NewsCopilot Studio agent security: Top 10 risks you can detect and prevent
Feb 12, 2026InfoNewsSecurityIndustryMicrosoft describes ten common Copilot Studio agent misconfigurations observed in real environments, including agents shared too broadly, agents exposed without authentication, risky HTTP Request actions, and agents with excessive privileges. The post maps each risk to detections in Microsoft Defender Advanced Hunting using Community Hunting Queries in the AI Agent folder.
Fix: Detect each misconfiguration with the Advanced Hunting Community Queries listed for it in the AI Agents folder of the Security portal, and follow the mitigations described in each section of the post.
Microsoft Security BlogGLM-5: From Vibe Coding to Agentic Engineering
Feb 11, 2026InfoNewsIndustryResearchZ.ai has released GLM-5, a 754B-parameter model under the MIT license, available on Hugging Face at 1.51TB. That is about twice the size of GLM-4.7, which had 368B parameters and 717GB. The post also notes Z.ai's framing of professional software engineers building with LLMs as "Agentic Engineering," a term the author has seen from Andrej Karpathy and Addy Osmani.
Simon Willison's WeblogCVE-2026-21523: GitHub Copilot and Visual Studio race condition allowing network code execution
Feb 10, 2026HighVulnerabilitySecurityCVE-2026-21523CVE-2026-21523 is a time-of-check time-of-use (TOCTOU) race condition, classified as CWE-367, in GitHub Copilot and Visual Studio. The source states that an authorized attacker can exploit it to execute code over a network. NIST has not yet provided an NVD assessment, and the entry was published 02/10/2026.
NVD/CVE DatabaseCVE-2026-21518: GitHub Copilot and Visual Studio Code command injection bypass
Feb 10, 2026MediumVulnerabilitySecurityCVE-2026-21518CVE-2026-21518 is an improper neutralization of special elements used in a command (CWE-77, 'command injection') flaw in GitHub Copilot and Visual Studio Code. The source states that an unauthorized attacker can exploit it over a network to bypass a security feature. NVD has not yet provided an assessment, and the record was published 02/10/2026 and last modified 02/11/2026.
NVD/CVE DatabaseCVE-2026-21516: GitHub Copilot command injection allows remote code execution over a network
Feb 10, 2026HighVulnerabilitySecurityCVE-2026-21516CVE-2026-21516 is a command injection flaw (CWE-77) in GitHub Copilot, caused by improper neutralization of special elements used in a command. According to the source, an unauthorized attacker can execute code over a network. NVD had not yet provided an assessment when the record was last modified on 02/11/2026, and the source lists Microsoft Corporation as the advisory source.
NVD/CVE DatabaseCVE-2026-21257: GitHub Copilot and Visual Studio command injection allows privilege elevation
Feb 10, 2026HighVulnerabilitySecurityCVE-2026-21257CVE-2026-21257 is a command injection flaw (CWE-77) in GitHub Copilot and Visual Studio. The source says an authorized attacker can exploit it over a network to elevate privileges. NVD has not yet provided an assessment, and the NVD record was published 02/10/2026 and last modified 02/11/2026.
NVD/CVE DatabaseCVE-2026-21256: GitHub Copilot and Visual Studio command injection over network
Feb 10, 2026HighVulnerabilitySecurityCVE-2026-21256CVE-2026-21256 is an improper neutralization of special elements used in a command, also known as command injection (CWE-77), in GitHub Copilot and Visual Studio. The source states that an unauthorized attacker can execute code over a network. NVD has not yet provided an assessment, and the record was published on 02/10/2026.
NVD/CVE DatabaseCVE-2026-24307: M365 Copilot improper input validation allows information disclosure
Jan 22, 2026CriticalVulnerabilitySecurityCVE-2026-24307CVE-2026-24307 is an improper validation of specified type of input (CWE-1287) in M365 Copilot. According to the source, an unauthorized attacker can exploit it over a network to disclose information. NVD had not yet provided an assessment when the entry was published on 01/22/2026, and last modified 02/12/2026.
NVD/CVE DatabaseCVE-2026-21521: Copilot information disclosure via improper neutralization of escape sequences
Jan 22, 2026HighVulnerabilitySecurityCVE-2026-21521CVE-2026-21521 is classified as CWE-150, Improper Neutralization of Escape, Meta, or Control Sequences, in Copilot. The source states that an unauthorized attacker can disclose information over a network. NVD has not yet provided an assessment, and the affected software configurations list is not populated in the source.
NVD/CVE DatabaseCVE-2026-21520: Copilot Studio exposure of sensitive information to unauthorized actor
Jan 22, 2026HighVulnerabilitySecurityCVE-2026-21520CVE-2026-21520 is an exposure of sensitive information to an unauthorized actor in Copilot Studio. According to the source, an unauthenticated attacker can view sensitive information through a network attack vector. The weakness is classified as CWE-77, Improper Neutralization of Special Elements used in a Command ('Command Injection'), and NVD has not yet provided an assessment.
NVD/CVE DatabaseCVE-2025-62116: AI Copilot missing authorization allows access control bypass
Dec 31, 2025MediumVulnerabilitySecurityCVE-2025-62116CVE-2025-62116 is a Missing Authorization vulnerability (CWE-862) in Quadlayers AI Copilot, a WordPress plugin, affecting versions from n/a through 1.4.7. The flaw allows exploitation of incorrectly configured access control security levels. Patchstack reported the issue, and NIST has not yet provided an NVD assessment.
NVD/CVE DatabaseCVE-2025-62998: WP AI CoPilot sensitive data exposure through sent data
Dec 18, 2025MediumVulnerabilitySecurityPrivacyCVE-2025-62998CVE-2025-62998 is an Insertion of Sensitive Information Into Sent Data (CWE-201) vulnerability in WP Messiah's WP AI CoPilot plugin, affecting versions from n/a through 1.2.7. The flaw allows retrieval of embedded sensitive data. NVD has not yet provided an assessment, and the record was published by Patchstack on 12/18/2025.
NVD/CVE DatabaseCVE-2025-64671: Copilot command injection allows local code execution by unauthorized attacker
Dec 9, 2025HighVulnerabilitySecurityCVE-2025-64671CVE-2025-64671 is a command injection flaw (CWE-77) in Copilot, reported by Microsoft Corporation. It allows an unauthorized attacker to execute code locally. NIST has not yet provided an NVD assessment, and the entry was published 12/09/2025 and last modified 12/12/2025.
NVD/CVE DatabaseCVE-2025-62994: WP AI CoPilot plugin sensitive data exposure through sent data
Dec 9, 2025MediumVulnerabilitySecurityCVE-2025-62994CVE-2025-62994 is an Insertion of Sensitive Information Into Sent Data vulnerability (CWE-201) in WP Messiah's WP AI CoPilot plugin (ai-co-pilot-for-wp). It affects versions from n/a through 1.2.7 and allows retrieval of embedded sensitive data. NVD had not yet provided an assessment, and the CVE was published 12/09/2025 by Patchstack.
NVD/CVE DatabaseCVE-2025-64660: GitHub Copilot and Visual Studio Code improper access control
Nov 20, 2025HighVulnerabilitySecurityCVE-2025-64660CVE-2025-64660 describes improper access control in GitHub Copilot and Visual Studio Code. According to the source, an authorized attacker can execute code over a network. The weakness is classified as CWE-284 (Improper Access Control), and NVD has not yet provided an assessment.
NVD/CVE DatabaseCVE-2025-62453: GitHub Copilot and Visual Studio Code security feature bypass via AI output
Nov 11, 2025MediumVulnerabilitySecurityCVE-2025-62453CVE-2025-62453 is an improper validation of generative AI output flaw in GitHub Copilot and Visual Studio Code, classified as CWE-693 (Protection Mechanism Failure). An authorized attacker can bypass a security feature locally. NVD has not yet provided an assessment; the entry was published 11/11/2025 and last modified 11/14/2025, with Microsoft Corporation as the source.
NVD/CVE DatabaseCVE-2025-62449: Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat…
Nov 11, 2025MediumVulnerabilitySecurityCVE-2025-62449CVE-2025-62449 is a path traversal flaw (CWE-22) in the Visual Studio Code CoPilot Chat Extension. It allows an authorized attacker to bypass a security feature locally. NVD had not yet provided an assessment at the time of the source text.
NVD/CVE DatabaseCVE-2025-62222: Visual Studio Code CoPilot Chat Extension command injection over network
Nov 11, 2025HighVulnerabilitySecurityCVE-2025-62222CVE-2025-62222 is an improper neutralization of special elements used in a command (CWE-77, command injection) flaw in the Visual Studio Code CoPilot Chat Extension. The source states that it allows an unauthorized attacker to execute code over a network. NIST has not yet provided an NVD assessment, and Microsoft Corporation is the listed source.
NVD/CVE DatabaseCVE-2025-59286: Copilot command injection allows unauthorized information disclosure
Oct 9, 2025CriticalVulnerabilitySecurityCVE-2025-59286CVE-2025-59286 is a command injection flaw (CWE-77) in Copilot, where improper neutralization of special elements in a command lets an unauthorized attacker disclose information over a network. The NVD has not yet provided an assessment, and the vendor advisory is from Microsoft Corporation. NVD published the entry on 10/09/2025 and last modified it on 12/11/2025.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.