home.social

#code-security — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #code-security, aggregated by home.social.

fetched live
  1. 🚨 Oh, look! #OpenAI generously gifted us #Codex Security, because who wouldn't want their code vulnerabilities open-sourced? 🎁 GitHub Copilot now has a sidekick to help you automate errors even faster! 💻 Just what every developer needs: more tools to manage their code chaos. 🙃
    github.com/openai/codex-securi #GitHubCopilot #CodeSecurity #DevTools #CodeChaos #HackerNews #ngated

  2. 🚨 Oh, look! #OpenAI generously gifted us #Codex Security, because who wouldn't want their code vulnerabilities open-sourced? 🎁 GitHub Copilot now has a sidekick to help you automate errors even faster! 💻 Just what every developer needs: more tools to manage their code chaos. 🙃
    github.com/openai/codex-securi #GitHubCopilot #CodeSecurity #DevTools #CodeChaos #HackerNews #ngated

  3. 🚀 Oh, look! Another "batteries-included" framework for Rust web apps! Because, clearly, what every developer needs is yet another tool to manage their existential crisis. 🔧🔍 Just don’t forget to "secure your code as yo"—whatever that means. 🙄
    github.com/tokio-rs/topcoat #RustFrameworks #DeveloperTools #WebDevelopment #CodeSecurity #ExistentialCrisis #HackerNews #ngated

  4. 🚀 Oh, look! Another "batteries-included" framework for Rust web apps! Because, clearly, what every developer needs is yet another tool to manage their existential crisis. 🔧🔍 Just don’t forget to "secure your code as yo"—whatever that means. 🙄
    github.com/tokio-rs/topcoat #RustFrameworks #DeveloperTools #WebDevelopment #CodeSecurity #ExistentialCrisis #HackerNews #ngated

  5. 🔥BREAKING NEWS: #Python lovers are *still* trying to make their code run safely—now with a sprinkle of #MicroPython and #WebAssembly magic. 🤦‍♂️ Simon's alpha package will apparently revolutionize the wheel for anyone who thinks running code securely was ever the problem. 🚀 Spoiler: it wasn't.
    simonwillison.net/2026/Jun/6/m #codeSecurity #innovation #HackerNews #ngated

  6. 🔥BREAKING NEWS: #Python lovers are *still* trying to make their code run safely—now with a sprinkle of #MicroPython and #WebAssembly magic. 🤦‍♂️ Simon's alpha package will apparently revolutionize the wheel for anyone who thinks running code securely was ever the problem. 🚀 Spoiler: it wasn't.
    simonwillison.net/2026/Jun/6/m #codeSecurity #innovation #HackerNews #ngated

  7. Anthropic Unveils Claude Security for AI-Powered Vulnerability Scanning

    Boost your organization's security with Claude Security, now in public beta, which scans codebases to detect and fix software vulnerabilities with just a few clicks. Say goodbye to tedious API integrations and custom agent builds - simply access the feature from the Claude.ai sidebar and start…

    osintsights.com/anthropic-unve

    #AipoweredVulnerabilityScanning #ClaudeSecurity #VulnerabilityManagement #CodeSecurity #EmergingThreats

  8. Firms Scramble to Secure AI-Generated Code

    As AI-generated code becomes more prevalent, a pressing question emerges: how much attention should security teams give to code produced by artificial intelligence? The surprising answer: a lot, with 58% of organizations dedicating over 10 hours a month to securing it.

    osintsights.com/firms-scramble

    #AigeneratedCode #CodeSecurity #ArtificialIntelligence #EmergingThreats #SecureCoding

  9. GitHub Bolsters Secret Scanning, Enhancing API and Workflow Integrations

    GitHub improved secret scanning. Developers can now use new API filters and get more details in workflows to manage leaked secrets better. This helps teams fix security issues faster.

    #GitHubSecurity, #SecretScanning, #APIIntegration, #DevOps, #CodeSecurity

    newsletter.tf/github-secret-sc

  10. GitHub's secret scanning tools now offer more control. Developers can use new API filters and get detailed alerts, making it easier to find and fix leaked secrets in code.

    #GitHubSecurity, #SecretScanning, #APIIntegration, #DevOps, #CodeSecurity
    newsletter.tf/github-secret-sc

  11. Cursor's $29.3B code editor marketed Composer 2 as an "in-house" model. A developer found the actual model ID within 24 hours: it was Kimi K2.5, built by Beijing's Moonshot AI. This marks the second undisclosed use of Chinese models in four months, raising questions about transparency when users route proprietary code through these systems.

    #AITransparency #CodeSecurity #TechAccountability

    implicator.ai/opinion-cursor-c

  12. 👾 Behold, the breathtaking breakthrough of rendering #graphics at the speed of a caffeinated snail using the legendary micro-teeny-tinygrad! 🎨✨ Apparently, #GitHub has decided we need yet another #AI tool to clutter our already overflowing virtual garages. Who knew code security could be so... miniscule? 🔍🔒
    github.com/quantbagel/gtinygrad #Tools #MicroTinygrad #CodeSecurity #HackerNews #ngated

  13. 👾 Behold, the breathtaking breakthrough of rendering #graphics at the speed of a caffeinated snail using the legendary micro-teeny-tinygrad! 🎨✨ Apparently, #GitHub has decided we need yet another #AI tool to clutter our already overflowing virtual garages. Who knew code security could be so... miniscule? 🔍🔒
    github.com/quantbagel/gtinygrad #Tools #MicroTinygrad #CodeSecurity #HackerNews #ngated

  14. 🎉 Ah, the KIM-1 turns 50, and what better way to celebrate than a GitHub demo no one asked for, buried under a pile of buzzword salad? 🤖 Just remember, folks: nothing screams "party" like platform #AI and code security lingo. 🎂
    github.com/netzherpes/KIM1-Demo #KIM1 #50thAnniversary #GitHubDemo #BuzzwordSalad #CodeSecurity #HackerNews #ngated

  15. 🎉 Ah, the KIM-1 turns 50, and what better way to celebrate than a GitHub demo no one asked for, buried under a pile of buzzword salad? 🤖 Just remember, folks: nothing screams "party" like platform #AI and code security lingo. 🎂
    github.com/netzherpes/KIM1-Demo #KIM1 #50thAnniversary #GitHubDemo #BuzzwordSalad #CodeSecurity #HackerNews #ngated

  16. “Noise reduction alone isn’t the goal; accuracy on real risks is.”
    — James Wickett, CEO & Co-founder, DryRun Security

    Why application security needs context at code review - and why intent matters more than alert volume.

    Read more:
    technadu.com/why-application-s

    #AppSec #DevSecOps #CodeSecurity #InfoSec

  17. “Noise reduction alone isn’t the goal; accuracy on real risks is.”
    — James Wickett, CEO & Co-founder, DryRun Security

    Why application security needs context at code review - and why intent matters more than alert volume.

    Read more:
    technadu.com/why-application-s

    #AppSec #DevSecOps #CodeSecurity #InfoSec

  18. AI models often miss IaC security flaws—not because they lack power, but because they lack focus.

    This benchmark shows how accuracy improves when AI gets clear context, tight scope, and an understanding of why a fix works.

    It’s the difference between a quick patch and real remediation.

    At AppSec Village, we appreciate sponsors like Symbiotic AI, who push for true precision in AI-powered security.

    Read the full article →
    symbioticsec.ai/blog/cracking-

    #AI #AIBenchmarks #CodeSecurity #DevSecOps

  19. AI models often miss IaC security flaws—not because they lack power, but because they lack focus.

    This benchmark shows how accuracy improves when AI gets clear context, tight scope, and an understanding of why a fix works.

    It’s the difference between a quick patch and real remediation.

    At AppSec Village, we appreciate sponsors like Symbiotic AI, who push for true precision in AI-powered security.

    Read the full article →
    symbioticsec.ai/blog/cracking-

    #AI #AIBenchmarks #CodeSecurity #DevSecOps

  20. Developer-first security isn’t buzzwords or “shift left.”

    It’s giving developers context, clarity, and tools that reduce cognitive load—not add more alerts or friction.

    This article breaks down why most approaches fall short, and what real developer-first security looks like in practice.

    At AppSec Village, we’re here for sponsors like Symbiotic Security who actually support how developers work.

    Read it here: symbioticsec.ai/blog/real-conv

    #AI #CodeSecurity #DevSecOps #DeveloperFirstSecurity

  21. Developer-first security isn’t buzzwords or “shift left.”

    It’s giving developers context, clarity, and tools that reduce cognitive load—not add more alerts or friction.

    This article breaks down why most approaches fall short, and what real developer-first security looks like in practice.

    At AppSec Village, we’re here for sponsors like Symbiotic Security who actually support how developers work.

    Read it here: symbioticsec.ai/blog/real-conv

    #AI #CodeSecurity #DevSecOps #DeveloperFirstSecurity

  22. 🚨 OH NO! React Server Components can't catch a break! 🎉 Just when you thought it was safe to deploy... surprise! More vulnerabilities! 😱 But hey, at least they're not letting hackers run wild with RCE, just crash your server and peek at your code. 🤦‍♂️ So much for smooth sailing, React team!
    react.dev/blog/2025/12/11/deni #ReactServerComponents #vulnerabilities #ServerCrash #CodeSecurity #HackerNews #HackerNews #ngated

  23. 🚨 OH NO! React Server Components can't catch a break! 🎉 Just when you thought it was safe to deploy... surprise! More vulnerabilities! 😱 But hey, at least they're not letting hackers run wild with RCE, just crash your server and peek at your code. 🤦‍♂️ So much for smooth sailing, React team!
    react.dev/blog/2025/12/11/deni #ReactServerComponents #vulnerabilities #ServerCrash #CodeSecurity #HackerNews #HackerNews #ngated

  24. "AI-driven security and spec-first IDEs are revolutionizing software development. Tools like Defender for Cloud and GitHub Advanced Security offer runtime insights, while spec-first tools like Kiro and Spec Kit embed security into code from the start. Faster remediation, better security, and a shift from code-first to intent-first development. "

    saysomething.hashnode.dev/ai-d

  25. "AI-driven security and spec-first IDEs are revolutionizing software development. Tools like Defender for Cloud and GitHub Advanced Security offer runtime insights, while spec-first tools like Kiro and Spec Kit embed security into code from the start. Faster remediation, better security, and a shift from code-first to intent-first development. #AIInnovation #DevSecOps #SpecFirst #CodeSecurity #SoftwareEngineering"

    saysomething.hashnode.dev/ai-d

  26. OpenAI has launched Aardvark, an autonomous “agentic security researcher” powered by GPT-5.

    It scans codebases for vulnerabilities, validates exploitability in sandboxed environments, and auto-generates potential patches.

    Early reports show 10+ CVEs identified in open-source projects.

    What’s your view - is AI-driven vulnerability research the future of cybersecurity or another layer of risk?

    #CyberSecurity #OpenAI #GPT5 #Aardvark #Infosec #AI #DevSecOps #VulnerabilityManagement #MachineLearning #CodeSecurity #TechNews

  27. OpenAI has launched Aardvark, an autonomous “agentic security researcher” powered by GPT-5.

    It scans codebases for vulnerabilities, validates exploitability in sandboxed environments, and auto-generates potential patches.

    Early reports show 10+ CVEs identified in open-source projects.

    What’s your view - is AI-driven vulnerability research the future of cybersecurity or another layer of risk?

    #CyberSecurity #OpenAI #GPT5 #Aardvark #Infosec #AI #DevSecOps #VulnerabilityManagement #MachineLearning #CodeSecurity #TechNews

  28. What does “developer-first security” really look like?
    This article from Symbiotic Security unpacks why more alerts ≠ better security.

    At AppSec Village, we believe these convos are key to bridging security + devs.

    symbioticsec.ai/blog/real-conv

    #CodeSecurity #DevSecOps #AI

  29. What does “developer-first security” really look like?
    This article from Symbiotic Security unpacks why more alerts ≠ better security.

    At AppSec Village, we believe these convos are key to bridging security + devs.

    symbioticsec.ai/blog/real-conv

    #CodeSecurity #DevSecOps #AI

  30. 😱 Breaking news: Someone discovered a #webshell and a normal file share an MD5 hash! 🚨 Stop the presses, this changes everything! Meanwhile, #GitHub is busy deploying #AI to write better code while nobody noticed the hash collision between a sandwich and a rock. 🍔🗿
    github.com/phith0n/collision-w #BreakingNews #HashCollision #CodeSecurity #HackerNews #ngated

  31. 😱 Breaking news: Someone discovered a #webshell and a normal file share an MD5 hash! 🚨 Stop the presses, this changes everything! Meanwhile, #GitHub is busy deploying #AI to write better code while nobody noticed the hash collision between a sandwich and a rock. 🍔🗿
    github.com/phith0n/collision-w #BreakingNews #HashCollision #CodeSecurity #HackerNews #ngated

  32. 🚨 OMG! Someone published evil Nx versions! 😱 Quick, panic and run to GitHub's 'sparkly' AI tools that promise to fix everything with a single click! 🤖✨ Because, of course, code security is just one magical AI away from being solved. 🙄
    github.com/nrwl/nx/security/ad #evilNxVersions #GitHub #AITools #codeSecurity #panicMode #techHumor #HackerNews #ngated

  33. AI coding tools are a security hazard. Replit's AI destroyed data; Amazon's Q was weaponized. Risks include vulnerabilities, blind trust, and skill erosion. Urgent need for guardrails & oversight.

    saysomething.hashnode.dev/the-

  34. This article shows how well model inversion reconstructs code and shares vulnerable examples from ChatGPT, CodeGen, and GitHub Copilot. hackernoon.com/model-inversion #codesecurity