home.social

#codesecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #codesecurity, aggregated by home.social.

  1. Cursor's $29.3B code editor marketed Composer 2 as an "in-house" model. A developer found the actual model ID within 24 hours: it was Kimi K2.5, built by Beijing's Moonshot AI. This marks the second undisclosed use of Chinese models in four months, raising questions about transparency when users route proprietary code through these systems.

    #AITransparency #CodeSecurity #TechAccountability

    implicator.ai/opinion-cursor-c

  2. Cursor's $29.3B code editor marketed Composer 2 as an "in-house" model. A developer found the actual model ID within 24 hours: it was Kimi K2.5, built by Beijing's Moonshot AI. This marks the second undisclosed use of Chinese models in four months, raising questions about transparency when users route proprietary code through these systems.

    #AITransparency #CodeSecurity #TechAccountability

    implicator.ai/opinion-cursor-c

  3. 👾 Behold, the breathtaking breakthrough of rendering #graphics at the speed of a caffeinated snail using the legendary micro-teeny-tinygrad! 🎨✨ Apparently, #GitHub has decided we need yet another #AI tool to clutter our already overflowing virtual garages. Who knew code security could be so... miniscule? 🔍🔒
    github.com/quantbagel/gtinygrad #Tools #MicroTinygrad #CodeSecurity #HackerNews #ngated

  4. 🎉 Ah, the KIM-1 turns 50, and what better way to celebrate than a GitHub demo no one asked for, buried under a pile of buzzword salad? 🤖 Just remember, folks: nothing screams "party" like platform #AI and code security lingo. 🎂
    github.com/netzherpes/KIM1-Demo #KIM1 #50thAnniversary #GitHubDemo #BuzzwordSalad #CodeSecurity #HackerNews #ngated

  5. 🎉 Ah, the KIM-1 turns 50, and what better way to celebrate than a GitHub demo no one asked for, buried under a pile of buzzword salad? 🤖 Just remember, folks: nothing screams "party" like platform #AI and code security lingo. 🎂
    github.com/netzherpes/KIM1-Demo #KIM1 #50thAnniversary #GitHubDemo #BuzzwordSalad #CodeSecurity #HackerNews #ngated

  6. 🎉 Ah, the KIM-1 turns 50, and what better way to celebrate than a GitHub demo no one asked for, buried under a pile of buzzword salad? 🤖 Just remember, folks: nothing screams "party" like platform #AI and code security lingo. 🎂
    github.com/netzherpes/KIM1-Demo #KIM1 #50thAnniversary #GitHubDemo #BuzzwordSalad #CodeSecurity #HackerNews #ngated

  7. 🎉 Ah, the KIM-1 turns 50, and what better way to celebrate than a GitHub demo no one asked for, buried under a pile of buzzword salad? 🤖 Just remember, folks: nothing screams "party" like platform #AI and code security lingo. 🎂
    github.com/netzherpes/KIM1-Demo #KIM1 #50thAnniversary #GitHubDemo #BuzzwordSalad #CodeSecurity #HackerNews #ngated

  8. “Noise reduction alone isn’t the goal; accuracy on real risks is.”
    — James Wickett, CEO & Co-founder, DryRun Security

    Why application security needs context at code review - and why intent matters more than alert volume.

    Read more:
    technadu.com/why-application-s

    #AppSec #DevSecOps #CodeSecurity #InfoSec

  9. Đang tìm kiếm mô hình/công cụ để quét và phát hiện mã độc trong dự án mã nguồn mở. Đang cân nhắc Nemotron, GPT-OSS, Qwen Coder hoặc liệu có mô hình điều chỉnh/tập trung chuyên sâu nào khác hỗ trợ? Cần gợi ý từ cộng đồng! #AiAnToan #PhanTichMa #OSS #CodeSecurity #MalwareDetection

    reddit.com/r/LocalLLaMA/commen

  10. AI models often miss IaC security flaws—not because they lack power, but because they lack focus.

    This benchmark shows how accuracy improves when AI gets clear context, tight scope, and an understanding of why a fix works.

    It’s the difference between a quick patch and real remediation.

    At AppSec Village, we appreciate sponsors like Symbiotic AI, who push for true precision in AI-powered security.

    Read the full article →
    symbioticsec.ai/blog/cracking-

    #AI #AIBenchmarks #CodeSecurity #DevSecOps

  11. Developer-first security isn’t buzzwords or “shift left.”

    It’s giving developers context, clarity, and tools that reduce cognitive load—not add more alerts or friction.

    This article breaks down why most approaches fall short, and what real developer-first security looks like in practice.

    At AppSec Village, we’re here for sponsors like Symbiotic Security who actually support how developers work.

    Read it here: symbioticsec.ai/blog/real-conv

    #AI #CodeSecurity #DevSecOps #DeveloperFirstSecurity

  12. Developer-first security isn’t buzzwords or “shift left.”

    It’s giving developers context, clarity, and tools that reduce cognitive load—not add more alerts or friction.

    This article breaks down why most approaches fall short, and what real developer-first security looks like in practice.

    At AppSec Village, we’re here for sponsors like Symbiotic Security who actually support how developers work.

    Read it here: symbioticsec.ai/blog/real-conv

    #AI #CodeSecurity #DevSecOps #DeveloperFirstSecurity

  13. Developer-first security isn’t buzzwords or “shift left.”

    It’s giving developers context, clarity, and tools that reduce cognitive load—not add more alerts or friction.

    This article breaks down why most approaches fall short, and what real developer-first security looks like in practice.

    At AppSec Village, we’re here for sponsors like Symbiotic Security who actually support how developers work.

    Read it here: symbioticsec.ai/blog/real-conv

    #AI #CodeSecurity #DevSecOps #DeveloperFirstSecurity

  14. Developer-first security isn’t buzzwords or “shift left.”

    It’s giving developers context, clarity, and tools that reduce cognitive load—not add more alerts or friction.

    This article breaks down why most approaches fall short, and what real developer-first security looks like in practice.

    At AppSec Village, we’re here for sponsors like Symbiotic Security who actually support how developers work.

    Read it here: symbioticsec.ai/blog/real-conv

    #AI #CodeSecurity #DevSecOps #DeveloperFirstSecurity

  15. 🚨 OH NO! React Server Components can't catch a break! 🎉 Just when you thought it was safe to deploy... surprise! More vulnerabilities! 😱 But hey, at least they're not letting hackers run wild with RCE, just crash your server and peek at your code. 🤦‍♂️ So much for smooth sailing, React team!
    react.dev/blog/2025/12/11/deni #ReactServerComponents #vulnerabilities #ServerCrash #CodeSecurity #HackerNews #HackerNews #ngated

  16. 🚨 OH NO! React Server Components can't catch a break! 🎉 Just when you thought it was safe to deploy... surprise! More vulnerabilities! 😱 But hey, at least they're not letting hackers run wild with RCE, just crash your server and peek at your code. 🤦‍♂️ So much for smooth sailing, React team!
    react.dev/blog/2025/12/11/deni #ReactServerComponents #vulnerabilities #ServerCrash #CodeSecurity #HackerNews #HackerNews #ngated

  17. 🚨 OH NO! React Server Components can't catch a break! 🎉 Just when you thought it was safe to deploy... surprise! More vulnerabilities! 😱 But hey, at least they're not letting hackers run wild with RCE, just crash your server and peek at your code. 🤦‍♂️ So much for smooth sailing, React team!
    react.dev/blog/2025/12/11/deni #ReactServerComponents #vulnerabilities #ServerCrash #CodeSecurity #HackerNews #HackerNews #ngated

  18. 🚨 OH NO! React Server Components can't catch a break! 🎉 Just when you thought it was safe to deploy... surprise! More vulnerabilities! 😱 But hey, at least they're not letting hackers run wild with RCE, just crash your server and peek at your code. 🤦‍♂️ So much for smooth sailing, React team!
    react.dev/blog/2025/12/11/deni #ReactServerComponents #vulnerabilities #ServerCrash #CodeSecurity #HackerNews #HackerNews #ngated

  19. "AI-driven security and spec-first IDEs are revolutionizing software development. Tools like Defender for Cloud and GitHub Advanced Security offer runtime insights, while spec-first tools like Kiro and Spec Kit embed security into code from the start. Faster remediation, better security, and a shift from code-first to intent-first development. "

    saysomething.hashnode.dev/ai-d

  20. OpenAI has launched Aardvark, an autonomous “agentic security researcher” powered by GPT-5.

    It scans codebases for vulnerabilities, validates exploitability in sandboxed environments, and auto-generates potential patches.

    Early reports show 10+ CVEs identified in open-source projects.

    What’s your view - is AI-driven vulnerability research the future of cybersecurity or another layer of risk?

    #CyberSecurity #OpenAI #GPT5 #Aardvark #Infosec #AI #DevSecOps #VulnerabilityManagement #MachineLearning #CodeSecurity #TechNews

  21. What does “developer-first security” really look like?
    This article from Symbiotic Security unpacks why more alerts ≠ better security.

    At AppSec Village, we believe these convos are key to bridging security + devs.

    symbioticsec.ai/blog/real-conv

    #CodeSecurity #DevSecOps #AI

  22. 😱 Breaking news: Someone discovered a #webshell and a normal file share an MD5 hash! 🚨 Stop the presses, this changes everything! Meanwhile, #GitHub is busy deploying #AI to write better code while nobody noticed the hash collision between a sandwich and a rock. 🍔🗿
    github.com/phith0n/collision-w #BreakingNews #HashCollision #CodeSecurity #HackerNews #ngated

  23. 😱 Breaking news: Someone discovered a #webshell and a normal file share an MD5 hash! 🚨 Stop the presses, this changes everything! Meanwhile, #GitHub is busy deploying #AI to write better code while nobody noticed the hash collision between a sandwich and a rock. 🍔🗿
    github.com/phith0n/collision-w #BreakingNews #HashCollision #CodeSecurity #HackerNews #ngated

  24. 😱 Breaking news: Someone discovered a #webshell and a normal file share an MD5 hash! 🚨 Stop the presses, this changes everything! Meanwhile, #GitHub is busy deploying #AI to write better code while nobody noticed the hash collision between a sandwich and a rock. 🍔🗿
    github.com/phith0n/collision-w #BreakingNews #HashCollision #CodeSecurity #HackerNews #ngated

  25. 😱 Breaking news: Someone discovered a #webshell and a normal file share an MD5 hash! 🚨 Stop the presses, this changes everything! Meanwhile, #GitHub is busy deploying #AI to write better code while nobody noticed the hash collision between a sandwich and a rock. 🍔🗿
    github.com/phith0n/collision-w #BreakingNews #HashCollision #CodeSecurity #HackerNews #ngated

  26. 🚨 OMG! Someone published evil Nx versions! 😱 Quick, panic and run to GitHub's 'sparkly' AI tools that promise to fix everything with a single click! 🤖✨ Because, of course, code security is just one magical AI away from being solved. 🙄
    github.com/nrwl/nx/security/ad #evilNxVersions #GitHub #AITools #codeSecurity #panicMode #techHumor #HackerNews #ngated

  27. 🚨 OMG! Someone published evil Nx versions! 😱 Quick, panic and run to GitHub's 'sparkly' AI tools that promise to fix everything with a single click! 🤖✨ Because, of course, code security is just one magical AI away from being solved. 🙄
    github.com/nrwl/nx/security/ad #evilNxVersions #GitHub #AITools #codeSecurity #panicMode #techHumor #HackerNews #ngated

  28. 🚨 OMG! Someone published evil Nx versions! 😱 Quick, panic and run to GitHub's 'sparkly' AI tools that promise to fix everything with a single click! 🤖✨ Because, of course, code security is just one magical AI away from being solved. 🙄
    github.com/nrwl/nx/security/ad #evilNxVersions #GitHub #AITools #codeSecurity #panicMode #techHumor #HackerNews #ngated

  29. 🚨 OMG! Someone published evil Nx versions! 😱 Quick, panic and run to GitHub's 'sparkly' AI tools that promise to fix everything with a single click! 🤖✨ Because, of course, code security is just one magical AI away from being solved. 🙄
    github.com/nrwl/nx/security/ad #evilNxVersions #GitHub #AITools #codeSecurity #panicMode #techHumor #HackerNews #ngated

  30. 🛡️ Vibekit @superagent_ai

    Open-source AI agent security. Features Docker sandbox, secret redaction, access monitoring, and prompt-injection blocking. Safeguards your .env file.

    everydev.ai/tools/vibekit

    #CodeSecurity #AICoding #AgentOps #AppSec #DevTools #OpenSource

  31. AI coding tools are a security hazard. Replit's AI destroyed data; Amazon's Q was weaponized. Risks include vulnerabilities, blind trust, and skill erosion. Urgent need for guardrails & oversight.

    saysomething.hashnode.dev/the-

  32. This article shows how well model inversion reconstructs code and shares vulnerable examples from ChatGPT, CodeGen, and GitHub Copilot. hackernoon.com/model-inversion #codesecurity

  33. This article details code deduplication, prompt transfer, dataset creation, benchmarks, and the effect of sampling temperature on finding vulnerabilities. hackernoon.com/the-art-of-prom #codesecurity

  34. This article shows "secure code" prompts fail on ChatGPT, more examples find more bugs, and the method effectively targets C code vulnerabilities. hackernoon.com/an-analysis-of- #codesecurity

  35. This article details the LLMs used (CodeGen, ChatGPT) and a test finding vulnerabilities in GitHub Copilot using the study's few-shot prompting method. hackernoon.com/llm-details-and #codesecurity

  36. This article discusses prompt transferability and limitations, concluding with a method for finding and benchmarking LLM code vulnerabilities. hackernoon.com/echoes-in-the-c #codesecurity

  37. This article evaluates LLMs like CodeGen/ChatGPT on vulnerable code gen via few-shot prompting, prompt transferability, and a security benchmark. hackernoon.com/experimenting-w #codesecurity

  38. This article proposes few-shot prompting for black-box LLM inversion, generating non-secure prompts to trigger code vulnerabilities via static analysis. hackernoon.com/systematic-disc #codesecurity