Symantec says Warlock operators ran an AV/EDR killer across at least 40 machines in roughly two hours after a suspected SharePoint compromise. The ransomware payloads moved between domain controllers through SYSVOL replication.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence55
China-linked Warlock operators hit at least four organisations through SharePoint flaws in two months, Symantec says. Its report lists six 2026 SharePoint CVEs only as possible additions, and the entry it documents is still older flaws on servers never patched or mitigated.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence55
Microsoft released metadata from 301,026 GitHub Copilot agent sessions, covering 9.3 million LLM calls in one June week. Capacity planners now have real cache and token figures to test against, though the files measure resource use only and cannot show whether the output was any good.
Reality
- Evidence64
- Adoption
- Insufficient
- Hype gap−5
- Incentives45
- Confidence60
Mandiant's findings say the intrusion never reached Checkmarx One or production AWS, and that answers the vendor's question rather than the one a customer has about what a build box pulled in late March.
Publishers:checkmarx.com
Reality
- Evidence38
- Adoption
- Insufficient
- Hype gap+25
- Incentives65
- Confidence45
Imperva found Microsoft's DebugMCP 1.1.4 let a malicious webpage run code on a developer's machine through an unauthenticated port 3001 listener. The fix reached 1.2.0 with no advisory, so finding exposed machines means checking installed extension versions.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence60
Four governments have put a bureau name on the fake-recruiter campaign against software developers, and their alert says the same crews also work as North Korea's remote IT hires, from the same IP addresses.
Perspective Coverage
8 publishers
- Builder
- Builder 34%
- Operator
- Operator 52%
- Investor
- Investor 14%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+5
- Incentives40
- Confidence72
A dev.to writeup traces roughly 3,800 exfiltrated GitHub repositories to one trojanised Nx Console install from the official Marketplace, where the sandbox that would have contained it has been an open feature request since 2018.
Reality
- Evidence42
- Adoption28
- Hype gap+18
- Incentives62
- Confidence45
The Rust Project's crates.io team says attackers posing as recruiters are luring team members and popular crate owners onto video calls that end in a pasted command. In August, one hijacked account shipped malicious crates.
Reality
- Evidence72
- Adoption58
- Hype gap+8
- Incentives40
- Confidence70
OpenSourceMalware counted 4,367 infected repositories across 2,152 GitHub owners in July, and traced one maintainer through five months of advisory, cleanup and reinfection while the trigger sat in editor config.
Publishers:opensourcemalware.com
Reality
- Evidence48
- Adoption62
- Hype gap+30
- Incentives60
- Confidence52
A developer hit no diagnostics in Zed and WebGL-era false errors in VS Code, then wrote a Rust language server that hands each shader to glslang. The diagnostics inherit whatever glslang build it fetches.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+30
- Incentives65
- Confidence45
Microsoft's Defender Experts date the Contagious Interview campaign to December 2022. Its payload lands at the one hiring stage where a candidate is expected to clone and run a stranger's code. The same team tells employers to give staff a non-persistent VM for coding tests.
Reality
- Evidence64
- Adoption35
- Hype gap+8
- Incentives58
- Confidence62
A fresh terminal resolves ffmpeg while the IDE on the same machine says the tool is missing. The difference is the environment block each process got when it was created, and Windows sends no update to a process already running.
Reality
- Evidence76
- Adoption
- Insufficient
- Hype gap−12
- Incentives18
- Confidence70
Seven agencies across four countries tied fake recruiters and take-home coding tasks to eight months of infections and drained cryptocurrency wallets.
Reality
- Evidence62
- Adoption70
- Hype gap+15
- Incentives32
- Confidence52
Developer clients reach a key-protected Azure Functions MCP server by attaching a header; the Claude desktop app has no such field, and the one-click fix still left VS Code holding an invalid_target error from Entra.
Reality
- Evidence54
- Adoption21
- Hype gap−9
- Incentives27
- Confidence56
For the first ninety minutes nobody opens an IDE. A mentor has to approve the team's SPEC.md, and that same file is what Antigravity or Cursor reads once the coding starts. It is worth 35 of the 100 points.
Reality
- Evidence42
- Adoption22
- Hype gap+18
- Incentives62
- Confidence55
GitGuardian argues that credentials and permissions decide how bad an agent incident gets. Checked against the three 2026 disclosures it cites, the argument holds up, and only one of the three involved steering a model.
Reality
- Evidence60
- Adoption45
- Hype gap+15
- Incentives82
- Confidence55
Socket reports no malicious stable release. The exposure sits with teams that resolve dev-* constraints directly, and with anyone who clones the repository and opens it in a VS Code-compatible IDE.
Reality
- Evidence58
- Adoption25
- Hype gap+12
- Incentives75
- Confidence45
Cline's coding agent runs on one engine in four places, licensed Apache 2.0, with a CLI built to run headless inside pipelines and a Node SDK for teams that want to build their own agent on top of it.
Reality
- Evidence38
- Adoption28
- Hype gap+22
- Incentives55
- Confidence34
GitGuardian says the ChainDrop worm reached 444 npm packages by planting a SessionStart hook in Claude Code and a folderOpen task in VS Code, and the publishing credential it steals is used to republish inside the same session.
Reality
- Evidence45
- Adoption55
- Hype gap+22
- Incentives80
- Confidence42
AgentCore Identity now hosts the redirect leg and keeps the tokens, and what you configure in exchange is an OIDC application in your corporate IdP, a service role, and AWS's callback URL inside your GitHub and Slack apps.
Reality
- Evidence62
- Adoption12
- Hype gap+8
- Incentives88
- Confidence55
Earlier coverage
- A misconfigured autoscaling policy watched the host service, not the Istio sidecar that saturated
Build · September 13, 2026 · 1 publisher
- VS Code moves agent sessions out of the editor and publishes the protocol under MIT
Product · August 14, 2026 · 1 publisher
- sampling/createMessage lets an MCP server run its own prompt through your model
Build · September 11, 2026 · 1 publisher
- Unexplained pending pulls showed up an hour before the antivirus found the fake font
Build · September 10, 2026 · 1 publisher
- Lean's reference manual classifies un-reviewed AI proofs as malicious code
Build · September 10, 2026 · 1 publisher
- Prompt injection can rewrite the one-line summary in Claude Code's approval dialog
Build · September 9, 2026 · 1 publisher
- A month testing eight AI coding tools found Cursor's diff-reviewed agent mode the standout
Build · September 9, 2026 · 1 publisher
- Shai-Hulud's third wave printed SAP's npm token straight into a workflow log
Security · September 8, 2026 · 1 publisher
- Microsoft's record 964-CVE Patch Tuesday includes two exploited zero-days
Security · September 8, 2026 · 1 publisher
- A task that passed three times out of three still took nine wrong turns
Build · August 31, 2026 · 1 publisher
- VS Code 1.135 sends an agent's work to a second model for review
Product · August 31, 2026 · 1 publisher
- A code graph caught the login bug sitting three hops and an event bus from the diff
Build · August 30, 2026 · 1 publisher
- A poisoned Nx Console build rode VS Code's auto-update into GitHub's own repositories
Security · August 27, 2026 · 1 publisher
- CLion is moving debug configuration out of the UI and into a JSON file an agent can rewrite
Build · August 27, 2026 · 1 publisher
- A 120-line Figma plugin, and everything the host made you build around it
Build · August 26, 2026 · 1 publisher
- A dropper that runs on folder-open, and why your blocklist never sees it
Build · August 25, 2026 · 1 publisher
- Nine bundled CLIs, zero static links: an OpenSSL CVE becomes a file copy, and the parser is the bill
Build · August 23, 2026 · 1 publisher
- MCP's roadmap fast-tracks five priorities and quietly queues everything else
Build · August 22, 2026 · 1 publisher
- The tray tax: one Windows suite drops Electron for C++ and WebView2
Build · August 21, 2026 · 1 publisher
- An AI reviewer called injectable SQL safe because it could not read the helper
Build · August 19, 2026 · 1 publisher
- Amazon Q executed code from any repo you opened, and it is not the only one
Build · August 19, 2026 · 1 publisher
- Copilot drops the flagship model, and the build record does not follow
Product · August 16, 2026 · 1 publisher
- Buf puts Protobuf diagnostics in the editor, where schema rules actually get obeyed or ignored
Build · August 16, 2026 · 1 publisher
- One MCP command, three JSON shapes, and a failure mode that never errors
Build · August 16, 2026 · 1 publisher
- A session that read "finished" and "still executing" was a slow queue, not a dropped handshake
Build · August 15, 2026 · 1 publisher
- Your shell exports never reach the Claude Code panel, and your gateway logs know it
Build · August 15, 2026 · 1 publisher
- Wrapping a web tool in VS Code: four sandbox rules, and two gaps in the published fix
Build · August 15, 2026 · 1 publisher
- The load average had already peaked: reading 11.08 / 38.69 / 23.59 in the right order
Build · August 15, 2026 · 1 publisher