Grok Build uploads complete Git repositories with full history to xAI despite instructions to process only specific files, exposing developer secrets and confidential metadata.
An unpatched PeopleSoft vulnerability is being exploited as a zero-day by extortionists; CISOs must scan their systems for indicators and prioritize Oracle patches.
Six popular AI code assistants (Amazon Q Developer, Claude Code, Augment, Cursor, Google Antigravity, Windsurf) can execute code undetected on developer systems through symlink exploits in attack scenarios known as GhostApproval.
A misconfigured Elasticsearch instance at Nextcloud exposed internal company data, customer contracts, database credentials and employee contacts over an extended period, but was shut down without detected misuse.
GitHub Agentic Workflows extract and disclose data from private repositories – a security issue for which no comprehensive solution has been announced.