software development

Microsoft’s Project Zenith puts large AI models directly on developer PCs

Microsoft’s Project Zenith puts large AI models directly on developer PCs 2026-09-08 at 07:30 By Anamarija Pogorelec Microsoft’s Project Zenith is a ready-to-code Windows 11 experience for developer-class PCs capable of running AI models with more than 30 billion parameters locally without relying on metered cloud tokens. Designed for systems with at least 64 GB […]

Microsoft’s Project Zenith puts large AI models directly on developer PCs Read More »

CISA review makes the case for eliminating vulnerability classes

CISA review makes the case for eliminating vulnerability classes 2026-09-01 at 18:23 By Zeljka Zorz For years, the security industry has treated vulnerabilities as an endless queue of individual fixes. A recent CISA review argues that this is precisely why attackers keep winning. The solution to this problem, they believe, is eliminating entire categories of […]

CISA review makes the case for eliminating vulnerability classes Read More »

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) 2026-08-26 at 13:59 By Zeljka Zorz Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The KEV entry does not contain or point to details […]

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) Read More »

Google’s $10,000 refund test shows why AI agents need zero trust

Google’s $10,000 refund test shows why AI agents need zero trust 2026-08-18 at 14:49 By Anamarija Pogorelec Google’s open-source autonomous Customer Support & Returns Agent, built using the Agent Development Kit (ADK) and Gemini, demonstrates how developers can apply zero-trust security principles to AI agents that interact with sensitive systems and take real-world actions. The […]

Google’s $10,000 refund test shows why AI agents need zero trust Read More »

Microsoft shortens NuGet API key lifetime to improve supply chain security

Microsoft shortens NuGet API key lifetime to improve supply chain security 2026-08-04 at 11:30 By Anamarija Pogorelec Microsoft is reducing the lifetime of new NuGet.org API keys from 365 days to 30 days starting August 17, 2026, to improve the security of NuGet, its package repository for .NET developers. API keys created before August 17 […]

Microsoft shortens NuGet API key lifetime to improve supply chain security Read More »

CISA lays out new guidance for using open-source software

CISA lays out new guidance for using open-source software 2026-08-03 at 14:53 By Anamarija Pogorelec The US Cybersecurity and Infrastructure Security Agency (CISA) has published the Open Source Software: Security Principles and Practices guide, which provides federal agencies with recommendations for managing the security of open source software, contributing to OSS projects, and evaluating open […]

CISA lays out new guidance for using open-source software Read More »

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077) 2026-07-28 at 14:04 By Zeljka Zorz JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon as possible. “For those who are unable to do so, we have released a security patch plugin,” noted Daniel Gallo, […]

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077) Read More »

AI took more than junior developer jobs and the bill comes later

AI took more than junior developer jobs and the bill comes later 2026-07-28 at 08:30 By Sinisa Markovic A ticket comes in for a small bug fix. Hand it to the junior on your team and you wait a day, review something that half works, and sit down to explain what went wrong. Describe it […]

AI took more than junior developer jobs and the bill comes later Read More »

GitHub revamps bug bounty program with new VIP tier, payout changes

GitHub revamps bug bounty program with new VIP tier, payout changes 2026-07-23 at 11:35 By Anamarija Pogorelec GitHub is changing its bug bounty program to reward higher-quality vulnerability reports and reduce low-effort submissions, including AI-generated reports. The changes will take effect on July 27, 2026. Reports submitted before that date will be honored under the […]

GitHub revamps bug bounty program with new VIP tier, payout changes Read More »

Small teams are the heaviest users of AI coding agents

Small teams are the heaviest users of AI coding agents 2026-07-22 at 09:00 By Sinisa Markovic The pull request arrives with the tests already run and the description already written, the work of an agent that handled the whole thing on its own. Somebody still has to read it. On GitHub that somebody is usually […]

Small teams are the heaviest users of AI coding agents Read More »

Nearly half of open-source AI projects never reach production

Nearly half of open-source AI projects never reach production 2026-07-20 at 07:00 By Anamarija Pogorelec Open models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State of Open Source AI 2026 identifies deployment, governance and operational tooling as persistent obstacles as […]

Nearly half of open-source AI projects never reach production Read More »

GitHub’s new tool helps prevent costly open-source license violations

GitHub’s new tool helps prevent costly open-source license violations 2026-07-02 at 07:00 By Anamarija Pogorelec GitHub’s Open Source Program Office (OSPO) uses the new GitHub License Compliance feature, now in public preview, to manage thousands of open-source dependencies and identify dependencies whose licenses require review. The feature is available to GitHub Advanced Security customers and […]

GitHub’s new tool helps prevent costly open-source license violations Read More »

Mozilla warns of indirect prompt injection risk in AI coding agents

Mozilla warns of indirect prompt injection risk in AI coding agents 2026-06-29 at 13:48 By Zeljka Zorz A malicious GitHub repository can silently compromise a developer’s machine without containing a single line of malicious code, security researchers at Mozilla’s Zero Day Investigative Network (0DIN) warned. The attack The proof-of-concept attack targets AI-powered coding agents such […]

Mozilla warns of indirect prompt injection risk in AI coding agents Read More »

Critical open-source projects get a new security framework

Critical open-source projects get a new security framework 2026-06-26 at 14:41 By Anamarija Pogorelec Open source software projects are getting a new framework for handling security vulnerabilities as AI shortens the time between flaw discovery and exploitation. The Linux Foundation has launched Akrites, an industry initiative that brings together technology companies, financial institutions, security vendors, […]

Critical open-source projects get a new security framework Read More »

Mystery hackers use novel SharkLoader dropper against governments, software devs

Mystery hackers use novel SharkLoader dropper against governments, software devs 2026-06-26 at 12:13 By Zeljka Zorz Kaspersky researchers have uncovered a previously unknown cyberattack campaign that has compromised government organizations and software development companies in multiple countries. They first stumbled onto the campaign while investigating an attack on a diplomatic organization in Indonesia. What initially […]

Mystery hackers use novel SharkLoader dropper against governments, software devs Read More »

Google sets timeline for Android developer verification enforcement

Google sets timeline for Android developer verification enforcement 2026-06-19 at 12:10 By Anamarija Pogorelec Android’s developer verification protections will take effect on September 30, 2026, starting with users in Brazil, Indonesia, Singapore, and Thailand. Developers distributing apps through participating stores in those markets must complete the verification process by the deadline. Google Play, HONOR App […]

Google sets timeline for Android developer verification enforcement Read More »

What’s new in Android 17? Anti-theft tools, scam detection, and parental controls

What’s new in Android 17? Anti-theft tools, scam detection, and parental controls 2026-06-17 at 13:40 By Anamarija Pogorelec The Android 17 rollout has started for supported Pixel devices, delivering new security and privacy capabilities before expanding to other devices later this year. Security and privacy updates Google has improved location privacy features so users can […]

What’s new in Android 17? Anti-theft tools, scam detection, and parental controls Read More »

Software supply chains are heading for a transparency test

Software supply chains are heading for a transparency test 2026-06-16 at 12:24 By Anamarija Pogorelec Software supply chain visibility is becoming part of product security work as the EU Cyber Resilience Act (CRA) moves toward application in December 2027. ENISA’s SBOM Adoption State of Play 2026 shows organizations preparing for CRA obligations through SBOM tooling, […]

Software supply chains are heading for a transparency test Read More »

Claude now reviews and fixes vulnerabilities as you write code

Claude now reviews and fixes vulnerabilities as you write code 2026-05-27 at 16:37 By Sinisa Markovic Anthropic introduced a security-guidance plugin for Claude Code that reviews code changes for common vulnerabilities and helps Claude identify and fix issues during the same development session. The company says the plugin is designed to catch issues such as […]

Claude now reviews and fixes vulnerabilities as you write code Read More »

CVE Lite CLI: Open-source dependency vulnerability scanner

CVE Lite CLI: Open-source dependency vulnerability scanner 2026-05-20 at 09:34 By Mirko Zorz Dependency vulnerability scanning in JavaScript and TypeScript projects has long sat at the end of the development pipeline. Pull requests get opened, continuous integration runs, and a security scanner returns a list of CVE identifiers that developers then have to triage hours […]

CVE Lite CLI: Open-source dependency vulnerability scanner Read More »

Scroll to Top