A high-severity vulnerability (CVE-2026-12957) in Amazon Q Developer for Visual Studio Code allowed attackers to execute arbitrary code and steal AWS credentials by automatically loading malicious MCP server…
JetBrains has issued patches for critical vulnerabilities in JetBrains Hub that could lead to full authentication bypass, account takeover, and privilege escalation. The vulnerabilities, tracked as CVE-2026-56141,…
On August 8, 2026, several significant cybersecurity incidents were reported. A Brazilian public health database exposed 102,215 records without authentication, raising concerns about data privacy. The UNC6671 group…
A vulnerability named GhostApproval has been discovered in six major AI coding assistants, including Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf. This flaw allows…
A survey conducted by Sonar reveals that 96% of software developers doubt the functional correctness of AI-generated code, while only 48% consistently verify such code before committing it. The findings are based on…
Microsoft has released updates to address a critical zero-day vulnerability in Windows Shell, tracked as CVE-2026-21510, which is actively being exploited. This security flaw allows remote attackers to bypass essential…
In December 2025, Adobe released five bulletins addressing 139 unique vulnerabilities as part of its security updates. This follows the November updates, where Adobe addressed 29 unique CVEs across several products.…