AI-Generated Code Security Has Not Improved in a Year
Veracode tested more than a hundred models and found a 56 per cent security pass rate, flat year on year. Coding-special...
ASEAN edition · Tue, 18 Aug 2026 · Signal over noise
AI-curated tech news, ASEAN business intelligence, and cybersecurity updates — written for the region.
Veracode tested more than a hundred models and found a 56 per cent security pass rate, flat year on year. Coding-special...
The AI Trust and Security Consortium launched on 11 August with fifty seats and incidents shared under strict confidenti...
Over 120 organisations have proposed SAFE, a common taxonomy and clock for reporting AI agent security incidents. It bor...
An unencrypted copy of the Firefox release-signing subkey was committed to a private repo. No evidence of misuse, everyo...
Agent Plugins 1.0.0 packages Agent Skills and MCP servers into one portable directory. Everything the specification refu...
Linux 7.2-rc7 is large, and Torvalds says many of the fixes come from review by AI tools. Machine review scales. Maintai...
From 14 August the approval prompt in Claude Code is off by default for Pro, Max and Team accounts. Anthropic says peopl...
Researchers at 1Password's Off-by-1 Labs found that autonomously generated security patches cleanly fixed the vulnerabil...
A permission-approval game logged 409,000 decisions across more than 40,000 runs. Reviewers missed 33.7% of malicious co...
GitHub gave Dependabot a three-day cooldown on 14 July and PyPI began rejecting new files on releases older than 14 days...
CVE-2026-58048 gives an authenticated cPanel user database root privileges. On shared hosting, that reaches databases be...
A self-propagating worm reached the maintainer of keyv and used the credentials it stole to publish infected releases ac...
Five KEV listings in three days: an RMM console, a CI/CD server, a Tomcat cluster channel and an AI workflow builder. No...
CVE-2026-66066 scores 9.5 and needs no authentication. The fix depends on a libvips version many deployments do not have...
npm v12 went generally available on 8 July, flipping install scripts, Git dependencies and remote-URL packages from auto...
On 8 July 2026, the EU General Court dismissed Apple's challenges to its Digital Markets Act gatekeeper designation for...
Cato AI Labs has disclosed DuneSlide — two critical remote-code-execution flaws in Cursor (CVE-2026-50548 and CVE-2026-5...
On 1 July 2026, Cloudflare split AI bot traffic into Search, Agent and Training categories for all customers, including...
GitHub's npm v12, due July 2026, turns three things npm install does automatically today into choices you have to opt in...
Beyond the new Siri, WWDC 2026 gave developers an expanded Foundation Models framework — multimodal prompts and access t...
The Miasma supply-chain attack didn't typosquat or steal an npm token — it hijacked a maintainer's CI pipeline and publi...
NEXTDC officially opened KL1 in Petaling Jaya on 14 May 2026 — an AUD$1 billion facility that holds Peninsular Malaysia'...
Indonesia's sovereign wealth fund INA has formalised a 30% annual cap on digital sector deployment, anchored by a joint...
Microsoft confirmed at Build 2026 in San Francisco that GitHub Copilot will run on Project Polaris — its own mixture-of-...