#codeSecurity

N-gated Hacker Newsngate
2026-01-22

👾 Behold, the breathtaking breakthrough of rendering at the speed of a caffeinated snail using the legendary micro-teeny-tinygrad! 🎨✨ Apparently, has decided we need yet another tool to clutter our already overflowing virtual garages. Who knew code security could be so... miniscule? 🔍🔒
github.com/quantbagel/gtinygrad

N-gated Hacker Newsngate
2026-01-11

🎉 Ah, the KIM-1 turns 50, and what better way to celebrate than a GitHub demo no one asked for, buried under a pile of buzzword salad? 🤖 Just remember, folks: nothing screams "party" like platform and code security lingo. 🎂
github.com/netzherpes/KIM1-Demo

2025-12-30

“Noise reduction alone isn’t the goal; accuracy on real risks is.”
— James Wickett, CEO & Co-founder, DryRun Security

Why application security needs context at code review - and why intent matters more than alert volume.

Read more:
technadu.com/why-application-s

#AppSec #DevSecOps #CodeSecurity #InfoSec

Why Application Security Needs Context at Code Review, Not More Alerts
2025-12-22

Đang tìm kiếm mô hình/công cụ để quét và phát hiện mã độc trong dự án mã nguồn mở. Đang cân nhắc Nemotron, GPT-OSS, Qwen Coder hoặc liệu có mô hình điều chỉnh/tập trung chuyên sâu nào khác hỗ trợ? Cần gợi ý từ cộng đồng! #AiAnToan #PhanTichMa #OSS #CodeSecurity #MalwareDetection

reddit.com/r/LocalLLaMA/commen

2025-12-18

AI models often miss IaC security flaws—not because they lack power, but because they lack focus.

This benchmark shows how accuracy improves when AI gets clear context, tight scope, and an understanding of why a fix works.

It’s the difference between a quick patch and real remediation.

At AppSec Village, we appreciate sponsors like Symbiotic AI, who push for true precision in AI-powered security.

Read the full article →
symbioticsec.ai/blog/cracking-

#AI #AIBenchmarks #CodeSecurity #DevSecOps

2025-12-17

Developer-first security isn’t buzzwords or “shift left.”

It’s giving developers context, clarity, and tools that reduce cognitive load—not add more alerts or friction.

This article breaks down why most approaches fall short, and what real developer-first security looks like in practice.

At AppSec Village, we’re here for sponsors like Symbiotic Security who actually support how developers work.

Read it here: symbioticsec.ai/blog/real-conv

#AI #CodeSecurity #DevSecOps #DeveloperFirstSecurity

N-gated Hacker Newsngate
2025-12-11

🚨 OH NO! React Server Components can't catch a break! 🎉 Just when you thought it was safe to deploy... surprise! More vulnerabilities! 😱 But hey, at least they're not letting hackers run wild with RCE, just crash your server and peek at your code. 🤦‍♂️ So much for smooth sailing, React team!
react.dev/blog/2025/12/11/deni

SPTRALsptral
2025-12-04

Una vulnerabilidad crítica en GitHub Actions permitía a atacantes saltarse restricciones de seguridad en repositorios privados. Asegúrate de que tus workflows no usen expresiones dinámicas no confiables. La actualización es crucial para proteger tu código.

2025-11-27

"AI-driven security and spec-first IDEs are revolutionizing software development. Tools like Defender for Cloud and GitHub Advanced Security offer runtime insights, while spec-first tools like Kiro and Spec Kit embed security into code from the start. Faster remediation, better security, and a shift from code-first to intent-first development. #AIInnovation #DevSecOps #SpecFirst #CodeSecurity #SoftwareEngineering"

saysomething.hashnode.dev/ai-d

2025-11-01

OpenAI has launched Aardvark, an autonomous “agentic security researcher” powered by GPT-5.

It scans codebases for vulnerabilities, validates exploitability in sandboxed environments, and auto-generates potential patches.

Early reports show 10+ CVEs identified in open-source projects.

What’s your view - is AI-driven vulnerability research the future of cybersecurity or another layer of risk?

#CyberSecurity #OpenAI #GPT5 #Aardvark #Infosec #AI #DevSecOps #VulnerabilityManagement #MachineLearning #CodeSecurity #TechNews

OpenAI Unveils Aardvark: GPT-5 Agent That Finds and Fixes Code Flaws Automatically
2025-10-20

What does “developer-first security” really look like?
This article from Symbiotic Security unpacks why more alerts ≠ better security.

At AppSec Village, we believe these convos are key to bridging security + devs.

symbioticsec.ai/blog/real-conv

#CodeSecurity #DevSecOps #AI

2025-10-10

Codoki.ai báo cáo kết quả ấn tượng: trong 3 tuần, 500 lượt đăng ký và phát hiện 820 lỗ hổng bảo mật trong mã nguồn do AI tạo ra. Mục tiêu của Codoki là đảm bảo an toàn, bảo mật và độ tin cậy cho mã AI, trở thành "cổng chất lượng" giúp dev tạo code sạch hơn.

#Codoki #AI #Security #CodeSecurity #Vulnerability #PhátHiệnLỗHổng #BảoMậtMãNguồn #AIcode #CôngNghệ #TechNews #DevTools

reddit.com/r/programming/comme

2025-10-06

Google DeepMind ra mắt Codemender, tác nhân AI mới về bảo mật mã nguồn. Codemender tự động tìm và sửa các lỗ hổng bảo mật, đã gửi 72 bản vá chất lượng cao cho các dự án mã nguồn mở lớn. Sắp có mặt công chúng!
#Codemender #AI #CodeSecurity #GoogleDeepMind #BảoMậtMãNguồn #TríTuệNhânTạo

reddit.com/r/singularity/comme

N-gated Hacker Newsngate
2025-09-24

😱 Breaking news: Someone discovered a and a normal file share an MD5 hash! 🚨 Stop the presses, this changes everything! Meanwhile, is busy deploying to write better code while nobody noticed the hash collision between a sandwich and a rock. 🍔🗿
github.com/phith0n/collision-w

If you train ML models, they can learn to write more secure code. But the quality of the training data is only as good as your AppSec tooling. #AICoding #SecureDevelopment #CodeSecurity #SoftwareDevelopment
jpmellojr.blogspot.com/2025/09

N-gated Hacker Newsngate
2025-08-27

🚨 OMG! Someone published evil Nx versions! 😱 Quick, panic and run to GitHub's 'sparkly' AI tools that promise to fix everything with a single click! 🤖✨ Because, of course, code security is just one magical AI away from being solved. 🙄
github.com/nrwl/nx/security/ad

EveryDev AIEveryDevAI
2025-08-16

🛡️ Vibekit @superagent_ai

Open-source AI agent security. Features Docker sandbox, secret redaction, access monitoring, and prompt-injection blocking. Safeguards your .env file.

everydev.ai/tools/vibekit

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst