Anthropic Expands AI Bug Hunting Program

In just eight weeks, Cisco's AI-powered bug hunting program scanned a staggering 1.8 billion lines of code, a task that would have taken their top security team a whopping eight years to complete. This groundbreaking feat showcases the incredible potential of AI-driven cybersecurity solutions.

https://osintsights.com/anthropic-expands-ai-bug-hunting-program?utm_source=mastodon&utm_medium=social

#AiBugHunting #ArtificialIntelligence #VulnerabilityScanning #SecureCoding #EmergingThreats

Anthropic Expands AI Bug Hunting Program

Discover how Anthropic's AI bug hunting program helps Cisco scan 1.8 billion lines of code quickly and efficiently - learn more about AI-powered vulnerability detection now.

OSINTSights

Ich möchte euch auf ein wichtiges Thema aufmerksam machen: Sicherheitslücken in Go, der von Google entwickelten Programmiersprache! Hier sind die relevanten Informationen:

* Go-Team hat neue Versionen veröffentlicht, die die Schwachstellen beheben
* Nutzer sollten ihre Installationen auf die aktuellen Updates migrieren, um Angriffe zu verhindern
* Go-Team reagiert gezielt auf Sicherheitsprobleme
#Go #Sicherheit #DecentralizedDevelopment #SecureCoding

🔗 https://news.google.com/rss/articles/CBMipgFBVV95cUxOeF9uelRzVUFhZHdzbVhkd1JJbjNHRVVwcmFFSTRmdEY4MFRhYlJCLXl1RXltZF9RZU9BTUF3OE5tLWprb25KTjItbnprNWxDT2JzN2hQZU9tb3N6bjhyQW5BVWRkeEYyWk1GZGhmZTJDaWlRTFc3WFRnN3FBYnNnbDNOS1BxU2dEUmVkM1VjZG5WZlJWeWJPSExCTlpEbFY1OHFVejJR?oc=5

Before you continue

Fake Claude Code installer campaigns are abusing trusted developer workflows instead of exploiting software vulnerabilities.
Rhys Downing of Ontinue explains how attackers used fake documentation pages, modified install commands, PowerShell loaders, and browser compromise techniques to steal credentials and establish persistence.

“Developers are becoming a preferred target because they sit at the intersection of trust and access.”

Read more:
https://www.technadu.com/copy-paste-compromise-why-developer-workflows-need-new-guardrails/628593/

#Cybersecurity #ThreatResearch #Developers #ApplicationSecurity #Ontinue #SecureCoding

RE: https://infosec.exchange/@SheHacksPurple/116637531032335169

Join @SheHacksPurple for her live book stream "Alice and Bob learn secure coding" on June 3 with special guest @ScottHelme

#infosec #development #softwaredevelopment #securecoding

Most developers are trained to write code — but senior engineers are defined by how well they can read and understand it.

The infographic breaks down why code comprehension is becoming the real differentiator in modern software systems.

Cross posted in LinkedIn:
https://www.linkedin.com/feed/update/activity:7461389515111170048

#SecureCoding #CodeReview #AIinSoftware #EngineeringLeadership

Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised | Wiz Blog

Detect and mitigate malicious npm packages linked to the latest Mini Shai-Hulud supply chain campaign targeting high-value developer tooling.

wiz.io

Do it today, please. Tell your team. Watch the full 60 seconds.

Video link: https://twp.ai/4hpg2D

#AppSec #SupplyChainSecurity #DevSecOps #SecureCoding #npm
2/2

Emergency DevSec Station drop: NPM Worm in the Wild

YouTube

How we reshape the fallout, is up to us.

But, there will be monsters.

There always are.

#secureCoding #humanism

Do it today, please. Tell your team. Watch the full 60 seconds.

Video link: https://twp.ai/4hpWKl

#AppSec #SupplyChainSecurity #DevSecOps #SecureCoding #npm
2/2

Emergency DevSec Station drop: NPM Worm in the Wild

YouTube