2987 related articles

VulX Watch is a security audit tool for AI-generated code that connects read-only to GitHub repos, independently reviews vulnerabilities, and provides line-level evidence for every finding.

OpenAI open-sources Codex Security components, bringing automated security detection to AI code generation. Analysis of its strategic value, developer impact, and the industry shift from capability to security.

OpenAI open-sources Codex Security components, bringing automated security detection to AI code generation. Analysis of its strategic significance and industry impact.

Claude Code was revealed to steganographically mark system prompts under specific conditions, triggering a developer trust crisis. This article analyzes the steganography, Anthropic's tightening China access, and how AI coding tools became a core enterprise security issue.

Anthropic launches Project Glass Wing—its Mythos Preview model found over 10,000 critical infrastructure vulnerabilities in hours, spanning 150 organizations across 15 countries. A deep dive into AI security auditing.

Alibaba has banned employees from using Claude Code company-wide, shifting sharply from encouragement to prohibition. An in-depth look at data security risks, privacy compliance dilemmas, and the domestic AI alternative trend.

Alibaba bans Claude Code over security risks, sparking tech community debate. An in-depth analysis of data leakage risks with cloud AI coding tools and the rise of local AI deployment.

Mozilla research reveals real attack chains targeting AI agent tools like Claude Code: malicious instructions hidden in DNS records bypass code scanning to steal API keys and cloud credentials.

In-depth analysis of Alibaba's comprehensive internal ban on Claude Code: from the hidden-marker controversy and Anthropic's regional-restriction stance to five core questions of enterprise AI coding tool security admission.

Alibaba reportedly plans to ban Claude Code internally over backdoor and data leakage concerns. A deep dive into enterprise AI security, supply chain trust issues, and what it takes for AI tools to win enterprise adoption.

Devin Review adds AI security audit to auto-detect auth bypasses, logic flaws & deep vulnerabilities in every PR, with full remediation from finding to fix.

Vercel's AI coding tool v0 launches Permission Modes with three levels — Ask Every Time, Smart Judgment, and Free Execution — giving developers fine-grained control over AI operations.
Product ReviewsHands-on review of OpenAI Codex Computer Use: step-by-step setup guide, WeChat demo, screenshot-based core principles, and analysis of three major security risks including privacy leakage and current limitations.
Industry InsightsUsing Anthropic's Claude Mythos Preview, Firefox fixed more security bugs in April 2025 than the previous 15 months. Explore how AI code auditing is revolutionizing browser and open-source security.
Deep DivesDeep dive into Claude Code Auto Mode: how the independent Classifier reviews AI operations, three-level graceful degradation prevents system deadlocks, SubAgent triple review with Prompt Injection protection, plus setup and plan requirements.
Deep DivesDeep dive into Cursor's Security Review feature: two AI security agents for PR-level review and codebase vulnerability scanning, enabling shift-left security for enterprise DevSecOps.
Product ReviewsRaptor is an open-source project that transforms Claude Code into an offensive & defensive security AI agent through prompt engineering and multi-layer architecture, enabling red team, blue team, and security research scenarios.

System prompts drive LLM apps but often lack version control and regression testing. Learn how to manage them with versioning, structured separation, testing, and code review.

Deep dive into Pwnd Blaster acoustic attack principles: how speakers and microphones create covert channels to bypass air-gapped systems. Covers attack chain analysis, real-world constraints, and defenses.

After Perplexity's Windows desktop app migrated from standalone to MS Store version, the right-click spell correction menu disappeared. This article analyzes the root causes involving MSIX sandbox mechanisms and offers practical solutions.