AI is changing the way software is being developed. From generating code, helping developers make sense of new frameworks, reviewing pull requests, and even suggesting solutions for existing vulnerabilities, AI is playing an increasingly active role in the software development process. There is an upside here, too. AI is speeding up development, eliminating redundant efforts, and helping organisations fix problems faster. It also raises serious questions about the quality of code, its security, accountability, and trust. When an AI writes or patches the code, who will ensure that it is indeed secure? And, are the current application security practices adequate…
Kirsten Doyle
Security researchers at Oasis Security have disclosed a vulnerability in Claude Desktop that could allow attackers to execute hidden prompts, access local files, exfiltrate conversation history, or execute code with a single click on a malicious link. The vulnerability, dubbed PromptFiction, affects the way Claude Desktop handled claude:// links. According to the researchers, clicking one of these links caused the application to automatically open, import a prompt from the URL, and immediately submit it without displaying the full prompt or requiring user approval. Anthropic addressed the issue in Claude Desktop version 1.1.2321. Hidden instructions Oasis Security demonstrated the attack using…
Russian state-sponsored actors are compromising poorly secured routers and networking devices around the world, with critical infrastructure organisations among the primary targets, reveals a new joint cybersecurity advisory from 20 government agencies. The advisory attributes the activity to cyber actors associated with the Russian Federal Security Service (FSB) Center 16, saying the group continues to exploit “poorly configured and vulnerable networking devices worldwide,” opportunistically targeting organisations across multiple critical infrastructure sectors. According to the advisory, communications, defence, energy, financial services, government, and healthcare organisations face the greatest risk. The campaign is being tracked across the cybersecurity industry under several names,…
Americans are becoming more effective at avoiding spam calls and texts, but new research suggests that the strategy comes with an unexpected cost. A new survey of 1,000 Americans from privacy company Cloaked, revealed that two-thirds of respondents have missed an important phone call because they ignored an unknown number. One in three have missed a call from a doctor, hospital, or healthcare provider, while others report missing calls from employers, pharmacies, financial institutions, government agencies, and even family emergencies. The findings come at a time when cybercrime losses have hit a new all-time high. According to the FBI’s Internet…
Security researchers at Sysdig have documented what they believe is the first documented case of an AI agent running a ransomware operation from end to end. Dubbed JADEPUFFER, the operation used a large language model (LLM) to automate an attack that began with the exploitation of an internet-facing Langflow instance and ended in destructive database extortion. Sysdig’s research describes an AI-driven campaign that adapted to failures, harvested credentials, searched for sensitive data, moved toward its intended target, and attacked a production database server. The attackers initially exploited CVE-2025-3248, a missing-authentication vulnerability in Langflow’s code validation endpoint that allows unauthenticated remote…
AI can generate code faster than most software organizations can absorb it. This should be a productivity breakthrough, but it also exposes a larger problem: many of the processes surrounding software delivery still happen at human speed. A new white paper from code4thought looks at what happens when AI changes how quickly teams write software, and what software engineering produces, how organizations govern it, and where engineers add the most value. AI-Assisted Software Engineering: The New Delivery Paradox pulls from six in-depth conversations covering security, product engineering, academic research, regulated industry, retail banking, and AI assurance. The expert contributors do…
A supply chain attack targeting Klue, a competitive intelligence platform, has lead to the theft of Salesforce data from multiple entities, including several cybersecurity vendors. Klue disclosed that threat actors had gained unauthorized access to part of its integration infrastructure in June after compromising a legacy credential linked to a backend system. “Our investigation determined that an attacker gained access through a compromised legacy credential associated with an integration service. The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce,” Klue said. According to incident investigations published by Huntress and other…
AI-powered attacks are the biggest cybersecurity concern among security professionals. Forty-one percent identified AI-powered attacks at scale as their biggest security concern, nearly double the number citing supply chain risk (21%) or unknown threats (21%). AI-driven threats and what security professionals are doing about them is also the top concern for nearly one in three boards (32%). These were some of the findings of new research conducted by Filigran during Infosecurity Europe 2026. A new phase of threat-informed defence The survey of 168 cybersecurity professionals across various industry sectors, suggest that organisations are entering a new phase of threat-informed defence,…
Oracle has issued a security alert to customers about a critical vulnerability affecting PeopleSoft environments after the notorious threat actor ShinyHunters claimed it used a previously unknown flaw to compromise over 100 entities. The vulnerability CVE-2026-35273 is in Oracle PeopleSoft PeopleTools, and has a CVSS score of 9.8/10. “Oracle PeopleSoft Enterprise Applications customers may also be affected by this vulnerability. This vulnerability is remotely exploitable without authentication. If successfully exploited, this vulnerability may result in remote code execution,” the alert read. ShinyHunters said they exploited a zero-day vulnerability in Oracle PeopleSoft systems to gain access to customer environments and steal…
AI-supported coding has progressed from experimental to the norm in organizations, yet technical debt, security risks, and costs could be piling up much faster than anyone realizes. This is one of the key takeaways from the Software Improvement Group (SIG) 2026 State of Software report, which analyzed more than 30,000 software systems and more than 400 billion lines of code. In other words, even though artificial intelligence is helping businesses to develop software more rapidly, software governance and quality management processes lag behind. The report revealed that 90% of IT workers currently use AI on their jobs, with AI-produced code…
