MikeTrendsTrends right now

search

AI security tools

Trends

  1. 1
    Pi pod lets developers run coding agents in self-hosted sandboxes●Show HN: Pi pod – Run your pi coding agent in sandboxes on your own serverYhnScienceBiology12140 min ago

    A new tool called Pi pod is being shared with developers, letting them run the Pi coding agent inside sandboxed environments on their own servers. The pitch is control and security: instead of relying on third-party infrastructure, teams can isolate agent execution on hardware they manage themselves. Early reaction on Hacker News is positive, with the launch drawing more than a hundred upvotes as developers weigh self-hosting coding agents against managed cloud options.

  2. 2
    Cloudflare releases security audit skill for coding agents●cloudflare/security-audit-skillβ¬’github57611 min ago

    Cloudflare has published an open-source security-audit skill for AI coding agents, available on GitHub under the name security-audit-skill. Written in JavaScript, the tool runs multi-phase security audits and produces machine-readable findings that are independently verified, aiming to make automated code review more trustworthy. Developers are picking it up and discussing how it could fit into agent-based development workflows.

  3. 3
    Meta and Microsoft reportedly curb employee use of Claude AI●Meta and Microsoft take steps to reduce employee usage of Claude AIYhnTechnologyAI26811 min ago

    Meta and Microsoft are reported to have taken steps to limit their employees' use of Anthropic's Claude AI assistant. The move suggests the two tech giants want staff relying on internal or approved AI tools rather than a direct competitor's product. Further details about how the restrictions are enforced have not been made clear.

  4. 4
    Greg Kroah-Hartman on software security in the LLM age●Greg Kroah-Hartman – Security in the LLM Age [video]YhnTechnologyAI3421 h ago

    Greg Kroah-Hartman, the longtime Linux kernel maintainer who leads the stable kernel branch, is featured in a talk on what large language models mean for software security. The discussion covers how LLM tools change the threat landscape for kernel and open-source development, and how maintainers should respond. The talk is drawing attention among developers debating AI's impact on critical infrastructure code.

  5. 5
    Google freezes open-source bug bounty program amid flood of AI slop●Google freezes open-source bug bounty program amid flood of invalid AI slopYhnLifeFood131 h ago

    Google has suspended part of its Open Source Vulnerability Reward Program, ending reward submissions for product vulnerabilities from October 1, citing an influx of invalid, low-quality bug reports generated by AI tools. The flood of junk submissions has made it impossible to sort genuine vulnerabilities from automated noise, forcing the company to pause the program. The move highlights a growing problem: AI-generated spam overwhelming security research channels meant for human researchers.

  6. 6
    Replit Previews Secure Windows Desktop App with AI Sandboxes●Replit Previews Secure Desktop App for Windows with AI Sandboxes𝕏xSE7938 min ago

    Replit has given a first look at a secure desktop application for Windows that runs AI workloads in isolated sandboxes. The preview highlights stronger safety and local performance for coding with AI assistance directly on the desktop. Developers are discussing what the sandboxing approach means for security and whether the app will reduce reliance on the browser-based Replit workspace.

  7. 7
    Malicious web pages could trick GitHub Copilot CLI into leaking secrets●Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets https:// sh.iMmastodonTechnology31 h ago

    Security discussions are highlighting a prompt injection risk in GitHub Copilot CLI: carefully crafted web pages containing hidden 'zombie' instructions could manipulate the coding assistant into revealing secrets or performing unintended actions when it processes content from those pages. Commenters warn that developers using AI tools in terminals may be exposed if the tool cannot distinguish trusted instructions from malicious text embedded in the material it reads.

  8. 8
    CrowdStrike Monetizes AI Cybersecurity Complexitiesβ–ΌCrowdStrike (CRWD) is Monetizing the Complexities of the AI Cybersecurity Environmentβœ‰newsEnvironment1 h ago

    CrowdStrike (CRWD) is being highlighted for its strategy of turning the growing complexities of AI-driven cybersecurity into revenue opportunities. The company, known for its cloud-based endpoint security platform, is positioning itself to benefit as enterprises confront new AI-related threats and seek advanced protection tools, according to a financial news report.

  9. 9
    Developers ask which AI models handle code security reviews●Ask HN: Which frontier model can do code security reviewsYhnEnvironmentWeather659 min ago

    A question on Hacker News is asking which frontier AI models are capable of performing code security reviews. The discussion seeks recommendations on which large language models can reliably audit code for vulnerabilities. With few replies so far, the thread reflects a broader interest among developers in using AI tools for security analysis.

  10. 10
    Open-source AI Agent Gateway keeps credentials out of configsβ–ΌAI Agent Gateway: Open-source tool keeps credentials out of agent configsβœ‰newsTechnologySoftware1 h ago

    A new open-source tool called AI Agent Gateway has been released, designed to keep credentials out of AI agent configurations. The gateway handles authentication separately so agents never store sensitive keys directly in their configs. Coverage highlights it as a practical security improvement for teams deploying AI agents, where hard-coded credentials have become a common risk.

  11. 11
    Prompt Injection Threat Now Targets AI Coding Agents●When people hear "prompt injection", they picture a chatbot being tricked by a clever user... # ai # security # devops #MmastodonTechnologySoftware31 h ago

    Security discussions are warning that prompt injection attacks are moving beyond chatbots to AI coding agents. The concern is that malicious instructions can be hidden in everyday development files, with a README alone potentially enough to manipulate an agent into harmful actions. Developers are being urged to treat repository content as untrusted input as AI tools increasingly read and execute instructions from codebases.

  12. 12
    AWS launches Strands Box sandboxes for AI agents●Introducing Strands Box: AI agent sandboxes powered by Dogwoodβœ‰newsTechnologySoftware1 h ago

    Amazon Web Services has introduced Strands Box, a tool for running AI agents in isolated sandboxes, built on its Dogwood technology. The sandboxes give agents a controlled environment to execute code and tasks safely. The announcement adds to AWS's growing Strands agent toolkit as companies look for secure ways to deploy autonomous AI systems in production.

  13. 13
    Pentagon launches AI pilot for managing sensitive information●Pentagon launches pilot program that will use AI to manage sensitive informationβœ‰newsTechnologyAI1 h ago

    The Pentagon has started a pilot program that will use artificial intelligence to handle and manage sensitive information within the US Department of Defense. The initiative, reported by DefenseScoop, signals the Pentagon's growing interest in applying AI tools to core administrative and data-management functions. The news is drawing attention because of the obvious security implications of letting AI systems handle classified or sensitive government material.

  14. 14
    Free software community clashes over AI-written GPL code●GPL apps/distros should not be using AI. GPL is not compatible with the ToS of these ai-generating code companies. It waMmastodonTechnologyAI01 h ago

    Free software advocates are arguing that GPL-licensed projects should not use AI code-generation tools, because the terms of service of services like Codex and Cursor conflict with the GPL's licensing requirements. The debate intensified after criticism of Debian embracing AI-generated code. Some argue AI should only be used for tasks like finding security vulnerabilities, never for writing code in GPL projects.

  15. 15

    Amazon Web Services has published the first part of a technical guide on building an AI vulnerability harness, a framework for testing AI systems for security weaknesses. The article walks readers through setting up tooling to probe machine learning models and AI applications for exploitable flaws. It is aimed at security engineers and developers who are adapting traditional penetration testing practices to AI systems, and further parts of the series are expected.

  16. 16

    Meta and Microsoft are reportedly restricting employees from using Anthropic's Claude AI tools for their work. The move, reported by tech news outlets, underscores growing caution among major AI developers about relying on rival companies' chatbots and coding assistants, likely over concerns about data security, confidentiality and competitive sensitivity. The story is drawing attention in tech circles as competition between AI providers intensifies.

  17. 17
    Temporal hires Oso team to build AI agent securityβ–ΌFast-growing Temporal hires team from NYC startup Oso to build AI agent security controlsβœ‰newsBusinessStartups4 h ago

    Temporal Technologies, the fast-growing Seattle-area workflow orchestration company, has hired the team from New York security startup Oso to develop security controls for AI agents. The acqui-hire reflects growing industry concern over how autonomous AI systems are authenticated and governed. Oso, known for open-source authorization tooling, will wind down as its engineers join Temporal's security efforts.

Repos