Reports
AI-generated structured vendor updates
CrowdStrike Unveils SANDWORM_MODE Worm Targeting AI Coding Environments
CrowdStrike uncovers SANDWORM_MODE, a sophisticated npm worm targeting AI coding environments. It steals credentials and crypto keys, propagates via abused credentials, signaling a shift in supply chain attacks towards AI development tools.
亚马逊CloudWatch发布Coding Agent Insights监控AI编码工具
...
Google Begins Gemini 4 Pre-training with 4M+ Context and Monthly Releases
Alphabet confirms start of largest pre-training run for Gemini 4, featuring 4M+ context and native multimodality with near-monthly releases. 2026 capex raised to $195-205B, Google Cloud Q2 up 82%, signaling full-stack AI acceleration.
CrowdStrike Integrates Claude Compliance API, Bringing AI Agent Monitoring into SOC
CrowdStrike integrates Anthropic's Claude Compliance API into its Falcon platform, enabling unified monitoring of Claude AI activities alongside endpoint, identity, and cloud telemetry. This formalizes AI agent security as a standard SOC function, reflecting the industry-wide shift of security budgets towards specialized vendors.
MemGhost Attack: Persistent False Memory Injection in AI Agents via Email
Researchers unveil MemGhost, a stealth memory injection attack that plants persistent false memories into AI agents via a single email without user notification. It exploits the persistent memory feature, highlighting critical security gaps and driving demand for memory auditing.
SANS Identifies Distributed Scanning of MCP Servers and AI Assistant Configs
SANS Internet Storm Center reports systematic scanning of MCP servers, AI assistant configs, and local LLM endpoints. 49 IPs targeted MCP handshakes, exploiting CVEs in MCP SDKs, signaling AI infrastructure as a new attack vector.
GhostApproval Vuln Exposes Systemic AI Coding Tool Flaw: Symlink Bypass in Human Review
Wiz Research discloses GhostApproval vulnerability affecting six major AI coding tools (Claude Code, Codex, Cursor, Amazon Q, Antigravity). Attackers use symlinks to bypass human review, achieving persistent remote access. The flaw reveals fundamental UI-level security gaps in Human-in-the-Loop mechanisms as agent permissions expand, requiring a redesign of confirmation workflows.
Google Antigravity 2.0 Replaces IDE with AI Agents, Forces Gemini CLI Migration
Google launches Antigravity 2.0, a revolutionary AI coding platform with desktop app, CLI, SDK, and Managed Agents API. It forces migration from Gemini CLI to Antigravity CLI, introduces Gemini Spark personal AI agent running on Google Cloud VM, and upgrades coding assistance from editor feature to software labor operating system.
Google Launches Gemini API Docs MCP & Agent Skills for AI Coding Agents
Google introduces Gemini API Docs MCP protocol and Agent Skills toolkit, enabling real-time access to updated API documentation and injecting best-practice patterns to resolve outdated code generation. Combined usage achieves 96.3% pass rate with 63% fewer tokens per correct answer.
OpenAI Partners with PNNL on Government Compliance AI Coding Benchmark
OpenAI partners with PNNL to launch DraftNEPABench, a benchmark evaluating AI coding agents' effectiveness in federal environmental permitting documentation. Focused on NEPA compliance, initial results show 15% time reduction in drafting.