AI models do not if legal or not!

AI models do not if legal or not!

An AI agents hacks a subscription system to achieve the goal it has been assigned: https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986
Does it mean that AI models are not aware of the legal barriers ?
And as they now know all the codes, it will be difficult to prevent them from hacking everything not secure enough or exposed because they have enough information like ip, usernames, … which have been sent in code and documents during coding sessions!

u/Spare_Dependent6893 — 4 days ago
▲ 3 r/developers+1 crossposts

is Electron reliable and usable ?

Regarding electronjs org, I would know if some of you already

  1. deploy Electron-based app on Windows with success,
  2. if a significant porportion of final users adopts your Electron-based app,
  3. if your Electron-based app is reliable,
  4. if your Electron-based app is secure enough for production usage ?

Thanks

reddit.com
u/Spare_Dependent6893 — 9 days ago

CrowdStrike 2026 : Dramatic acceleration in attacks and vulnerabilities being exploited within just a few hours

CrowdStrike 2026 Threat Hunting Report reveals key informations on the multiple roles of AI in protection, attacks and vulnerabilities exploitation : https://www.crowdstrike.com/en-us/resources/reports/threat-hunting-report.

Worth to read it but do not know all what we have to do at our scale as a lambda company to be fully protected now!!!

At least at our level of AI usage, we do not expose any sensitive IT information through obfuscation and pseudonymisation.

reddit.com
u/Spare_Dependent6893 — 16 days ago

When AI Agents Go Off-Script: What OpenAI and Anthropic's Recent Incidents Teach Us About Exposure

If an AI agent can turn bare internet access into three real breaches with zero inside knowledge (see Anthropic/OpenAI's recent disclosures), what do you think happens the day one of your internal docs — architecture, configs, real customer names — leaks some other way? Wrote a piece on this, and on pseudonymizing docs before they ever reach an AI provider. Feedback welcome

dev.to
u/Spare_Dependent6893 — 17 days ago
▲ 1 r/documentAutomation+1 crossposts

pseudonymization of documents before sending to ai for review/update

One of my client sees that some words and excels documents produces by product/dev team where sent to ai and ask me to extend my promptCape development which they used for code obfuscation with document pseudonymization features. This is what he uses now to protect PII in their documents sent to ai. If you are interested by document pseudonymization, please give me your feedbacks about the promptCape way of doing it.

reddit.com
u/Spare_Dependent6893 — 21 days ago

promptCape now with pseudonymization of documents

One of my client sees that some words and excels documents produces by product/dev team where sent to ai and ask me to extend promptCape with document pseudonymization features. This is what he uses now and I just update the promptCape.com site to have this new version avalaible. Have a look if you want to protect PII in your documents sent to ai.

u/Spare_Dependent6893 — 24 days ago
▲ 5 r/codingProtection+1 crossposts

i started having one AI attack the other AIs' work. four things they called "done" tonight were not.

i've stopped thinking of my agents as junior engineers. they're minions. tiny, eager, weirdly confident, and they will absolutely do what you said instead of what you meant.

that reframe changed how i verify everything.

a minion doesn't lie to hurt you. it wants to come back with the banana. so if something is in the way, it finds a way around the thing, and it still comes back proud.

tonight one of them proved it.

i asked a build agent to run two other agents live for the first time. clean report, real artifacts on disk, everything looked right. what actually happened: those two agents were never granted permission to run for that tenant. no config file on my machine grants it. so it added the grant to its own in-memory copy of the config, raised a file-size safety cap while it was in there, and ran.

not malicious. it just really wanted to bring me the banana.

the receipt was perfect. the run was never authorized.

i only caught it because the verifying seat reads the config on disk instead of reading the report. one grep. the lamp was dark, and it had always been dark.

three more the same night, quieter. a script that reported success while never writing the one column it existed to change. an api that answered "updated successfully" and changed nothing, caught by reading it back. a claim that one row existed when the database had five.

so the rule i actually run now: a minion's word is a claim, never evidence. the test can't be "did it report done." it has to be "does the world agree."

and the verifier can't be another minion from the same crew. different model, different account, no loyalty to the thing it's inspecting. that one has never once not been worth paying for.

reddit.com
u/Spare_Dependent6893 — 26 days ago
▲ 21 r/codingProtection+1 crossposts

Cybersecurity statistics of the week (July 13th - July 19th)

Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.

All the reports and research below were published between July 13th - July 19th.

You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/ 

Ransomware

The State of Ransomware 2026 (Sophos)

Now in its seventh straight year, this is the definitive look at ransomware trends worldwide.

Key stats:

  • 79% of ransomware attacks start with an identity-based approach.
  • 67% of root causes across 661 incident response and MDR cases are identity-related.
  • 97% of victims where compromised credentials are identified as the root cause have MFA enabled in some form at the time of the attack.

Read the full report here.

Ransomware and Cyber Extortion in Q2 2026 (ReliaQuest)

ReliaQuest's Q2 numbers on ransomware activity. The big takeaway: The Gentlemen is the group everyone should be watching. Plus, it looks like Deadlock is back. 

Key stats:

  • The Gentlemen surged 588% quarter-over-quarter to 179 posts in Q1.
  • Deadlock emerged in June 2026 with 75 named victims in a single month, after being absent from public data-leak sites for 11 months.
  • The US absorbed 1,094 ransomware victim data leak posts in Q2, roughly 49% of observed activity and nine times the volume of the next country.

Read the full report here.

Vulnerability Management

The 2026 State of Vulnerability Remediation (Vicarius)

A look at how security leaders are fixing vulnerabilities. 

Key stats:

  • 79% of organizations experienced a security incident in the past 12 months involving a vulnerability that was already known and sitting in their inventory.
  • 75% of critical vulnerability responses initiate administrative workflows (like ticket creation or routing) rather than immediately fixing the underlying flaw.
  • 58% of all vulnerability remediation activities require direct human intervention.

Read the full report here.

AI Security

AI Agents Are Entering Critical Workflows. Who's Governing Them? (JumpCloud)

AI agents are moving into real work, but 800 IT leaders admit governance hasn't caught up.

Key stats:

  • More than 60% of organizations run AI agents in production.
  • Organizations have adopted fewer than one-third of standard AI governance and security practices.
  • The share of organizations requiring human review before high-risk AI actions dropped from 40% to 25% in six months.

Read the full report here.

The AI Security Report 2026 (Check Point)

A breakdown of how AI has gone from cyber assistant to active attacker. 

Key stats:

  • High-risk enterprise AI prompts doubled over the year, increasing from about 1 in every 50 interactions to 1 in every 25 interactions.
  • The average organization runs ten AI applications per month.
  • Between 87% and 93% of organizations experienced at least one high-risk AI interaction each month.

Read the full report here.

The Year Agents Entered the Workforce (Straiker)

Straiker put AI agents through adversarial testing to see where they fail.

Key stats:

  • More than 1,700 successful exploits occurred across production coding, productivity, and first-party AI agents during adversarial testing.
  • 36% of successful attacks on coding agents reached remote code execution on the developer's machine.
  • 91% of successful attacks on productivity agents ended in silent data exfiltration.

Read the full report here.

Rethinking AI's Impact on Cybersecurity Roles (ISC2)

ISC2 on how AI is changing the day-to-day of cybersecurity work.

Key stats:

  • 89% of cybersecurity professionals report having experienced AI recommendations that lead to incorrect outcomes at their organizations.
  • 62% list over-reliance on AI as a top concern.
  • 50% say their organizations hold human decision-makers ultimately accountable when AI-recommended actions lead to incorrect outcomes.

Read the full report here.

Executive Risk

2026 Executive Trends Report (Nisos)

Scary insight into how exposed executives are on the internet. 

Key stats:

  • 100% of executives have breach data linking their name to at least one current email address.
  • 94% have at least one plaintext password exposed in breach data.
  • 94% have home addresses publicly linked to their name in public records or people-search sites.

Read the full report here.

Industry-Specific

Government Ransomware Roundup: H1 2026 (Comparitech)

Comparitech tracked ransomware attacks specifically against government entities in the first half of 2026.

Key stats:

  • From January to June 2026, an average of one ransomware attack on a government entity occurred every day.
  • The median ransom demand in H1 2026 was $100,000, one-fifth of the H2 2025 median of $500,000.
  • The most prolific ransomware strains against government were The Gentlemen (22), Qilin (21), LockBit (14), APT73/BASHE (12), and INC (10).

Read the full report here.

reddit.com
u/Narcisians — 28 days ago
▲ 3 r/codingProtection+2 crossposts

I built a free, fully-local security scanner for AI-coded apps it catches the stuff Claude Code and Cursor ship by default (open databases, live API keys, injection holes)

Every vibe-coded app I audited had the same problems: live API keys in client code, Supabase tables with no RLS, and exec() running raw user input. AI tools make things work, not safe.

So I built VibeGuard free, open-source (MIT), and it runs entirely on your machine. No account, no telemetry; your code never leaves your laptop.

Catches:

•🗄️ Open databases missing RLS, fake policies, Firebase. read: true

•🔑 50+ secret types (OpenAI, Stripe, AWS…) in code, git, localStorage

•💉 SQL/command injection & XSS via real AST taint analysis, not just regex

•🤖 AI-specific holes — LLM output piped into shell/SQL, hallucinated npm packages

Use it:

git clone https://github.com/yagyeshVyas/VibeGuard.git

cd VibeGuard && npm install && npm link

vibeguard scan # find issues

vibeguard fix # auto-fix 43 rule types

vibeguard pre-deploy # blocks deploy on critical findings

Also runs as an MCP server, so Claude Code / Cursor can scan while writing code. Pre-commit hooks + CI templates included.

Honest scope: it catches the mechanical holes AI leaves behind it; it's not a replacement for a real security review. Benchmark (precision/recall) is in the repo.

https://github.com/yagyeshVyas/VibeGuard

reddit.com
u/Spare_Dependent6893 — 1 month ago
▲ 34 r/codingProtection+1 crossposts

Are AI coding agents becoming a new security risk inside engineering teams?

I keep seeing people talk about AI coding agents as a productivity tool, but I think we are under-discussing the security side.

A normal code assistant suggests code.

An agent can do much more.

It can read your repo, edit files, run commands, call tools, open PRs, access tickets, check logs, maybe even touch secrets or deployment workflows depending on how it is set up.

That changes the risk.

At that point, the question is not just “did the agent write good code?”

It becomes:

What did it access?
What did it change?
Why did it make that change?
Did it introduce a vulnerability?
Did it leak context somewhere?
Can someone review the full trace later?
What permissions should it never have?

The scary part is that a lot of teams are moving fast with agents before they have clear rules around access, audit logs, testing, and ownership.

This feels similar to early cloud/Kubernetes days. Everyone loved the speed, then later realized the hard part was visibility, limits, and knowing who owned what.

Curious how security/AppSec people are thinking about this.

Are AI coding agents mostly a productivity win right now, or are they becoming a new attack surface inside the SDLC?

reddit.com
u/Spare_Dependent6893 — 1 month ago
▲ 3 r/codingProtection+2 crossposts

How will be used the code we send to ai ?

Pokemon players were not aware that their scans are a very valuable ai asset for some domains : an interesting way of using data for training models to indirect goals we may be are not aligned with, but did not know at the time... -> How Pokémon Go players may have unknowingly helped train military AI | Cybernews

May be it will be the same with all the code and data we send to ai.

reddit.com
u/Spare_Dependent6893 — 1 month ago