Microsoft warns of job‑themed repo lures targeting developers with multi‑stage backdoors

Microsoft says it has uncovered a coordinated campaign targeting software developers through malicious repositories posing as legitimate Next.js projects and technical assessments. The campaign employs carefully crafted lures to blend into routine workflows, such as cloning repositories, opening projects, and running builds, thereby allowing the malicious code to execute undetected. Telemetry collected during an incident…

Read More

Drive business productivity through open collaboration, AI and document creation

Businesses of all sizes depend on “office” suites for their day-to-day tasks and for collaboration. AI, for its part, promises significant productivity gains for knowledge workers and for anyone who works with documents. According to studies, we spend over half our time using “office” software. And the global market for productivity applications is worth $22.5…

Read More

Compromised npm package silently installs OpenClaw on developer machines

A new security bypass has users installing AI agent OpenClaw — whether they intended to or not. Researchers have discovered that a compromised npm publish token pushed an update for the widely-used Cline command line interface (CLI) containing a malicious postinstall script. That script installs the wildly popular, but increasingly condemned, agentic application OpenClaw on…

Read More

Visual Studio Code previews chat customizations editor

Just-released Version 1.113 of Microsoft’s Visual Studio Code editor emphasizes improvements ranging from chat customizations to support for MCP (Model Context Protocol) in Copilot CLI and Claude agents. Released March 25, VS Code can be downloaded for Windows, Linux, or Mac via the VS Code download webpage. VS Code 1.113 closely follows VS Code Versions…

Read More