frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

AI coding agents in CI/CD pipelines create new attack vectors

https://www.stepsecurity.io/blog/when-ai-meets-ci-cd-coding-agents-in-github-actions-pose-hidden-security-risks
2•kurmiashish•7h ago

Comments

kurmiashish•7h ago
This article explores how AI coding agents (GitHub Copilot, Claude Code, etc.) operating in CI/CD environments introduce novel security risks that traditional EDR solutions can't detect. The key insight: these agents have elevated privileges to create branches, open PRs, and execute code based on natural language instructions - but organizations have zero visibility into what they're actually doing behind the scenes. The post highlights real attack scenarios where agents can be manipulated through behavioral exploitation rather than direct compromise. For example, tricking an agent into generating subtle vulnerabilities in PRs that human reviewers might miss, or having them trigger malicious workflow runs through seemingly innocent issue comments. Most interesting is the "context gap" problem - traditional security tools see low-level system calls but miss the AI decision chain that led to those actions. When an agent downloads from gist.githubusercontent.com, is it fetching legitimate dependencies or malicious code? Without CI/CD-aware monitoring, you can't tell. The article is part of a series examining these risks and demonstrating runtime monitoring approaches specific to AI-powered development workflows.

Is anyone building a voice agent for runners?

1•vietthangif•4m ago•0 comments

Restaurants, Salons and Workouts Are Free for Hot People–If They Post

https://www.wsj.com/style/neon-coat-app-influencers-free-meals-classes-d310564f
1•paulpauper•6m ago•0 comments

Four-day work week benefits workers, employers, study says

https://medicalxpress.com/news/2025-07-day-week-benefits-workers-employers.html
1•OutOfHere•8m ago•0 comments

Deep Film Inc. Back End/AI Engineer and UI/UX Engineer

https://berlinstartupjobs.com/engineering/backend-ai-engineer-ui-ux-engineer-deep-film-inc/
1•CharlesRP•8m ago•0 comments

"Destroy the web": Sam Altman on AI concerns for economy and finance

https://www.youtube.com/watch?v=9LFlEZxc1rk
1•Brysonbw•11m ago•0 comments

How to Catch a Wily Poacher in a Sting: A Thermal Robotic Deer

https://www.wsj.com/us-news/how-to-catch-a-wily-poacher-in-a-sting-a-thermal-robotic-deer-ffef0fa8
2•Element_•14m ago•0 comments

Notes on Rewriting JSX as Astro

https://carlosn.com.br/blog/post/notes-on-rewriting-jsx-as-astro/
2•carlosneves•20m ago•0 comments

Addressing Privacy Fatigue

https://www.fastmail.com/blog/addressing-privacy-fatigue/
4•billybuckwheat•20m ago•0 comments

Troubled SPAC to buy iRocket for $400M but it returned most of its cash

https://techcrunch.com/2025/07/23/a-troubled-spac-plans-to-buy-irocket-for-400m-but-it-already-returned-most-of-its-cash/
2•pseudolus•20m ago•1 comments

Vibe coding turned this Swedish AI unicorn into the fastest growing startup ever

https://www.forbes.com/sites/iainmartin/2025/07/23/vibe-coding-turned-this-swedish-ai-unicorn-into-the-fastest-growing-software-startup-ever/
2•myth_drannon•32m ago•0 comments

I Eat

https://taylor.town/how-i-eat
4•paulpauper•33m ago•0 comments

Show HN: Voice-First AI Code Review Platform (Looking for OSS Beta testers)

https://www.lightlayer.dev/
2•changisaac•41m ago•0 comments

Ask HN: Has anyone deployed LLMs to production?

3•saaspirant•42m ago•0 comments

Surprising Science: How Electric Cars Transform Urban Air

https://modernengineeringmarvels.com/2025/07/22/surprising-science-how-electric-cars-quietly-transform-urban-air/
3•tzs•45m ago•0 comments

What is X-Forwarded-For and when can you trust it?

https://httptoolkit.com/blog/what-is-x-forwarded-for/
3•thunderbong•46m ago•1 comments

Spaghetti All'assassina

https://en.wikipedia.org/wiki/Spaghetti_all%27assassina
2•jameslk•47m ago•0 comments

Show HN: Marchat – Terminal-based chat app written in Go

https://github.com/Cod-e-Codes/marchat
3•Cod-e-Codes•48m ago•0 comments

Donald Trump Is Fairy-Godmothering AI

https://www.theatlantic.com/technology/archive/2025/07/donald-trump-ai-action-plan/683647/
5•CharlesW•51m ago•0 comments

Could you swap your mouse and keyboard for a smart bracelet?

https://www.scimex.org/newsfeed/could-you-swap-your-mouse-and-keyboard-for-a-smart-bracelet
2•geox•52m ago•0 comments

Anyone building P2P alternatives to capitalism?

https://github.com/contribution-protocol/contribution-protocol-project
3•mzk_pi•53m ago•1 comments

Ending 'woke AI' isn't enough: fight the 'monster' within it

https://nypost.com/2025/07/23/opinion/ending-woke-ai-isnt-enough-fight-the-monster-within-it/
3•kvee•57m ago•1 comments

Show HN: Synthetic Users that test your app, catch bugs, and provide feedback

https://synthetic.usejina.com/
2•fearlessboi•1h ago•1 comments

What's That Splatter on Your Windshield?

https://www.nytimes.com/interactive/2025/07/23/science/23xp-bugquiz.html
3•avalys•1h ago•1 comments

When photography was born, fascination, obsession, and danger followed

https://www.washingtonpost.com/books/2025/07/12/flashes-brilliance-history-early-photography-anika-burgess-review/
2•prismatic•1h ago•0 comments

Cluely Paying $1M Salaries

https://twitter.com/im_roy_lee/status/1948112169503207774
9•thisismytest•1h ago•0 comments

The Largest Ever Solar Storm Detected In 14,300-year-old Tree Rings (2023)

https://astrobiology.com/2023/10/the-largest-ever-solar-storm-detected-in-14300-year-old-tree-rings.html
3•georgecmu•1h ago•0 comments

Contextual.ai

https://contextual.ai/
3•handfuloflight•1h ago•0 comments

Guide to PDF security

https://www.unicornforms.com/blog/complete-guide-to-pdf-security
3•waldopat•1h ago•0 comments

A small web July

https://smallcypress.bearblog.dev/a-small-web-july/
35•debo_•1h ago•11 comments

Low cost mmWave 60GHz radar sensor for advanced sensing

https://www.infineon.com/part/BGT60TR13C
3•teleforce•1h ago•0 comments