code review

Tech Optimizer
July 18, 2026
North Korea's Contagious Interview hackers have been using a deceptive strategy to target developers by posing as recruiters and embedding malware in SVG files. Elastic Security Labs discovered that the attackers hid malicious payloads within HTML comment blocks of these files, allowing the malware to evade antivirus detection. At the time of the findings, no antivirus engines flagged the compromised repositories, which included trojanized GitHub repositories disguised as coding challenges. The malware executed automatically at server startup and deployed four modules: a browser credential and cryptocurrency wallet stealer, a file stealer, a remote access Trojan, and a clipboard monitor. The campaign, tracked as REF9403, is part of the ongoing Contagious Interview operation attributed to North Korea's Lazarus Group, which aims to generate revenue through cryptocurrency theft. Developers are advised to audit any projects run from unsolicited sources and to monitor specific domains associated with the attack.
Winsage
July 9, 2026
Microsoft has reaffirmed its commitment to security, focusing on enhancing protection for Windows users. The company is utilizing a multi-model agentic scanning harness (MDASH) that incorporates various AI models to identify Windows vulnerabilities earlier in the development process. This proactive approach allows security experts to detect potential issues before public releases. Microsoft is also investing in technologies that use AI to streamline the development of fixes while maintaining human oversight during code reviews. The company acknowledges the dual nature of AI in security, as it accelerates both the identification of vulnerabilities and the potential for exploitation. Microsoft aims to strengthen its systems to find vulnerabilities earlier and deliver timely security patches to customers.
AppWizard
June 30, 2026
The Godot Foundation has decided to implement new guidelines to prohibit AI-authored code, pull requests from AI agents, and AI-generated text in communications between contributors. This decision follows concerns about the increasing number of AI-generated contributions, which have made code review more challenging for maintainers. The Foundation aims to reduce the burden on maintainers and ensure that all contributions come from accountable humans. The new policies will explicitly reject AI-authored code and advise contributors to use AI assistance only for minor tasks while requiring disclosure of its use. Machine translations of human-authored text will still be allowed. The Foundation plans to adopt a cautious approach to AI tools and will re-evaluate its policies as the situation evolves.
Search