North Korean threat group published 60+ malicious npm packages over 7 months, specifically designed to fool AI coding agents into installing them (PromptMink)

OpenAI Codex: How a Branch Name Stole GitHub Tokens via Command Injection

AI Code Compiles. It Passes Tests. It Destroyed 6.3 Million Orders.

Amazon's AI agent Kiro inherited an engineer's elevated permissions, bypassed two-person approval, and deleted a live AWS production environment