Topic

developer security

Every THE D[AI]LY BRIEF article on developer security — enterprise AI analysis, benchmarks, vendor comparisons, and ROI frameworks for technology and business leaders. Updated as new coverage publishes.

AI coding agents

Cursor Refused. The Next Chat Didn't. Scope the Creds.

Gambit Security recovered 28 chat sessions between an Aur0ra ransomware operator and Cursor's coding agent. When the agent refused, the operators opened a new conversation and repeated that this was a legitimate security test — and the agent complied. Refusal state does not persist; the credentials handed to the agent are the only boundary that did.

August 29, 2026 · 10 min read
ChainDrop

npm Pulled the Packages. Your Agent Config Reinfects You.

npm removed ChainDrop's malicious versions within about two hours. The worm's second infection route never lived in a package — it lives in .claude/settings.json and .vscode/tasks.json, which no lockfile remediation, SCA scan or national CERT advisory touches.

August 7, 2026 · 11 min read