Microsoft is expanding agentic software development across GitHub Copilot, Aspire, Windows development environments, WSL, and model-context-protocol integrations, with Distinguished Engineer David Fowler saying manual line-by-line coding is becoming less central. However, automated code generation continues to produce material security defects: Veracode’s 2026 benchmark found known vulnerabilities in roughly 44% of AI code-generation tasks, while Sonar’s evaluation of GPT-5.6 variants found higher bug and vulnerability densities than GPT-5.5 despite improved functional-task pass rates, including cryptographic misconfiguration, insecure resource handling, and concurrency flaws. Microsoft is deploying its MDASH agentic scanner across engineering environments to identify vulnerabilities at scale.
Security researchers also found exploitable weaknesses in rapidly built “vibe-coded” applications, including client-side-only authentication, browser-exposed API keys, permissive or missing Supabase Row-Level Security policies, and internet-exposed internal tools. Tests of GitHub Copilot’s GPT-4o recommendations showed proposed fixes for a Node.js path-traversal flaw could be bypassed by relative or URL-encoded traversal payloads. Organizations should require human architectural and security review of AI-produced changes and retain secure-by-default libraries, SAST, software-composition analysis, secret scanning, pull-request controls, backend secret management, and deny-by-default database access policies.

Track how attackers are adapting to this technology.
10 events from the most recent confirmed update back to the earliest known activity.
Microsoft's Aspire team stated that AI agents can effectively write code, but generating code is distinct from delivering a complete working application. Aspire supports agent actions including starting services, inspecting logs and telemetry, restarting failed components, and retesting applications.
GitHub added Windows development environments to its Copilot coding agent, enabling the agent to build and test Windows-targeted projects, run linters, and verify builds.
Veracode's 2026 GenAI Code Security Report found that approximately 44% of tested AI code-generation tasks produced code containing a known vulnerability in a controlled benchmark.
An evaluation of GPT-4o through GitHub Copilot found that its proposed checks for a deliberately vulnerable Node.js bank-statement API could be bypassed by relative and URL-encoded traversal payloads. The assessment concluded that LLM suggestions lack sufficient source-to-sink context to serve as standalone vulnerability remediation.
Microsoft Distinguished Engineer David Fowler said that “typing code is absolutely over,” describing a shift toward AI agents performing more implementation work while developers retain responsibility for architecture, validation, testing, dependencies, and security review.
Microsoft deployed its MDASH agentic vulnerability-scanning system across major engineering environments, including Windows, Azure, and identity systems. The Windows security team said it enabled deeper vulnerability hunting involving the Windows kernel, Hyper-V, and networking stack.
Sonar evaluated GPT-5.6 Sol, GPT-5.6 Terra, and GPT-5.5 on 4,444 Java tasks using SonarQube analysis. Sol achieved the highest functional pass rate, but both GPT-5.6 variants had higher bug and vulnerability densities, particularly for concurrency defects, cryptographic misconfiguration, and insecure resource handling.
After Wiz shared its findings with Lovable's security team, Lovable published security best-practice guidance and collaborated on a global system-prompt change intended to discourage embedding secrets in client-side code.
Wiz Research identified client-side-only authentication, browser-exposed credentials, permissive or absent Supabase Row-Level Security, and publicly accessible internal applications in vibe-coded apps. Reported examples included an enterprise game exposing users' PII and IP addresses.
Wiz released baseline open-source security rules files and the prompt used to generate them, targeting common languages and frameworks for use with AI coding assistants. The guidance promotes concise, scoped rules and conventional controls such as SAST, SCA, secret scanning, and pull-request review.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
windowslatest.com
Open sourcesonarsource.com
Open sourcewiz.io
Open sourcewiz.io
Open sourcenodejs-security.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.