







**[Register here](https://konghq.com/events/webinars/the-most-prevalent-code-flaws-in-api-development-and-how-hackers-exploit-them?utm_source=kong-email&utm_medium=email&ut
Vibe Coding Failures: Documented AI Code Incidents
A curated directory of real-world incidents where AI-generated code failed in production.

Comment and Control: Prompt Injection to Credential Theft in Claude Code, Gemini CLI, and GitHub Copilot Agent
Anthropic Claude Code Security Review, Google Gemini CLI Action, and GitHub Copilot Agent are vulnerable to prompt injection via GitHub comments — turning PR titles, issue bodies, and issue comments into attack vectors for API key and token theft.

What I Found Interesting in Claude Code's Source
A breakdown of the most interesting engineering patterns in Claude Code's leaked source code: composable system prompts, runtime instruction injection, context compression, forking, prompt caching architecture, and more.
Why Executive Interest In APIs Is Booming
A decade ago, API awareness was limited, with evangelists educating a mostly unaware C-suite. Today, APIs are integral to business, widely embraced by executives and developers alike, reflecting a significant shift in digital transformation strategies.

Web Crypto’s SubtleCrypto: A Masterclass in Developer Hostility and How It Strangles the Modern Web
Not Subtle, Just Sabotage — An API Against the Web
AI vs human code gen report: AI code creates 1.7x more issues
We analyzed 470 open-source GitHub pull requests, using CodeRabbit’s structured issue taxonomy and found that AI generated code creates 1.7x more issues.

Comforting Myths - Infrequently Noted
I've been hearing confusing reports of Apple's openness to collaboration on challenging APIs so often that either my priors are invalid, or something else is at work. To find out, I needed data.

Code scanning shows AI security detections on pull requests - GitHub Changelog
GitHub code scanning now surfaces AI-powered security detections directly on pull requests, expanding vulnerability coverage to languages and frameworks not currently supported by CodeQL. These detections help teams identify and…

Web Install API Dev Spec
Web Install API Dev Design Spec Author: Amanda Baker, Diego Gonzalez, Kristin Lee, Lia Hiscock Spec status: Last updated: Links: Explainer | Chrome Status | CR bug | UX changes review doc Feature Overview Introduction Goals Non-goals Concepts Interfaces and Interactions JS API changes navig...

Hacking the Hackathon
At their best, internal hackathons provide a necessary patch to systemic problems. But their usual structure limits their potential.

How We Exploited CodeRabbit: From a Simple PR to RCE and Write Access on 1M Repositories - Kudelski Security Research Center
Aug 19, 2025 - Nils Amiet -
Microsoft's open source tools were hacked to steal passwords of AI developers | TechCrunch
Microsoft shut down dozens of GitHub code repositories for Azure and AI coding tools after a reported hack.

Vulnerability Research Is Cooked
For the last two years, technologists have ominously predicted that AI coding agents will be responsible for a deluge of security vulnerabilities. They were right! Just, not for the reasons they thought.