Browsing Category
Developer Tools
68 posts
Developer tools, coding workflows, package managers, software engineering platforms, cloud development environments, AI coding assistants, language tooling, and developer productivity news.
Google’s Vertex AI Media Endpoint Shutdown Gives Developers a June 30 Migration Deadline
Google is retiring older Vertex AI, Imagen, and Veo media-generation endpoints on June 30. Developers using Google’s AI image or video APIs should check model IDs, migrate to the recommended Gemini and Veo replacements, and test output changes before production jobs start failing.
AWS AgentCore Turns Enterprise AI Agents Into an Operations Stack
AWS used its New York Summit to expand Bedrock AgentCore, launch AWS Context and AWS Continuum, and push AI agents deeper into enterprise operations. The real story is not another chatbot layer, but a managed stack for grounding, governing, testing, and remediating agent behavior.
Unreal Engine 6 Turns Fortnite Into Epic’s Test Bed for Portable Games
Epic’s Unreal Engine 6 roadmap merges UE5 and UEFN, moves gameplay toward Verse, and uses Fortnite cosmetics as the first test of portable game assets. The plan could reshape game development, but adoption, AI tooling, and creator-economy incentives remain open questions.
SearchLeak Shows How Microsoft 365 Copilot Search Can Become a Data Leak
Varonis disclosed SearchLeak, a patched Microsoft 365 Copilot Enterprise Search vulnerability chain that could turn one trusted-looking Microsoft link into a path for stealing emails, files, calendar data, and MFA codes.
Microsoft AutoJack Research Shows How AI Browsing Agents Can Break Localhost Trust
Microsoft’s AutoJack research shows how an AI browsing agent could turn a malicious webpage into a local remote-code-execution path through AutoGen Studio’s MCP WebSocket surface. The specific issue was fixed before a PyPI release, but the localhost trust problem is bigger than one tool.
F5’s Emergency NGINX Patches Put Web Server Teams on a Fast Upgrade Clock
F5 issued out-of-band NGINX updates for flaws affecting HTTP/3, proxy protocol, gRPC, Gateway Fabric, and related products. Teams running internet-facing NGINX should check versions, exposed modules, Kubernetes ingress paths, and temporary mitigations before treating this as routine patching.
Microsoft MDASH Moves AI Bug Hunting Into Real Security Workflows
Microsoft says its MDASH agentic security system is now being used across Windows, Azure, and identity workflows, with new findings in Hyper-V, HTTP.sys, the Windows kernel, and Active Directory. The update shows AI vulnerability discovery moving from benchmark claims toward real engineering pipelines, while proof generation remains the hard part.
JetBrains AI Plugin Malware Puts Developer API Keys at Risk
JetBrains says it removed 15 malicious Marketplace plugins that posed as AI coding tools while stealing developer API keys. Users who installed or configured the plugins should revoke affected OpenAI, DeepSeek, SiliconFlow, or other AI provider keys and check usage logs now.
Mastra npm Compromise Turns AI Agent Frameworks Into a Supply-Chain Target
Attackers republished more than 140 Mastra npm packages with a poisoned easy-day-js dependency, exposing AI agent developers to an install-time remote payload. Teams that installed affected @mastra packages on June 17 should treat developer machines and CI runners as compromised.
SpaceX’s $60B Cursor Deal Turns AI Coding Tools Into Infrastructure
SpaceX’s SEC filing confirms a $60 billion all-stock deal to buy Anysphere, the company behind Cursor. The acquisition turns AI coding tools into a strategic infrastructure bet tied to compute, developer distribution, and xAI’s coding-agent ambitions.