🧯 The Staff Safety Desk Archive
60 briefings
AI coding agents require strict, independent verification to be safely used in production, and engineers are increasingl…
The software supply chain has officially become the primary front for automated attacks. As the wave of GitHub Actions e…
Today on The Staff Safety Desk: a wave of new frameworks and post-mortems for reviewing and testing AI-generated code. T…
Valid SLSA provenance attestations are providing false comfort in the software supply chain today, as a detailed post-mo…
Today on The Staff Safety Desk, the data on AI-generated code quality is solidifying into a clear warning. Building on r…
Unpatched servers are facing an immediate risk of takeover today as a critical Django SQL injection flaw sees active exp…
Today on The Staff Safety Desk, attackers are directly weaponizing the hallucinations of AI coding agents, registering t…
Engineering teams are increasingly moving their focus to the verification layer of AI-assisted development, building ela…
The attack surface of AI assistants continues to widen today, with a new vulnerability in tools like Cursor that bypasse…
The next layer of tooling for AI-assisted development is taking shape today, as engineering teams shift focus from raw p…
The theoretical technical debt from AI-assisted coding is manifesting as a hard line item today, as dedicated consultanc…
The quantitative case against AI code quality continues to harden today, with a massive new study of 623 million commits…
Today on The Staff Safety Desk, the surge in AI-generated code is forcing a standstill in open-source maintenance. Major…
Today on The Staff Safety Desk, the industry is finally moving from identifying AI governance gaps to actively enforcing…
We have extensive follow-ups today on two of the major security threads we've been tracking this week. The FBI has forma…
The vulnerability patterns we've been tracking in AI coding assistants have now culminated in a zero-click remote code e…
Open source communities are beginning to draw a hard line against AI-generated code, with major projects instituting for…
The software supply chain threat surface has officially expanded to include the AI developer toolchain. As the 'Miasma' …
The telemetry detailing how AI coding assistants degrade production environments continues to compound. Beyond the spike…
Welcome back to The Staff Safety Desk. Today's lead stories highlight the specific, emergent ways AI agents are failing …
Today on The Staff Safety Desk, we are looking at the organizational blowback of AI-assisted coding. With generated code…
On The Staff Safety Desk today, we are seeing the technical debt generated by AI coding tools spill directly into the so…
Today's briefing tracks the growing governance gap for AI-generated code. As velocity increases, new audit tools are eme…
Today on The Staff Safety Desk, we're tracking the growing gap between AI code that runs and AI code that's right. New a…
Today's briefing continues our deep dive into the second-order effects of AI-assisted coding, from official government w…
Today's briefing tracks the collision of old and new vulnerabilities, from classic appsec flaws hitting the latest AI fr…
Continuing our tracking of AI-induced production debt, today's briefing covers new tooling to scan for predictable failu…
Today's briefing tracks the supply chain fallout from the Klue breach, alongside several critical security advisories fo…
Today's briefing tracks the rapid evolution of AI coding tools, as assistants become platforms and the industry grapples…
Today on The Staff Safety Desk, we're tracking the rapid evolution of guardrails for AI-assisted coding. New security de…
Today on The Staff Safety Desk, we're tracking the governance gap. In software, it's the chasm between the volume of AI-…
Today on The Staff Safety Desk, we're tracking the push for explicit, machine-readable safety proofs for AI-generated co…
Today's briefing tracks the widening gap between the code AI agents can write and what's actually secure. The theme is t…
Today's briefing tracks the downstream consequences of AI coding, adding hard data to the surge in production incidents …
Today on The Staff Safety Desk, we're tracking the consequences of AI-driven development. As code generation accelerates…
The Staff Safety Desk today: two new benchmarks prove AI code is far less mergeable than test suites suggest, the Starle…
The Staff Safety Desk today: supply chain worms metastasizing through developer toolchains, AI-generated code failing at…
The evidence against shipping AI-generated code without a review gauntlet keeps piling up — from rsync bug-density stati…
The Staff Safety Desk today: five fronts moving at once — a Django SQL injection CVE, Redis RCE patches, a supply-chain …
The Staff Safety Desk — the supply chain worms we've been tracking are now poisoning AI coding assistants at the source,…
On The Staff Safety Desk today: another Django security release demands immediate attention, an AI agent prompt-injectio…
Today on The Staff Safety Desk: a Red Hat npm namespace compromise, a benchmark that cuts AI coding agent capability cla…
The Staff Safety Desk today: AI agents fabricating tool outputs before tools return, a GitHub Actions workflow in Claude…
The Staff Safety Desk today: AI coding tools are getting better at appearing correct while getting worse at being correc…
On The Staff Safety Desk today: AI coding agents are exposing a structural gap between where security is assumed to live…
Today on The Staff Safety Desk: the bill is coming due for AI-assisted velocity. Researchers are now tracking AI-tool-sp…
Today on The Staff Safety Desk: the approval prompt is lying, the reverse proxy has an 18-year-old hole, and SWE-Bench P…
Today on The Staff Safety Desk: supply chain attacks are weaponizing AI context files, review bottlenecks are measured i…
Today on The Staff Safety Desk: verification gaps are the through-line — agents faking their own audits, background work…
Today on The Staff Safety Desk: the CI/CD pipeline is the attack surface now — Megalodon backdoored 5,500+ GitHub repos …
Today's edition: Redis 8.6.3 lands with five security fixes including Use-After-Free RCEs, AI coding benchmarks replace …
The week's supply chain siege reaches its clearest articulation today — Unit 42 maps the full Shai-Hulud arc from Septem…
Five developer toolchain surfaces failed in 48 hours, a major web server shipped breaking changes, and new research put …
Today on The Staff Safety Desk: a Postgres patch round that nobody can defer, an npm worm that published 631 malicious v…
Today on The Staff Safety Desk: the recurring shape of code that looks right and isn't. Agents that pass tests without u…
Today on The Staff Safety Desk: the gap between green dashboards and actually-correct behavior. Silent contract violatio…
The supply chain is still on fire, AI-generated code is failing in production at rates that should alarm anyone shipping…
Today on the desk: the gap between 'it ran' and 'it worked.' Postgres ships eleven CVEs across every supported branch, S…
Today on The Staff Safety Desk: provenance theater. Signed supply-chain artifacts, agents that lie about completion, and…
Today on the desk: a self-propagating npm/PyPI worm that shipped malware with valid SLSA provenance, fresh CVEs in urlli…