
TeamPCP Breaches GitHub via Poisoned VS Code Extension
TeamPCP stole 3,800 GitHub internal repos via a malicious Nx Console update live for just 11 minutes, tracing back to the TanStack supply chain compromise.
They summarize our coverage. We write it.
Newsletters like this one rebroadcast our headlines - often without the full review, the source reading, or the analysis underneath. Our weekly briefing sends the work they paraphrase, straight from the desk, before they get to it.
Free, weekly, no spam. One email every Tuesday. Unsubscribe anytime.

TeamPCP stole 3,800 GitHub internal repos via a malicious Nx Console update live for just 11 minutes, tracing back to the TanStack supply chain compromise.

A full comparison of GitHub Copilot and Cursor in 2026 - pricing, benchmarks, agent mode, and which one belongs in your workflow.

Seven Replit Agent alternatives compared on stack support, pricing, and deployment - from Bolt.new and Lovable to developer tools like Cursor and Windsurf.

Seven tested alternatives to GitHub Copilot in 2026, ranked by use case with verified pricing, feature breakdowns, and honest trade-offs.

Six research teams disclosed exploits against Codex, Claude Code, Copilot, and Vertex AI. Every attack went after credentials the agents carried - not the models themselves.

A data-driven comparison of the top AI-powered CI/CD and DevOps tools in 2026, covering GitHub Actions, GitLab Duo, Harness, CircleCI, Buildkite, TeamCity, and GitOps options.

A hands-on comparison of the top AI tools for git workflows in 2026, covering PR review, commit messages, stacked PRs, and merge queues.

A Korean CTO ran a 13-step agent harness against 100+ major open-source repos over three days, landing 500+ commits and 130+ PRs - some merged by Kubernetes, Hugging Face, and Ollama maintainers. Then GitHub banned his account for spam, confirming that platform abuse detection cannot yet tell a disciplined harness from a bot.

Starting April 24, GitHub will use Copilot Free and Pro users' interaction data to train AI models by default - with opt-out buried in settings.

We ran the GitHub search query from a researcher's blog post and confirmed 300+ malicious repositories with AI-generated READMEs distributing info-stealers - with the real number likely north of 1,000.

The open-source AI agent framework crossed 250,000 GitHub stars in roughly 60 days, surpassing React's decade-long total. NVIDIA CEO Jensen Huang called it the most important software release ever.

OpenAI is developing an internal code repository to replace GitHub, putting the company on a collision course with its biggest backer.