Javascript stories
Australia's developers are contributing more widely abroad, with GitHub data showing a 16% quarterly rise in cross-border open-source collaboration.
Developers using AI-generated code on Hostinger's Node.js plans will now get automatic alerts on vulnerable dependencies as apps are scanned in the background.
The release aims to ease a key hurdle for firms moving AI agents into production by unifying memory, retrieval and access across environments.
CrowdStrike said state-backed espionage and extortion are surging as AI assets inside tech groups draw hackers seeking code, models and access.
The deal gives the web giant a direct role in a tool used in 129 million weekly downloads, while keeping it open source and vendor-neutral.
Developers using npm could have secrets exposed as 176 malicious packages were set up to hijack dependency resolution and run postinstall malware.
Software teams can now tackle sprawling code audits and migrations with parallel AI subagents, though the feature uses more tokens and needs approval.
Enterprises running AI agents can now cut infrastructure overhead, as MongoDB adds automated embeddings, memory and faster database performance.
Organisations using AI in software development will get training on secure coding and governance as vulnerabilities and data risks mount.
Detection of malicious code can collapse when AI reviewers are fed large files packed with harmless text, Cloudflare's research shows.
Hundreds of packages could have exposed API keys and logins after Claude Code saved approved commands in a file npm may publish by default.
A shortage of experienced coders is putting pressure on teams maintaining mission-critical web systems as most PHP users plan upgrades.
Broad exposure across thousands of applications is feared after Google tied the axios npm supply chain attack to suspected North Korean hackers.
Google has launched Antigravity, a full-stack coding agent in AI Studio that turns text prompts into collaborative, production-ready web apps.
Malicious fake Windsurf IDE extension hid JavaScript, abused Solana to fetch payloads, and stole developers' browser credentials and tokens.
Ransomware group LeakNet adopts ClickFix lures and a Deno-based fileless loader to scale attacks and evade traditional endpoint defences.
Enterprises can now vet open-source dependencies before build time, as the catalogue adds independent malware and vulnerability checks for Python and Java.
The tool has already blocked more than 52,000 risky npm packages as supply chain attacks continue to hit software teams.
A free account could have let attackers alter Zapier-maintained packages and hijack logged-in users' browser sessions, researchers said.
Burnout is rising as marketers race to master AI, while more than 70% of teams now work beyond sustainable capacity.