Code Security
The latest Code Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft's MDASH Code Scanner Lands in Private-Preview Limbo—Here's What to Do
Microsoft's July 2026 release notes for Security Exposure Management have added a long-anticipated feature: Codename MDASH, an agentic code scanner that uses a multi-model AI system to hunt for...
SonarQube Now Scans AI-Written Code Across Copilot, Claude Code, and More
SonarSource has rolled out a suite of SonarQube plugins that inject static analysis directly into the workflow of popular AI coding agents, ensuring that code generated by tools like GitHub Copilot,...
ASUS and Dell debut dedicated hardware for Windows 365 cloud PCs
Microsoft's vision for a cloud-first desktop experience has taken a significant leap forward this week with the announcement of purpose-built hardware endpoints for Windows 365 Cloud PC. ASUS and...
Microsoft's AI-Driven Rust Migration: Rewriting Windows Legacy Code by 2030
Microsoft's ambitious engineering gamble—to use artificial intelligence to rewrite millions of lines of legacy C and C++ code into Rust by 2030—has landed squarely in the spotlight this week,...
Microsoft Faces ACCC Scrutiny Over Copilot Bundling in Australia
Microsoft's controversial decision to bundle its AI-powered Copilot feature into Microsoft 365 subscription plans has triggered formal intervention from Australia's consumer watchdog, the Australian...
Visual Studio 2026 Debuts Agentic Copilot Superpowers—and New Attack Vectors
Microsoft fired its boldest shot yet in the AI-first IDE war, launching Visual Studio 2026 (version 18.0) through a new Insiders Channel that replaces the long-standing Preview program. The release...
Microsoft’s AI Coding Assistant Under Fire as GitHub Copilot Command Injection Chain Exposes Developers to Remote Code Execution
A zero-click AI command injection flaw in Microsoft 365 Copilot, tracked as CVE-2025-32711 and nicknamed EchoLeak, laid bare a dangerous new attack surface in June 2025. The vulnerability carried a...
GitHub Copilot Free Tier: Democratizing AI-Powered Coding Across Platforms Including Xcode
The arrival of GitHub Copilot’s free tier has sparked a wave of conversation—and a healthy dose of excitement—across developer communities the world over. No longer restricted to open-source...
Security Alert: Critical Vulnerability CVE-2025-49714 Affects Visual Studio Code Python Extension
Security Alert: Critical Vulnerability CVE-2025-49714 Affects Visual Studio Code Python Extension Contrary to some reports, a significant security vulnerability, identified as CVE-2025-49714, does...
Git for Windows' July 8 CVE-2025-48386 Buffer Overflow Threatens Credential Theft
Critical Git for Windows Vulnerability CVE-2025-48386 Exposes Systems to Buffer Overflow Risks A significant security flaw, identified as CVE-2025-48386, has been discovered in Git for Windows,...
Git GUI bug CVE-2025-46835 lets attackers overwrite files via malicious repos
Unpacking CVE-2025-46835: A Critical Vulnerability in Git GUI Threatens Software Development Security A recently disclosed vulnerability, CVE-2025-46835, has brought to light a significant security...
Microsoft Open-Sources GitHub Copilot Chat for VS Code: A Game-Changer for AI Transparency
Microsoft's decision to open-source its GitHub Copilot Chat extension for Visual Studio Code marks a significant milestone in AI-assisted software development. This move, announced on July 2, 2024,...