NewsIDEsaster 30+ Vulnerabilities Across Every Major AI IDE 100% VulnerableSC Media·high signalXBlueskyLinkedInCopy linkAri Marzouk disclosed 30+ vulns (24 CVEs) affecting Cursor, Copilot, Windsurf, Zed, Kiro, Roo Code, Junie, Cline. 100% of tested IDEs vulnerable to prompt injection enabling RCE.SourceSource pageSC Media↳ Follow the threadPolicy dependency / Stack layerA replay of 68,266 real Claude Code requests says plain LRU beats the clever KV-cache policiesGitHubPolicy dependency / Stack layerAnthropic's September threat report: Chinese students produced "more than a dozen possible zero day findings in a single month" with ClaudeAnthropicStack layer / Threat patternTwo agent IDEs now ship the same sentence, and one of them has more open PRs than open issuesGitHubStack layer / Threat patternClaude Code 2.1.269 Ships a Plugin Eval Runner and a Knob to Raise the Workflow Tool's Concurrent Agent Cap to 256Anthropic (claude-code CHANGELOG)Stack layer / Threat patternAgentsDock Open-Sources an IDE That Collapses Termius, Cursor and Claude Code Into One DockAgentsDock (surfaced on Hacker News item 49678435)Policy dependency / Stack layerSGLang Hit With Unauthenticated Pickle RCE via /update_weights_from_tensor, the Fourth Critical Inference-Stack CVE in Four WeeksCERT Coordination CenterPolicy dependency / Stack layerGitHub adds four VS Code Agents fields to the Copilot usage metrics API, kept separate from editor Agent ModeGitHub ChangelogStack layer / Threat patternCROSS-CATEGORY: Five Launches in 96 Hours Sold Self-Hosting and Air-Gapping as the Entire DifferentiatorCoder blog, GitHub API and Hacker News Show HN (five independent launches)