Fed up with vibe coders, dev sneaks data-nuking prompt injection into their code

2026-05-28T20:51:48Z98f1bbc2aa0bef8bc2c1543081f150900f3590ed080021c2950332c0a2c3a1ce
AI-assisted codingBadHostBitLocker zero-dayCISA credentialsCanvas outageCopyFailDaemon Tools backdoorLinux vulnerabilitiesSSD side-channelStarletteTeamPCPVPN compromisebrowser fingerprintingbug-bounty abusecredential leakelement-data credential theftexploit disclosurejqwikopen-source supply-chainprompt-injection

What happened

This feed aggregates numerous Arstechnica security stories from May 2026 covering a wide range of high-impact incidents: a developer slipped a destructive prompt-injection into jqwik tests that instructed AI coding agents to delete app output; websites can now fingerprint visitors by measuring SSD activity from JavaScript; a critical “BadHost” vulnerability was found in the widely used Starlette package putting millions of AI agents at risk; a zero-day was published that defeats default Windows 11 BitLocker protections; and multiple severe Linux vulnerabilities (including CopyFail) and supply‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
98f1bbc2aa0bef8bc2c1543081f150900f3590ed080021c2950332c0a2c3a1ce
Enrichment time
2026-05-28T20:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.