Skip to content
AppSec Santa Weekly

#7 — Bitwarden CLI Worm Hunts AI Coding Assistants, Cursor+GPT-5.5 Tops Endor's League, Checkmarx Data Hits the Dark Web

Shai-Hulud's Third Coming backdoors @bitwarden/cli to harvest Claude Code, Gemini, and Codex tokens. Cursor+GPT-5.5 takes #1 in Endor's Agent Security League at 23.5% — six points above last week's leader. Checkmarx's March 23 stolen data appears on the dark web. 49 releases tracked.

| 49 releases 18 min read

Want this in your inbox?

Every Tuesday, no spam.

Subscribe