INTEL_REPORT
LWN.net (kernel & development security) · published 5/29/2026, 2:09:30 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Nesbitt: Protestware for coding agents Andrew Nesbitt has written a blog post detailing a recent incident with the jqwik library for property-based testing in Java. On May 25, the 1.10.0 release of jqwik included a change that attempts to instruct coding agents to disregard previous instructions and delete jqwik tests and code. I think this is a new class of supply-chain input worth keeping an eye on, mostly because of how little of the existing tooling has any opinion …
https://lwn.net/Articles/1075315
sha256:c1fffafd70053ec2afd96ee81700812786d839fefb75c401ef28208c6a84e551
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
| Type | Value | Link |
|---|---|---|
| domain | system.out.print | Open → |
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.