HeadFlash

Topic · 25 stories

AI coding agents security: attacks and flaws, news

Edited by Marcin Rybak

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Timeline

  1. Remote code execution flaw found in OpenCode AI coding agent Security
  2. Plugin4Shell flaw let a git branch trick bypass safety locks on four AI coding agents AI
  3. Plugin4Shell zero-click flaw hits Claude Code, Codex, Gemini CLI and Copilot AI
  4. PhantomFix Flaw Hijacks Sentry Seer Autofix Agent Security
  5. Claude Code vulnerability allows code execution via malicious pull requests Security
  6. New ‘hallusquatting’ attack exploits AI coding assistants to install malware AI
  7. Four AI Coding Tools Hit by Sandbox Escapes via Prompt Injection AI
  8. HalluSquatting AI attack could hijack your computer AI
  9. GhostApproval Attack Tricks AI Coding Tools into Writing SSH Keys AI
  10. Ghostcommit Hides Prompt Injection in PNG Images to Steal Repository Secrets AI
Show older (15 stories)
  1. HalluSquatting Exploits AI Hallucinations to Build Agentic Botnets Security
  2. GhostApproval Tricks Six AI Coding Tools Into Writing SSH Keys via Symlinks Security
  3. Friendly Fire Attack Manipulates Claude Code and Codex Into Running Malicious Code Security
  4. Ghostcommit Steals Repository Secrets by Hiding Prompt Injection in PNG Images Security
  5. Researchers Warn AI Agents Can Be Turned Into Botnets via Hallucination Exploit AI
  6. GitLost Vulnerability Lets Attackers Leak Private Repos via GitHub AI Agent AI
  7. GitHub AI Agent Tricked into Leaking Private Repositories via Prompt Injection Security
  8. Mozilla Researchers Show Claude Code Can Be Tricked into Reverse Shell via DNS AI
  9. Critical Amazon Q Extension Vulnerability Allows Code Execution via Malicious Repo Security
  10. Claude Code Can Be Tricked Into Reverse Shell via DNS Text Record Security
  11. AI Coding Agents Bypass Package Verification, Fueling Supply Chain Attacks AI
  12. Claude Code Repo Attack Delivers Reverse Shell via DNS TXT Record Security
  13. 15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers Security
  14. Microsoft GitHub Repositories Compromised with Credential-Stealing Malware Security
  15. Microsoft Repos Used to Deliver Malware via AI Coding Tools Security