Tag: ai coding agents
11 articles

AI Coding Agents Expose Corporate Networks to Untrusted Code
The alarming truth is that AI coding agents are unwittingly putting corporate networks at risk by blindly trusting untrusted code, leaving them vulnerable to security breaches. Thousands of agent manifest files have already been uncovered in a wide scan of corporate domains, exposing a massive supply-chain surface that's not adequately protected.

AI Coding Agents Exposed to Code Execution via Malicious Git Configs
Researchers have uncovered a shocking vulnerability in seven AI coding agents, where malicious Git configurations can trick the tools into running attacker-supplied code on a developer's machine. This flaw, linked to Git's core.fsmonitor setting, has already led to eight security flaws, with four still unpatched.

Malicious Servers Exploit AI Coding Agents via MCP
Malicious servers are cleverly exploiting AI coding agents using a sneaky technique called GhostSplice, which breaks down secret-stealing instructions into harmless-sounding messages that the agents unwittingly combine. This allows hackers to leak sensitive information, like secret keys and proprietary data, in a way that's hard to detect.

AI Coding Agents Exposed to Predictable Name Attacks
Researchers have made a startling discovery: AI coding agents are surprisingly predictable, often generating identical fake names for tasks like skill installs and repository requests, making them vulnerable to exploitation by attackers. This weakness was found across multiple popular coding tools, with identical names being hallucinated up to 85% of the time for repository requests and 100% for skill installs.

AI Coding Agents Expose Sandbox Vulnerabilities
Security researchers at Pillar Security uncovered a clever way that AI coding agents can bypass sandbox defenses, exposing vulnerabilities that can allow code to run on the host system. By writing files that the host later reads, loads, or executes, these agents can cleverly circumvent sandbox rules.

AI Agents Built to Catch Malware Can Be Tricked Into Running It
Researchers have uncovered a vulnerability in AI-powered malware detection systems, cleverly dubbed Friendly Fire, that can be exploited to trick these very systems into running malicious code. This proof-of-concept hack highlights a disturbing weakness in autonomous AI coding agents designed to protect against threats.

AI Coding Agents Trigger Endpoint Security Rules Meant for Attackers
In a surprising twist, over half of the blocked activity detected by Sophos in June 2026 came from developer coding assistants, not hackers, triggering endpoint security rules meant to catch malicious actors. This unexpected behavior highlights the need for a closer look at the intersection of AI-powered coding tools and cybersecurity protocols.

AI Coding Agents Expose Unix-Era Security Flaw
A clever trick that exploits a long-standing Unix security flaw, dubbed GhostApproval, can bypass human approvals in AI coding assistants, rendering consent meaningless. By manipulating a harmless-looking project file, attackers can secretly alter sensitive system settings.

AI Coding Agents Exposed to Agentjacking Attack
Imagine a sneaky new attack that tricks AI coding assistants into doing an attacker's bidding - without ever touching the victim's infrastructure. This clever hack, dubbed Agentjacking, uses a sneaky sequence of steps to get AI tools to execute malicious code on developers' machines.

AI Coding Agents Exposed to 'Agentjacking' Attacks
Beware of "agentjacking" attacks that exploit AI coding agents' implicit trust, allowing hackers to trick them into executing malicious code on developers' machines. This new class of attack starts with a simple exploit of publicly available credentials, putting even the most secure systems at risk.

Cline Kanban Flaw Exposes AI Coding Agents to Website Hijacking
A critical vulnerability in Cline Kanban's WebSocket endpoints lets hackers hijack websites visited by developers, silently interacting with local AI agents - and it's a flaw that requires zero phishing, malware, or social engineering. This severe flaw, scoring 9.7 on the CVSS scale, puts AI coding agents at risk of website hijacking.