Skip to main content

Tag: ai coding agents

8 articles

Researchers in a university setting examine code with highlighted predictable names on a projected screen.

AI Coding Agents Exposed to Predictable Name Attacks

Researchers have made a startling discovery: AI coding agents are surprisingly predictable, often generating identical fake names for tasks like skill installs and repository requests, making them vulnerable to exploitation by attackers. This weakness was found across multiple popular coding tools, with identical names being hallucinated up to 85% of the time for repository requests and 100% for skill installs.

Analyst 207
Modern computer workstation with blank screen in a bright office setting.

AI Coding Agents Expose Sandbox Vulnerabilities

Security researchers at Pillar Security uncovered a clever way that AI coding agents can bypass sandbox defenses, exposing vulnerabilities that can allow code to run on the host system. By writing files that the host later reads, loads, or executes, these agents can cleverly circumvent sandbox rules.

Analyst 207
Laptop screen displays code on a desk with papers and notebook in a minimalist room.

AI Agents Built to Catch Malware Can Be Tricked Into Running It

Researchers have uncovered a vulnerability in AI-powered malware detection systems, cleverly dubbed Friendly Fire, that can be exploited to trick these very systems into running malicious code. This proof-of-concept hack highlights a disturbing weakness in autonomous AI coding agents designed to protect against threats.

Analyst 207
Developer workstation with laptop and coding tools, subtle security presence hinted at with blurred software interface and…

AI Coding Agents Trigger Endpoint Security Rules Meant for Attackers

In a surprising twist, over half of the blocked activity detected by Sophos in June 2026 came from developer coding assistants, not hackers, triggering endpoint security rules meant to catch malicious actors. This unexpected behavior highlights the need for a closer look at the intersection of AI-powered coding tools and cybersecurity protocols.

Analyst 207
Unix-era computer terminal in a clean lab setting with coding interface and subtle file system hint.

AI Coding Agents Expose Unix-Era Security Flaw

A clever trick that exploits a long-standing Unix security flaw, dubbed GhostApproval, can bypass human approvals in AI coding assistants, rendering consent meaningless. By manipulating a harmless-looking project file, attackers can secretly alter sensitive system settings.

Analyst 207
Cluttered modern office workstation with blurred screens and scattered papers.

AI Coding Agents Exposed to Agentjacking Attack

Imagine a sneaky new attack that tricks AI coding assistants into doing an attacker's bidding - without ever touching the victim's infrastructure. This clever hack, dubbed Agentjacking, uses a sneaky sequence of steps to get AI tools to execute malicious code on developers' machines.

Analyst 207
Developer workstation with laptop, code, notes, and coffee cups, set against a blurred office or city backdrop.

AI Coding Agents Exposed to 'Agentjacking' Attacks

Beware of "agentjacking" attacks that exploit AI coding agents' implicit trust, allowing hackers to trick them into executing malicious code on developers' machines. This new class of attack starts with a simple exploit of publicly available credentials, putting even the most secure systems at risk.

Analyst 207
Cluttered developer workstation with laptop and monitor in shared office space.

Cline Kanban Flaw Exposes AI Coding Agents to Website Hijacking

A critical vulnerability in Cline Kanban's WebSocket endpoints lets hackers hijack websites visited by developers, silently interacting with local AI agents - and it's a flaw that requires zero phishing, malware, or social engineering. This severe flaw, scoring 9.7 on the CVSS scale, puts AI coding agents at risk of website hijacking.

Analyst 207