Tag: ai coding agents
8 articles

AI Coding Agents Exposed to Predictable Name Attacks
Researchers have made a startling discovery: AI coding agents are surprisingly predictable, often generating identical fake names for tasks like skill installs and repository requests, making them vulnerable to exploitation by attackers. This weakness was found across multiple popular coding tools, with identical names being hallucinated up to 85% of the time for repository requests and 100% for skill installs.

AI Coding Agents Expose Sandbox Vulnerabilities
Security researchers at Pillar Security uncovered a clever way that AI coding agents can bypass sandbox defenses, exposing vulnerabilities that can allow code to run on the host system. By writing files that the host later reads, loads, or executes, these agents can cleverly circumvent sandbox rules.

AI Agents Built to Catch Malware Can Be Tricked Into Running It
Researchers have uncovered a vulnerability in AI-powered malware detection systems, cleverly dubbed Friendly Fire, that can be exploited to trick these very systems into running malicious code. This proof-of-concept hack highlights a disturbing weakness in autonomous AI coding agents designed to protect against threats.

AI Coding Agents Trigger Endpoint Security Rules Meant for Attackers
In a surprising twist, over half of the blocked activity detected by Sophos in June 2026 came from developer coding assistants, not hackers, triggering endpoint security rules meant to catch malicious actors. This unexpected behavior highlights the need for a closer look at the intersection of AI-powered coding tools and cybersecurity protocols.

AI Coding Agents Expose Unix-Era Security Flaw
A clever trick that exploits a long-standing Unix security flaw, dubbed GhostApproval, can bypass human approvals in AI coding assistants, rendering consent meaningless. By manipulating a harmless-looking project file, attackers can secretly alter sensitive system settings.

AI Coding Agents Exposed to Agentjacking Attack
Imagine a sneaky new attack that tricks AI coding assistants into doing an attacker's bidding - without ever touching the victim's infrastructure. This clever hack, dubbed Agentjacking, uses a sneaky sequence of steps to get AI tools to execute malicious code on developers' machines.

AI Coding Agents Exposed to 'Agentjacking' Attacks
Beware of "agentjacking" attacks that exploit AI coding agents' implicit trust, allowing hackers to trick them into executing malicious code on developers' machines. This new class of attack starts with a simple exploit of publicly available credentials, putting even the most secure systems at risk.

Cline Kanban Flaw Exposes AI Coding Agents to Website Hijacking
A critical vulnerability in Cline Kanban's WebSocket endpoints lets hackers hijack websites visited by developers, silently interacting with local AI agents - and it's a flaw that requires zero phishing, malware, or social engineering. This severe flaw, scoring 9.7 on the CVSS scale, puts AI coding agents at risk of website hijacking.