AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found… Continue reading
Tag: coding
AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
Ravie LakshmananSep 24, 2026Hacking News / Cybersecurity News This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A… Continue reading
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
A flaw in four widely used AI coding agents lets someone who controls a plugin’s code repository swap the plugin an agent installs for a malicious one, even… Continue reading
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Swati KhandelwalSep 16, 2026Artificial Intelligence / Software Security Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100… Continue reading
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting… Continue reading
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
Swati KhandelwalAug 11, 2026AI Security / Cyber Attack A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source… Continue reading
Ravie LakshmananJul 17, 2026Social Engineering / Malware North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal… Continue reading
Ravie LakshmananJul 13, 2026Cybersecurity / Hacking Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That’s supposed to be the… Continue reading
Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer’s computer. The assistant asks permission to… Continue reading
Sophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are setting off detection… Continue reading









