xAI's Grok Build CLI 0.2.93 uploaded entire Git repositories including commit history and unredacted credentials to a Google Cloud Storage bucket by default. Here's what was exposed and what xAI's server-side fix left unanswered.
xAI's Grok Build CLI 0.2.93 uploaded entire Git repositories including commit history and unredacted credentials to a Google Cloud Storage bucket by default. Here's what was exposed and what xAI's server-side fix left unanswered.
Research published in June 2026 documents a new supply-chain attack class targeting AI coding agent skill ecosystems: VulMask disguises malicious payloads as security vulnerabilities inside skill auxiliary resources, evading automated scanners. A Snyk audit of 3,984 skills found 13.4% carry critical-severity issues.
Salt Security's 1H 2026 State of AI and API Security report finds 92% of organizations lack the maturity to defend AI agent environments, while 99% of attack attempts originate from authenticated sources — rogue agents operating with legitimate credentials and no human oversight.
Johann Rehberger demonstrated a TOCTOU race condition against Claude Computer-Use where swapping the UI during the agent's reasoning window causes it to click the wrong element — in a working demo, the agent sends a malicious email while believing it clicked a harmless Continue button.
Researchers at the University of Missouri-Kansas City found that hiding malicious instructions inside PNG images committed to a repository can manipulate AI coding agents into exfiltrating environment variables and credentials without any visible text reviewers can catch.