5 min read
News Brief Researchers at the University of Missouri-Kansas City found that hiding malicious instructions inside PNG images committed to a repository can manipulate AI coding agents into exfiltrating environment variables and credentials without any visible text reviewers can catch.