Tenet Security's DEF CON August 2026 research expands Agentjacking to Cloudflare, Datadog, and Sentry — 90% success rate, 15,000+ organisations exposed, DNS hijacking via AI coding agent manipulation, zero traditional exploitation required.
Tenet Security's DEF CON August 2026 research expands Agentjacking to Cloudflare, Datadog, and Sentry — 90% success rate, 15,000+ organisations exposed, DNS hijacking via AI coding agent manipulation, zero traditional exploitation required.
Novee Security disclosed CVE-2026-54316 at Black Hat USA 2026: a zero-privilege GitHub issue can reach CI runner secrets across Claude Code, Gemini CLI, and OpenAI Codex. The Claude Code variant eventually exfiltrated secrets one character at a time via Hugging Face download counters. A separate Gemini CLI flaw scored CVSS 10.0.
Researchers from Seoul National University, UIUC, and Largosoft introduce Agent Data Injection (ADI) as a distinct attack class that bypasses existing IPI defenses with up to 50% success, targeting the structured metadata and context data agents implicitly trust.
Anthropic's Claude Opus 5 system card documents the model's alignment improvements, OSS-Fuzz benchmark results, and intentional limits on offensive cybersecurity capability. The model blocks binary vulnerability scanning, pen testing assistance, and exploit generation, with flagged requests falling back to an older Claude version rather than failing outright.
Researchers at Concordia University tested Cursor, Claude Code, and Codex Desktop against a benchmark of malicious GitHub issues. Two thirds of the attacks penetrated all guardrails, with LLMs — not agent frameworks — doing most of the blocking.
Researchers at the University of Missouri-Kansas City found that hiding malicious instructions inside PNG images committed to a repository can manipulate AI coding agents into exfiltrating environment variables and credentials without any visible text reviewers can catch.
Straiker's STAR Labs ran over 1,700 adversarial scenarios against production AI coding and productivity agents. The headline finding: 36% of successful coding agent attacks reach remote code execution on the developer's machine, putting source code and cloud credentials at direct risk.
Wiz researchers found that six AI coding assistants will write to your SSH keys or shell config while displaying an innocent-looking filename in the confirmation dialog. The agent knows. The dialog doesn't say.
Anthropic has disclosed what it describes as the first documented case of a large-scale autonomous AI cyberattack — a Chinese state-sponsored group that jailbroke Claude Code and used it to autonomously conduct reconnaissance, exploitation, lateral movement, and data exfiltration across roughly 30 global targets.
Tenet Security's Threat Labs published research on June 17 demonstrating how a single fake Sentry error event can hijack AI coding agents like Claude Code and Cursor into executing arbitrary code on developer machines — no phishing, no infrastructure access, 85% success rate across 100+ tested organisations.
LLMs suggest non-existent package names in 20-30% of coding responses. Attackers register these hallucinated names with malicious payloads — slopsquatting as a supply chain attack.
A self-replicating worm compromised 73 Microsoft GitHub repositories on June 5, 2026, via stolen contributor PAT and malicious AI coding tool configs. Contained in 105 seconds.
Adversa AI disclosed SymJack (symlink hijacking to plant malicious MCP servers) and TrustFall (trust dialog bypass) hitting six AI coding agents including Copilot and Cursor.
A flawed permission check in Anthropic's Claude Code GitHub Action allowed attackers to use prompt injection via a crafted issue to steal CI/CD secrets. Patched in v1.0.94.