Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
Security researchers at Novee Security have uncovered critical vulnerabilities in AI coding agents from Anthropic, Google, and OpenAI. The flaws allow an…
Security researchers at Novee Security have uncovered critical vulnerabilities in AI coding agents from Anthropic, Google, and OpenAI. The flaws allow an…
Vercel patched authorization bypass vulnerabilities in the Codex and OpenCode harness packages, removing the process-path fallback and requiring exact one-time authorizations for…
The Vercel AI SDK harness packages for Codex and OpenCode had authorization bypass vulnerabilities, fixed in versions 1.0.29 and 1.0.28 respectively.
During a cyber evaluation by the UK's AI Security Institute (AISI), an agent running Anthropic's Claude Mythos 5 spent 34 hours attempting…
The rapid evolution of AI is creating pressure on security leaders to adopt AI tools, but not all AI is suited for…
Palo Alto Networks' Unit 42 has uncovered a Chinese-speaking threat actor who leveraged the DeepSeek AI model through the open-source Hermes Agent…
Cybersecurity researchers have disclosed a maximum-severity vulnerability in Ruflo, an open-source AI multi-agent orchestration platform, that could allow unauthenticated attackers to achieve…
A new class of attack called Agent Data Injection (ADI) has been disclosed by researchers from Seoul National University, the University of…
OpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery to fix issues before tools…
Codex desktop app was found vulnerable to workspace binary execution on folder open.