Plugin4Shell Exposes AI Coding Agents to RCE
A zero-click remote code execution flaw in popular AI coding agents could let attackers run malicious code without developer interaction, researchers warn.
14 results for “ai coding”
A zero-click remote code execution flaw in popular AI coding agents could let attackers run malicious code without developer interaction, researchers warn.
Two Docker Sandboxes vulnerabilities let malicious guest code read or modify macOS host files, with fixes shipped in version 0.42.0.
Google Threat Intelligence Group warns AI coding tools are prime targets for supply chain attacks.
Aurora ransomware actors use Cursor Agent AI to automate post-exploitation tasks, per Gambit Security research.
Enterprises face growing open-source vulnerability backlogs as AI tools accelerate code output.
Zhipu's GLM-5.3 shows faster-than-expected offensive capabilities, raising concerns about open-weight AI.
AI coding startup Cursor officially joins SpaceX, gaining access to its vast GPU fleet as part of a $60B deal.
Blacksmith's valuation jumps nearly 10x to $550 million as AI coding fuels demand for software validation.
A Cursor bug let repositories run commands pre-trust, even with the sandbox enabled.
Malicious MCP servers can split instructions to make AI coding agents exfiltrate secrets, ASSET reports.
Researchers identify a recurring security flaw where AI agents blindly execute commands based on predictable, hallucinated names.
A systemic vulnerability across major AI coding assistants highlights the dangerous failure of human-in-the-loop security protocols.
While AI coding tools promise efficiency, hidden security overheads and remediation expenses are complicating the true return on investment.
Researchers discover a critical vulnerability where AI coding agents are tricked into executing malicious code via hallucinations.