AI coding agents breached: attackers targeted credentials, not models | VentureBeat

TL;DR AI
2 min readKey summary
Researchers found critical flaws in AI coding agents like OpenAI Codex, Anthropic Claude Code, and GitHub Copilot.
Exploits used crafted repository names, hidden instructions, prompt injection, and sandbox or permission bypasses to steal tokens or trigger unauthorized execution.
Vendors including OpenAI, Anthropic, Microsoft, and GitHub patched the issues; some were classified as critical.
The incidents highlight that the biggest risk in AI coding tools is often exposure of real systems and enterprise secrets, not model weights.
