Switch language한국어
Back to the list

AI coding agents breached: attackers targeted credentials, not models | VentureBeat

TL;DR AI

Key summary

2 min read
  1. Researchers found critical flaws in AI coding agents like OpenAI Codex, Anthropic Claude Code, and GitHub Copilot.

  2. Exploits used crafted repository names, hidden instructions, prompt injection, and sandbox or permission bypasses to steal tokens or trigger unauthorized execution.

  3. Vendors including OpenAI, Anthropic, Microsoft, and GitHub patched the issues; some were classified as critical.

  4. The incidents highlight that the biggest risk in AI coding tools is often exposure of real systems and enterprise secrets, not model weights.

Read the original