Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them,...
A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them,...
Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file...
SpaceXAI has open-sourced Grok Build, its terminal-based AI coding agent and text user interface (TUI), releasing the project’s source code...
xAI's Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage...
Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on...
Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of...
Sophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code,...
AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will...
An AI coding assistant that refuses to answer a dangerous request in its chat box can answer it anyway if...
AI coding agents (Claude Code, Cursor, Codex, and others built on skill packs such as GStack) are showing up in customer environments. They...
Scanners meant to catch malicious add-on "skills" for AI coding agents can be fooled by a few simple changes that...
Swati KhandelwalJul 01, 2026AI Coding / Vulnerability Two flaws in Cursor, an AI code editor, could let a single, ordinary-looking...
What if your AI coding assistant could be tricked into stealing your own company’s secrets – by reading a single...
What if your AI coding assistant could be tricked into stealing your own company’s secrets – by reading a single...
What if your AI coding assistant could be tricked into stealing your own company’s secrets – by reading a single...