Related Threat Clusters
-
Critical Vulnerability in Claude Code GitHub Actions Exposes Repositories to Attacks
A critical supply chain vulnerability in Claude Code’s GitHub Actions, identified by security researcher Ryota K from GMO Flat Security, allows attackers to compromise any repository using Anthropic’s CI/CD workflow.…
18 articles · Updated June 2, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
743 articles · Updated April 29, 2026 -
Ghostcommit Attack Exploits AI Reviewers to Steal Secrets
Researchers from the ASSET Research Group demonstrated a new attack method called 'Ghostcommit' that hides malicious instructions within PNG images to bypass AI code reviewers. The attack exploits a significant gap in…
9 articles · Updated July 11, 2026 -
AI Code Reviewers Vulnerable to Git Identity Spoofing Attack
A security demonstration revealed that the AI-powered code reviewer, Claude, can be tricked into approving malicious code by spoofing a trusted developer's identity using two simple Git commands. The attack exploits the…
2 articles · Updated April 16, 2026
Recent Intelligence Reports
- Spoofed Git Identity Ai Code Reviewer — www.manifold.security · July 12, 2026
- Snyk researcher Stephen Thoemmes — snyk.io · July 2, 2026
- AI Coding Agents Skip Package Verification, and Attackers Are Exploiting It — Techtimes · July 1, 2026