CodeQL is a tool tracked by ThreatCluster, appearing in 4 threat clusters built from 3 intelligence report mentions.
CodeQL is a tool tracked across 4 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed April 28, 2026; most recent activity July 12, 2026.
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
Researchers from the ASSET Research Group demonstrated a new attack method called 'Ghostcommit' that hides malicious instructions within PNG images to bypass AI code reviewers. The attack exploits a significant gap in…
A security demonstration revealed that the AI-powered code reviewer, Claude, can be tricked into approving malicious code by spoofing a trusted developer's identity using two simple Git commands. The attack exploits the…
James Kettle from PortSwigger discusses the top web hacking techniques of 2025 and anticipates the influence of large language models (LLMs) on future vulnerabilities. He emphasizes the importance of having a robust…
CodeQL is a tool tracked by ThreatCluster, appearing in 4 threat clusters built from 3 intelligence report mentions.
The most recent intelligence report mentioning CodeQL on ThreatCluster is dated July 12, 2026. Activity was first observed April 28, 2026, giving a tracked span from then to July 12, 2026.
Across ThreatCluster reporting, CodeQL most frequently co-occurs with Data Breach, Malware, Prompt Injection, Supply Chain Attack, Cline Supply Chain Compromise, among 12 tracked related entities.
The most significant recent cluster is “GitHub Breach: 3,800 Internal Repositories Compromised via Malicious VS Code Extension” (149 articles · Updated May 20, 2026). CodeQL appears across 4 threat clusters in total, listed above with sources.
CodeQL appears in 3 intelligence report mentions across 4 deduplicated threat clusters, aggregated from 17,000+ monitored sources.