Related Threat Clusters
-
Critical Gemini CLI Vulnerability Allows Arbitrary Code Execution
A critical vulnerability in Google’s Gemini CLI, tracked as CVE-2026-12537, has been disclosed, enabling attackers to execute arbitrary code in CI/CD environments, particularly within GitHub Actions workflows. This flaw…
2 articles · Updated June 29, 2026 -
Critical RCE Vulnerability in Google Gemini CLI Exposes CI/CD Pipelines
Google has issued urgent security updates for its Gemini CLI and GitHub Action to address a critical vulnerability, identified as GHSA-wpqr-6v78-jr5g. This flaw allows for Remote Code Execution (RCE) attacks due to…
14 articles · Updated April 27, 2026 -
Critical RCE Vulnerabilities in Cursor IDE Enable Zero-Click Prompt Injection Attacks
Cato AI Labs disclosed two critical remote code execution (RCE) vulnerabilities in Cursor IDE, tracked as CVE-2026-50548 and CVE-2026-50549. These vulnerabilities allow attackers to exploit zero-click prompt injection,…
37 articles · Updated July 1, 2026 -
New Cryptographic Context Injection Attack Targets AI Coding Agents
A novel attack technique named Cryptographic Context Injection has been identified, allowing attackers to inject malicious instructions into AI models like Grok and Gemini. This method involves shipping encrypted…
11 articles · Updated August 20, 2026 -
AI-Driven Botnet Migration by Russian Actor in Just Six Minutes
A Russian-speaking threat actor known as 'bandcampro' utilized AI to migrate a command-and-control (C&C) botnet in just six minutes, performing only 11% of the work manually. The operation targeted eight computers in a…
21 articles · Updated July 14, 2026 -
Critical Vulnerability in MCP Protocol Exposes 200,000 AI Servers to Remote Code Execution
A report by OX Security has identified a critical vulnerability in the Model Context Protocol (MCP) developed by Anthropic, potentially exposing over 200,000 AI servers to remote code execution. The flaw lies in the…
12 articles · Updated April 16, 2026 -
InstallFix Campaign Exploits AI Trust to Deliver Malware via Fake Install Pages
The InstallFix campaign targets users by creating fake installation pages for Anthropic's Claude AI, tricking them into executing malware. This sophisticated social engineering tactic exploits the growing reliance on AI…
53 articles · Updated May 5, 2026 -
AI-Generated Security Patches Fail 74% of the Time, Study Reveals
A recent study by 1Password's Off-by-1 Labs found that AI-generated patches for software vulnerabilities succeeded only 26% of the time. The research analyzed 6,080 patches created by AI models ChatGPT 5.5 and Claude…
13 articles · Updated August 6, 2026 -
Vulnerabilities in AI Coding Tools Expose GitHub Secrets to Attackers
AI coding tools from Anthropic, Google, and OpenAI were found vulnerable to malicious GitHub issues. Researchers at Novee Security identified flaws in Claude Code, Gemini CLI, and Codex that could allow remote code…
2 articles · Updated August 7, 2026 -
GitHub Breach: 3,800 Internal Repositories Compromised via Malicious VS Code Extension
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
149 articles · Updated May 20, 2026
Recent Intelligence Reports
- SymJack attack — adversa.ai · August 20, 2026
- AI coding tools vulnerable to malicious GitHub issues | brief — Scworld · August 7, 2026
- Patch Claude Code and Gemini CLI before GitHub issues reach CI secrets — Feeds.4Sysops · August 7, 2026
- Human oversight is still critical as AI patching tools miss security risks — Csoonline · August 7, 2026
- Inside The Influence And Fraud Patriot Bait Campaign — www.trendmicro.com · August 6, 2026
- Cymulate, which found — cymulate.com · July 23, 2026
- Week of Sandbox Escapes — www.pillar.security · July 21, 2026
- AI agents can escape sandboxes without ever breaking them — Csoonline · July 21, 2026