RoguePilot is a vulnerability tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.
RoguePilot is a vulnerability tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed February 25, 2026; most recent activity July 7, 2026.
Researchers from Mozilla's 0DIN have demonstrated a new attack vector that allows AI coding agents, specifically Anthropic's Claude Code, to execute malicious payloads from seemingly benign GitHub repositories. The…
A cybersecurity incident has emerged where attackers exploited GitHub Issues to inject malicious instructions that are processed by Copilot during the launch of a Codespace. This attack leverages the zero-day…
RoguePilot is a vulnerability tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.
The most recent intelligence report mentioning RoguePilot on ThreatCluster is dated July 7, 2026. Activity was first observed February 25, 2026, giving a tracked span from then to July 7, 2026.
Across ThreatCluster reporting, RoguePilot most frequently co-occurs with Data Breach, Orca Research Pod, T1567 - Exfiltration Over Web Service, Copilot, GitHub, among 12 tracked related entities.
The most significant recent cluster is “New GitHub Exploit Allows AI Coding Agents to Execute Malicious Payloads” (58 articles · Updated June 28, 2026). RoguePilot appears across 2 threat clusters in total, listed above with sources.
RoguePilot appears in 2 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.