RoguePilot - Vulnerability

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
February 25, 2026
Last Seen
July 7, 2026

RoguePilot is a vulnerability tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.

RoguePilot is a vulnerability tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed February 25, 2026; most recent activity July 7, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • GitLost: a public GitHub issue can steer an org's Agentic Workflow into leaking private repo contents, and a one-word prefix ("Additionally") bypassed the threat — Reddit · July 7, 2026
  • GitHub Copilot Exploited to Perform Full Repository Takeover via Passive Prompt Injection — Cybersecuritynews · February 25, 2026

Frequently asked questions

What is RoguePilot?

RoguePilot is a vulnerability tracked by ThreatCluster, appearing in 2 threat clusters built from 2 intelligence report mentions.

Is RoguePilot still active?

The most recent intelligence report mentioning RoguePilot on ThreatCluster is dated July 7, 2026. Activity was first observed February 25, 2026, giving a tracked span from then to July 7, 2026.

What is RoguePilot associated with?

Across ThreatCluster reporting, RoguePilot most frequently co-occurs with Data Breach, Orca Research Pod, T1567 - Exfiltration Over Web Service, Copilot, GitHub, among 12 tracked related entities.

What are the latest developments involving RoguePilot?

The most significant recent cluster is “New GitHub Exploit Allows AI Coding Agents to Execute Malicious Payloads” (58 articles · Updated June 28, 2026). RoguePilot appears across 2 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on RoguePilot?

RoguePilot appears in 2 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown