CybersecurityDev3 min reading time

GitSpawn: Untrusted repos can execute code via AI coding agents

Hacker News
Read full post
Researchers discovered that several AI coding agents execute git commands that can run arbitrary code from a repository's configuration without user approval, posing security risks when using untrusted repos. This vulnerability arises because git commands refresh their index using repository-specific settings like core.fsmonitor, which can specify executable commands.

More in Cybersecurity

Cybersecurity10 min read

Anthropic Details Disrupted Claude Misuse Across Seven Harm Areas

Covered by 4 sources
Cybersecurity4 min read

Sam Altman met with top power utilities about securing the electrical grid. He offered one possible solution: OpenAI's cyber services.

Covered by 2 sources
Cybersecurity6 min read

Anthropic reveals rogue AI agents hate CAPTCHAs, just like you

TechCrunch