Skip to main content
Security AI

Git configuration flaws expose several AI coding agents to local command execution

Manifold Security disclosed eight flaws across seven command-line AI coding agents that can cause a repository's Git configuration to name a command executed on a developer's machine. The article says exploitation requires a received repository with its .git directory intact, rather than an ordinary clone. It reports fixes for goose, Claude Code and Cursor; Hermes Agent, Qwen Code, Grok Build and a second Claude Code path remained unpatched at publication. OpenAI published three CVEs covering the class in Codex, according to the article.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security AI
Security AI

Google opens Fairwind cyber-defense program to selected partners

Google said it launched the Fairwind Program for a trusted group of Google Cloud customers, government agencies and cybersecurity partners. The program initially provides access to Gemini 3.8 Flash Cyber and the CodeMender harness...

Security AI
Security AI

AISLE reports six curl CVEs fixed in version 8.22.0

AISLE reported that curl 8.22.0 fixes six low-severity CVEs that curl's security team reviewed and assigned public identifiers. The company said its autonomous system submitted 29 reports after other AI cybersecurity systems had p...

Security
Security

Anthropic and OpenAI report new controls for advanced cyber models

Anthropic and OpenAI reported new access limits and safeguards around advanced cybersecurity models. Anthropic said Claude Mythos 5.1 is limited to trusted-access programs and support work in cybersecurity and life sciences, while...

Products AI
Products AI

Adobe brings Firefly and creative tools into Slack

Adobe has integrated its creative tools into Slack, allowing Slackbot to route prompts to Firefly, Photoshop, Premiere and Acrobat and return generated files in channels. The integration can use channel conversations, canvases and...

Policy AI
Policy AI

US backs OpenAI's fair-use argument in Times copyright case

The Trump administration filed a statement of interest supporting OpenAI's argument that training large language models on copyrighted text can be fair use in The New York Times' copyright lawsuit against OpenAI and Microsoft. The...

AI Infrastructure
AI Infrastructure

AWS opens Bedrock access to GPT-5.6 models from Australia

AWS says teams using its Sydney and Melbourne regions can now invoke OpenAI GPT-5.6 Sol, Terra and Luna through Amazon Bedrock global cross-Region inference. Applications call a local Bedrock Runtime endpoint while AWS routes proc...