#supply-chain

9 articles

Agentjacking: Fake Sentry Bug Hijacks 100+ AI Coding Agents

Tenet Security proved that a single injected Sentry error can make Claude Code, Cursor, and Codex execute attacker-controlled code…

Claude Code Silently Skipped Your Security Prompt — Malicious Repos Could Disable It

CVE-2026-33068 let attackers bypass Claude Code's workspace trust dialog by committing a malicious .claude/settings.json. Fixed in…

CVE-2026-69192: The '012.0.0.1' Address Bug That Sneaks Internal Servers Past Coding-Agent SSRF Filters

A parsing mismatch in the ip-address npm package can make your agent fetch an internal cloud-metadata server it meant to block. He…

Agent Skills Went From Zero to 670,000 in Eight Months. Now Comes the Security Reckoning.

SKILL.md conquered 26+ coding agent platforms in under a year. A Snyk audit found 13.4% of community skills contain critical secur…

Your AI Agent's Config Directory Is Now the Most Dangerous Place on Your Machine

Six major campaigns in 2026 — GhostApproval, TrapDoor, Miasma, IronWorm, Clinejection, RoguePilot — all converge on the same attac…

Beware: Your Coding Agent's "Safe Mode" Can Be Turned Into a Remote Code Execution Engine

AI Now Institute's "Friendly Fire" exploit shows that Claude Code auto-mode and Codex auto-review — the modes marketed as the safe…

Beware: Clinejection — How a GitHub Issue Title Became a Supply Chain Attack on Millions of Developers

A prompt injection in a GitHub issue title compromised Cline's CI/CD pipeline, poisoned the Actions cache, stole npm publication t…

Beware: GhostCommit Hides Prompt Injection in PNGs to Drain Your .env

A new supply-chain attack smuggles prompt-injection instructions inside image files so coding agents exfiltrate .env secrets right…

Gitlawb Zero Just Got Paranoid About Permissions — And You Should Be Too

Zero now rejects malformed permission payloads before prompting. A critical security hardening for the agent that runs in your ter…