AWS fixed a Kiro prompt injection chain that rewrote mcp.json and launched attacker-controlled code with developer privileges ...
AWS Kiro prompt injection flaw let hidden web page text rewrite the IDE’s MCP configuration file and silently execute ...
CrashStealer Mac malware uses a signed Werkbit installer and fake password prompt to steal Keychain data, browser credentials ...
Open-source Android AI agents can turn hidden screen text into host commands, and all five tested frameworks failed at least ...
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two ...
Cursor IDE zero-day vulnerability: AI security firm Mindgard spent seven months trying to report a Windows code-execution ...
Researchers exposed seven sandbox escapes in Cursor, Codex, Gemini CLI & Antigravity. Discover how AI coding agents ...
GitHub is layering spending limits, expanded credit allowances and increasingly granular usage reporting onto Copilot, while Microsoft is reworking Visual Studio and VS Code to expose -- and reduce -- ...
Rubrik's AI chief says a second AI now judges every AI agent action in real time, replacing human review — but the judge's accuracy is unmeasured.
Researchers escaped the sandboxes of Cursor, Codex, Gemini CLI and Antigravity without breaking them. Three vendors patched; Google downgraded its two.
HalluSquatting exploits AI coding assistants that hallucinate fake repository names, letting attackers register those names ...
Google Launches Codemender For Automated Vulnerability Repair Arabian Post. clearfix>Google has released CodeMender in public preview as a managed artificial intelligence security agent designed to ...