AI News
107 articles — Page 7 of 9
Today
GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code
The models they tested through Copilot, Claude from Anthropic, and Gemini from Google, refused almost every harmful request when asked directly. Reframed as steps in a normal coding task, they produced the harmful…
GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
Everything a reviewer would check matches. The commit's hash does not. That matters because so many systems treat a verified commit hash as a permanent, unique name for its contents.
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
The activity cluster, tracked by Elastic Security Labs under the moniker REF6045 , involves infecting victims through fake CAPTCHA verification pages that deceive them into running a malicious command that installs a…
New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware
New research, which its authors call HalluSquatting , turns that habit into an attack: work out the fake names an AI reliably invents, register them first, and wait for the assistant to fetch your trap on a user's…
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
The agents are not malicious. They just do a lot of things that, to a behavioral engine, look exactly like an attack.
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
The activity dates back to at least August 2022, according to DNS threat intelligence firm Infoblox. Once such campaign, observed earlier this year, involved the actor luring victims with a trojanized 7-Zip installer…
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
The affected tools are Amazon Q Developer, Anthropic's Claude Code, Augment, Cursor, Google Antigravity, and Windsurf. Wiz calls the pattern GhostApproval and published it on July 8.
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
That is the finding in a proof-of-concept published Wednesday by the AI Now Institute, an attack it calls " Friendly Fire. " It works against Anthropic's Claude Code and OpenAI's Codex when either is running in an…
Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images
"You can also @-mention Instagram accounts in the Meta AI app to bring specific Instagram profiles right into your images," the social media giant said in a post.
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
The vulnerability, tracked as CVE-2026-50656 (CVSS score: 7.8), is a privilege escalation issue in the Microsoft Malware Protection Engine ("mpengine.dll"), which provides scanning, detection, and cleaning capabilities…
AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up
That is the gap, and it is not your fault. The tools and runbooks most teams run on were built for attackers who work at human speed. AI-driven attacks do not, and they run at scale. Save your seat for the free webinar,…
My thoughts on Fable
I’ve been using Fable quite a bit since it came back (but not for long…) and I’ve barely used it to do any building. I like Anthropic’s models mostly for their thinking, they’re resourcefu...