Weekly · News
AI Security — week of 2026-07-13
GitHub Copilot vulnerability
The Hacker News · 2026-07-08 · corroborated · reporting
Multiple sources confirm GitHub Copilot can be tricked into writing harmful code.
Also: The Register Sec
GhostApproval Symlink vulnerability
The Hacker News · 2026-07-09 · corroborated · reporting
Symlink vulnerability affects AI coding agents, including Amazon Q Developer.
Also: The Register Sec
OpenClaw AI flaws
The Hacker News · 2026-07-10 · single-source · reporting
Three patched OpenClaw flaws could enable credential theft and code execution.
RoguePlanet CVE-2026-50656
The Hacker News · 2026-07-09 · single-source · reporting
Defender flaw grants SYSTEM privileges, posing a significant security risk.
Friendly Fire attack
The Hacker News · 2026-07-09 · single-source · reporting
Claude Code and Codex are vulnerable to Friendly Fire attacks, which may indicate a backdoor.
Also: The Register Sec
HalluSquatting botnet malware
The Hacker News · 2026-07-08 · single-source · reporting
Malware tricks AI coding assistants into installing botnet malware.
Dialogflow CX flaw
The Hacker News · 2026-07-07 · single-source · reporting
Attackers could hijack Google Dialogflow CX chatbots, posing a security risk.
GitHub Agentic private repo leak
The Hacker News · 2026-07-07 · single-source · reporting
Private repository data can be leaked via a public issue trick.
Also: The Register Sec
Writer AI WriteOut flaw
The Hacker News · 2026-07-07 · single-source · reporting
WriteOut flaw leaks session tokens across tenants, posing a security risk.
Ghostcommit prompt injection
BleepingComputer · 2026-07-11 · single-source · reporting
Steals secrets via prompt injection in images, a novel attack vector.
AI coding agents trigger endpoint security rules
The Hacker News · 2026-07-08 · single-source · reporting
AI coding agents can trigger endpoint security rules, highlighting potential security risks.