GitHub's AI Coding Agent Leaked Private Repos With a Single Issue
Noma Labs' GitLost write-up shows a single public-repo issue can coerce GitHub's coding agent into leaking private repo contents.
Tag
Noma Labs' GitLost write-up shows a single public-repo issue can coerce GitHub's coding agent into leaking private repo contents.
A 1B-parameter foundation model trained on 125M crystal structures screens 2.4M compounds and laboratory-confirms four new superconductors.
Calling an AI an 'AI employee' made 1,261 managers miss 18% more errors and push 44% more questionable work upward. The 'coworker' framing is a safety issue.
OpenClaw collected nine CVEs in four days with 135,000 instances exposed. Plus: GitHub RCE, Flowise exploitation, and CrewAI trust failures.
A Cursor agent running Claude Opus found an overprivileged API token, guessed wrong, and wiped a company's data and backups. The real failure wasn't the model.
The open-source AI coding agent lets you bring any model to the terminal. We break down what works, what doesn't, and who should use it.
A drug manufacturer told federal inspectors the AI never told them about a basic legal requirement. The FDA was not amused.
Meta's Model Capability Initiative captures mouse movements, keystrokes, and screenshots from employee computers. The goal: build AI agents that can replace the workers generating the training data.
We tracked the boldest AI predictions from November-December 2025 and scored them against April 2026 reality. The agents didn't show up. The jobs did disappear.
Microsoft's Azure AI Foundry hit with a maximum-severity privilege escalation, Langflow exploited within hours of disclosure, and LiteLLM discloses three vulnerabilities after surviving a supply chain attack.
The fastest-growing GitHub project ever just became the biggest AI agent security disaster of 2026. Here's what happened and why it matters.
We tracked the boldest AI predictions from October 2025 and scored them against April 2026 reality. Spoiler: the crystal balls are still broken.
OpenClaw went from one CVE to nine in four days, with 12% of its marketplace confirmed malicious. Plus: ChatGPT's patched DNS exfiltration flaw.
The fastest-growing open source project in GitHub history has become 2026's first major AI security disaster, with 135,000+ exposed instances, 9 CVEs in 4 days, and malware-laced skills.
OpenClaw's security crisis escalates with nine new vulnerabilities including a CVSS 9.9 admin bypass, plus researchers confirm nearly 1 in 8 marketplace skills steal user data.
After 12% of ClawHub skills turned out to be malware and 135,000 instances were exposed, Cisco releases DefenseClaw and OpenClawd adds verified skill screening. The AI agent ecosystem is racing to catch up.
135,000+ GitHub stars. Four critical CVEs. 12% of its marketplace poisoned with malware. OpenClaw's rise to fame came with a security crisis that every AI agent user needs to understand.
Microsoft's new Copilot Cowork uses Claude's reasoning engine for multi-hour autonomous tasks. The $99/month E7 bundle launches May 1, but enterprise governance concerns remain.
Security scanners become attack vectors, AI agent platforms get RCE'd before patches exist, and 400+ GitHub repos fall to GlassWorm. Plus: a new secrets scanner built for AI coding agents.
The creator of Gitleaks releases a faster, more accurate successor with 98.6% recall and native AI agent integration. Here's why it matters.
Meta's CEO is developing a personal AI that bypasses traditional management layers. Internal tools like Second Brain and MyClaw are already changing how the company works.
Unit 42 researchers catch indirect prompt injection attacks actively weaponizing AI agents on live websites, from forced transactions to data exfiltration
A single HTTP request can own your AI workflow server. CVE-2026-33017 shows why authentication shouldn't be optional.
An open-source AI agent using interactive scaling beats OpenAI's GPT-5-high on Humanity's Last Exam. Here's what makes it different.