GitHub's AI Coding Agent Leaked Private Repos With a Single Issue
Noma Labs' GitLost write-up shows a single public-repo issue can coerce GitHub's coding agent into leaking private repo contents.
Tag
Noma Labs' GitLost write-up shows a single public-repo issue can coerce GitHub's coding agent into leaking private repo contents.
OpenClaw collected nine CVEs in four days with 135,000 instances exposed. Plus: GitHub RCE, Flowise exploitation, and CrewAI trust failures.
Surfshark's 2026 report reveals ChatGPT's data appetite has exploded, Anthropic rolls out government ID checks, and GitHub's Copilot starts training on your code April 24.
GitHub's new data policy uses Free, Pro, and Pro+ user interactions to train AI models by default. Your private repo code while using Copilot is fair game unless you disable it.
A self-propagating malware campaign steals developer credentials via malicious VS Code extensions, then force-pushes cryptocurrency-stealing code into legitimate Python projects.