Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI Coding Agents Vulnerable to Running Malicious Code

AI Coding Agents Vulnerable to Running Malicious Code

Posted on July 9, 2026 By CWS

Recent research has unveiled a critical vulnerability in AI coding agents that are intended to identify security flaws in open-source code. These agents, rather than safeguarding systems, could inadvertently execute malicious scripts on the host machine. This vulnerability was demonstrated in a proof-of-concept by the AI Now Institute, which termed the attack ‘Friendly Fire’.

AI Coding Agents Under Scrutiny

The study specifically tested Anthropic’s Claude Code and OpenAI’s Codex, both operating in autonomous modes capable of approving their own commands. The attack effectively turns the agents’ primary function—examining untrusted code for security issues—against them. Researchers Boyan Milanov and Heidy Khlaaf conducted trials on various setups, showing how these AI tools could be manipulated to run harmful code.

The autonomous modes in Claude Code and Codex utilize classifiers to determine command safety, pausing only for commands deemed risky. However, when activated, these modes can potentially allow the execution of malicious code without user intervention.

Exploit Details and Implications

This vulnerability does not stem from specific software versions but rather from a fundamental design flaw. The researchers demonstrated the exploit using the Python library geopy, introducing a script named ‘security.sh’ that covertly executed a payload. By cleverly disguising the binary as a harmless file, they managed to bypass the agents’ safety checks.

Previous attempts to exploit AI agents have typically involved configuration files requiring user trust. This new method, however, leverages a README.md file, which is commonly found and trusted in repositories, thereby broadening the scope for potential misuse.

Recommendations and Precautions

AI Now’s report highlights that simply updating models will not mitigate this issue, as the models cannot yet consistently differentiate between code and executable instructions. They urge policymakers and vendors to reassess the deployment of AI agents in security roles, noting the rapid adoption outpacing necessary security measures.

Although the proof-of-concept remains a controlled experiment, the researchers stress the importance of not allowing untrusted code to interact with command-capable agents. They advise teams using these tools to be vigilant for any unauthorized execution of binaries or scripts prompted by documentation files.

While sandboxing offers some protection, it is not foolproof, and previous vulnerabilities have allowed code to escape these confines. The researchers advocate for stricter operational modes that require user verification for each step, albeit at the cost of automation.

In conclusion, this research underscores the need for enhanced security practices in deploying AI coding agents. As the technology continues to evolve, both developers and users must remain diligent in identifying and mitigating potential threats.

The Hacker News Tags:AI research, AI security, AI vulnerabilities, Anthropic Claude, autonomous agents, code scanning, coding agents, Cybersecurity, malicious code, OpenAI Codex, proof-of-concept, security risks, Software Security, software testing, tech news

Post navigation

Previous Post: Unpatched Tenda Firmware Backdoor Risks Device Security
Next Post: GhostApproval Flaw in Popular AI Coding Tools Raises Security Concerns

Related Posts

26 Malicious Apps on Apple Store Targeting Crypto Wallets 26 Malicious Apps on Apple Store Targeting Crypto Wallets The Hacker News
Chinese Hackers Exploit ArcGIS Server as Backdoor for Over a Year Chinese Hackers Exploit ArcGIS Server as Backdoor for Over a Year The Hacker News
Critical Lanscope Endpoint Manager Bug Exploited in Ongoing Cyberattacks, CISA Confirms Critical Lanscope Endpoint Manager Bug Exploited in Ongoing Cyberattacks, CISA Confirms The Hacker News
ENCFORGE Ransomware Hits AI Files in Langflow Attack ENCFORGE Ransomware Hits AI Files in Langflow Attack The Hacker News
RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers The Hacker News
Pentera Enhances AI Security with Validation Engines Pentera Enhances AI Security with Validation Engines The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AWS Enhances Network Firewall with Rule Hit Count Feature
  • Anthropic Enhances AI Security Access, Launches $35M Fund
  • Malware Service Exploits Adobe-themed Domain for Attacks
  • AI and Security: Key Insights from This Week’s Cyber Threats
  • Iran-Linked Cyberattack Disrupts UK Power Plant for Four Days

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AWS Enhances Network Firewall with Rule Hit Count Feature
  • Anthropic Enhances AI Security Access, Launches $35M Fund
  • Malware Service Exploits Adobe-themed Domain for Attacks
  • AI and Security: Key Insights from This Week’s Cyber Threats
  • Iran-Linked Cyberattack Disrupts UK Power Plant for Four Days

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark