LIVE · cybersecurity feed
Live wire
CVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildHackers Are Probing PaperCut Servers, and 47% Still Have No PatchNew Malware Uses Fake CAPTCHAs to Deploy BackdoorCVE-2026-76581 · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCECVE-2026-76639 · Hack One Robot, Reach the Next: Unitree G1 Security FlawsRhysida Ransomware Group Targets Berlin Government Ahead of VoteThe Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn
vulnerability

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive

zeroday.news ·

Manifold Security has reported the discovery of eight security vulnerabilities across seven distinct command-line AI coding agents. The core mechanism of these flaws involves a malicious Git configuration file within a repository, which can instruct the AI agent to execute an arbitrary command on the developer's machine. Four of these identified vulnerabilities remain unpatched at the time of the report's publication.

The reported vulnerabilities leverage the way certain AI coding agents interact with Git repositories. Specifically, a repository's `.git/config` file can be crafted to specify a command that the agent then executes. This execution occurs with the privileges of the user running the agent and bypasses any sandboxing mechanisms the agent might employ. Furthermore, the execution proceeds without requiring an explicit approval prompt from the user, making the attack potentially stealthy.

For successful exploitation, the malicious repository must be introduced to the developer's system. This typically implies that the developer either clones a repository containing the malicious configuration or initializes a repository from untrusted sources. Once the repository is present and the AI agent interacts with it in a manner that triggers the Git configuration, the embedded command is executed.

The affected AI agents include those from prominent developers such as Claude, Codex, and Cursor, among others. Products in this category are designed to assist developers by automating coding tasks, generating code, or providing intelligent suggestions. Their integration with version control systems like Git is a common feature, enabling them to operate directly within a developer's workflow.

Mitigation for this class of vulnerability generally involves exercising caution when interacting with untrusted repositories. Developers should avoid cloning or initializing Git repositories from unknown or unverified sources. Additionally, security best practices suggest reviewing the contents of `.git/config` files, especially in new or unfamiliar repositories, before allowing AI agents or other tools to interact with them. Vendors of AI agents are also expected to implement more robust parsing and execution policies for Git configurations, potentially by disallowing arbitrary command execution or by introducing explicit user prompts for such actions.

This discovery highlights a broader security concern at the intersection of AI development tools and established software development practices. As AI agents become more deeply integrated into the development lifecycle, the potential for novel attack vectors that exploit the trust placed in these tools and their underlying infrastructure increases. It underscores the ongoing need for rigorous security auditing of AI-powered development tools and for developers to maintain vigilance regarding the provenance of their code and development environments.

vulnerabilitypatchaicloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31. GeoNetwork originated at the United Nations Food and

vulnerability

Chrome and Firefox Updates Patch Dozens of Vulnerabilities

The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs. The post Chrome and Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek.

ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

cloud

Legacy Lenovo login opens 5,000 Dropbox accounts to attackers

Cloud storage biz severs old integration and urges victims to reset credentials

ransomware

Ransomware protection for MSPs: A 6-point checklist for faster recovery

Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. [...]