Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
That is the finding in a proof-of-concept published Wednesday by the AI Now Institute, an attack it calls “Friendly Fire.” It works against Anthropic’s Claude Code and OpenAI’s Codex when either is running in an autonomous mode that approves its own
Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices
Tracked as CVE-2026-11405, the vulnerability allows unauthenticated attackers to access a device’s web management interface.
The post Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices appeared first on SecurityWeek.
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
The affected tools are Amazon Q Developer, Anthropic’s Claude Code, Augment, Cursor, Google Antigravity, and Windsurf.
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
The activity dates back to at least August 2022, according to DNS threat intelligence firm Infoblox. Once such campaign, observed earlier this year, involved the
Mount Royal University confirms breach as hackers claim attack
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
Hackers exploit Roundcube flaw to spy on academic researchers
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
The agents are not malicious. They just do a lot of things that, to a behavioral engine, look exactly like an attack.
Decrypting browser credentials, listing what sits in Windows’ credential store,
