organization · 3 records
Manifold Security

One Extension Could Hijack AI Assistants Across Multiple Browsers
Security researchers identified a method where malicious browser extensions can hijack AI assistants in various Chromium-based products.
1 outlet Markets read Cyber read

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Several AI coding agents are susceptible to remote code execution when they automatically run malicious commands defined in a repository's Git configuration file.
1 outlet Cyber read

Microsoft Azure DevOps flaw allows unauthorized access to sensitive source code
A vulnerability in Microsoft's official Azure DevOps MCP server allows hidden HTML comments in pull request descriptions to hijack AI coding agents, enabling unauthorized access to source code, secrets, and work items across projects via a confused-deputy attack.
1 outlet Markets read