Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow SecretsThe Hacker News·Aug 7, 08:18 UTC · Aug 7, 2026Exploit / PoC in the wildCVE-2026-12537CVE-2026-54316160
Researchers flag flaw in Google’s AI coding assistant that allowed for ‘silent’ code exfiltrationCyberScoop·Jul 28, 20:26 UTC · Jul 28, 2025Exploit / PoC in the wild60
Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code ExecutionThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Exploit / PoCCVE-2026-26268CVE-2026-10591150
New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker CommandsThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Exploit / PoCCVE-2025-32711150
Sandyaa: Open-source autonomous security bug hunterHelp Net Security·May 13, 00:00 UTC · May 13, 2026Exploit / PoC45
More evidence your AI agents can be turned against youCyberScoop·Dec 5, 20:48 UTC · Dec 5, 2025Exploit / PoC in the wild60
Wiz Uncovers Critical Access Bypass Flaw in AIThe Hacker News·Jul 30, 07:43 UTC · Jul 30, 2025Exploit / PoC in the wild60
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running ItThe Hacker News·Jul 9, 05:17 UTC · Jul 9, 2026Exploit / PoCCVE-2026-3986150
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo DataThe Hacker News·Jul 7, 14:07 UTC · Jul 7, 2026Exploit / PoC145
Microsoft Issues Security Fixes for 56 Flaws, Including Active Exploit and Two ZeroThe Hacker News·Dec 10, 15:09 UTC · Dec 10, 2025Exploit / PoC in the wildCVE-2025-62223CVE-2025-62221CVE-2025-54100+6 CVEs60
Google Makes CodeMender Available as Managed AI Security AgentInfosecurity Magazine·Jul 22, 10:30 UTC · Jul 22, 2026Exploit / PoC60