Skip to content
DossierUpdated ongoing

Security of AI agents and coding tools

A dossier on the security of AI agents and coding tools in 2026. Browsers, supply chain and prompt injection, with links to the reports that remain.

23
Stories
6 July 2026
First story
2 October 2026
Latest story

As of 5 October 2026.

This dossier collects attacks on AI agents, coding tools and browsers. Each entry is one sentence from the original report. Where that report stays indexed, the link points to it. The other reports are summarised here.

Timeline

  • 6 July 2026. ZCode: Zhipus GLM-5.2 challenges Claude Code. Zhipu AI launches ZCode, its own development environment for GLM-5.2, positioning it as an affordable alternative to Claude Code and Codex.
  • 7 July 2026. Anthropic Obsidian Brain Leak: Hoax Fooled 1.1M Viewers. No Anthropic leak: a viral X post fabricated an internal 'Obsidian Brain' story that reached 1.1M views before being debunked.
  • 9 July 2026. Microsoft expands the AI scanner MDASH to all of Windows. More security updates instead of calendar patches – what this means for admins.
  • 12 July 2026. The U.S. state mandates external audits, reporting obligations, and whistleblower protections for major AI developers starting in 2027.
  • 13 July 2026. Jscrambler Package Injects Infostealer Into AI Coding Tools. Five manipulated npm versions of the Jscrambler package harvested credentials from Claude Desktop, Cursor, and other AI tools within hours.
  • 13 July 2026. A technical analysis finds that the coding AI Grok Build transmits entire codebases and unprotected credentials to SpaceXAI's cloud storage.
  • 13 July 2026. A security team shows how AI coding assistants auto-fetch invented package names, letting attackers install malware.
  • 16 July 2026. OpenAI uses AI attacker GPT-Red against its own models. The internal system automatically attacks its own AI models, uncovers new security vulnerabilities, and remains unpublished.
  • 20 July 2026. Mistral slips to ninth place in the new AI safety index. The safety index reassesses nine AI providers: No company achieves more than a grade of C+, Mistral rejects the classification.
  • 1 August 2026. Copilot worm infects Word documents – after 144 days unpatched. Håkon Måløy shows how prepared Word files can replicate themselves through Copilot – Microsoft did not close the gap after 144 days.
  • 3 August 2026. Two Chrome updates show how much Google is now relying on AI-supported search and automatic fixing of security vulnerabilities in the code.
  • 4 August 2026. JFrog exposes 54 out of 55 SQLite reports as AI forgery. An IT security researcher uncovered through Docker tests: 54 out of 55 reported SQLite vulnerabilities existed only in AI-generated CVE reports.
  • 6 August 2026. Meta launches Muse Code: Coding agent for terminals. The new terminal agent for programming tasks competes against Claude Code and Codex – at a fraction of the usual cost.
  • 8 August 2026. Zenity finds zero-click vulnerability in five AI browsers. Security researchers hijack Claude, Atlas, Gemini, Comet, and Copilot Edge via email – without any clicks from users.
  • 9 August 2026. CrowdStrike: Criminals hijack stolen AI access. A security report from CrowdStrike shows how attackers exploit hijacked corporate access to AI services for cyberattacks and high bills.
  • 10 August 2026. Atlassian's Rovo leaks company data via two security flaws. Two independent security teams demonstrate how Atlassian's AI assistant Rovo can be tricked into sending internal Jira and Confluence data to attackers.
  • 10 August 2026. PortSwigger bypasses email protection – also AI assistants affected. A researcher demonstrates at Black Hat how pure CSS tricks can compromise passwords, tokens, and even an AI mailbox assistant.
  • 11 August 2026. The Daybreak program gives vetted security teams access to a cyber model with far fewer refusals on hacking requests.
  • 11 August 2026. LiteLLM attack hits over 2500 companies worldwide. A compromised scanner opened the door to the open AI gateway LiteLLM in March – a new report shows the extent of the stolen credentials.
  • 11 August 2026. OpenAI, Anthropic, Google: Researchers Crack Reasoning Logs. A study shows how encrypted AI reasoning traces from major providers can be read in plain text through weaker models.
  • 12 August 2026. GhostSplice brings AI coding assistants to data theft. Researchers from the ASSET Research Group dissect instructions over MCP channels and make Cursor, Copilot, and Claude Code disclose credentials.
  • 13 August 2026. Hudson Rock analyzes a 153-gigabyte data archive from the March attack and names additional global corporations as potential targets.
  • 14 August 2026. Start-up Tenet Security shows at DEF CON how doctored cloud logs trick AI coding agents into handing over control.
  • 14 August 2026. An unsecured database at AI note-taker tl;dv exposed conference data from tens of thousands of meetings worldwide, including government agencies.
  • 15 August 2026. A pro se plaintiff hid AI commands in white text inside court filings, and a Connecticut judge responded with sanctions.
  • 18 August 2026. Ray Flaw: CISA Reports Active Attacks on AI Computing Tool. The vulnerability CVE-2025-62593 lets attackers hijack Ray servers via the browser – exploited even before the official release in late November 2025.
  • 27 August 2026. The platform AnonyMousKIT calls with AI voices as fake Apple support and extracts unlock codes from owners of stolen iPhones.
  • 31 August 2026. Anthropic warns of malware that takes over Claude accounts. Infostealer malware copies login sessions and drains usage limits – Anthropic logs out affected users, removes payment data and refunds charges.
  • 7 September 2026. Jakub Pachocki considers the control of today's AI systems inadequately secured and calls for externally verified development limits.
  • 8 September 2026. GitSpawn hijacks Claude Code and six other AI agents. The security service provider Manifold Security uncovers a class of vulnerabilities that takes over developer machines simply by opening a folder.
  • 18 September 2026. FBI warns of hacker group Waterplum: disguise as AI company. FBI, Japanese police as well as BND and domestic intelligence warn of Waterplum: The group disguises job offers from AI companies to infect developer computers.
  • 20 September 2026. Plugin4Shell: Security vulnerability affects four AI coding agents. Four widespread AI coding agents could be compromised by manipulated Git branches – two manufacturers have already responded, two have not.
  • 21 September 2026. BragJack hijacks AI assistants in five browsers. A security researcher demonstrates how a single extension remotely controls AI assistants in Chrome, Edge, Opera Neon, Comet, and Claude.
  • 23 September 2026. ZCode: Zhipu apologizes after secret code upload. The Zhipu coding assistant ZCode sent repositories unnoticed to the company cloud for months – now follows an apology, a patch, and open source code.
  • 2 October 2026. Glow Security finds 13,000 leaked screenshots on GitHub. A security report shows how AI coding agents independently publish confidential company images in public GitHub repositories.

What this means for companies in Germany

Teams using coding agents or AI browsers should follow the linked reports. Protective steps appear only where that article states them. Entries without a link replace the separate report.

All stories