
Anthropic, Google, and OpenAI Coding Agents Exposed to Zero-Privilege RCE
A newly disclosed critical flaw in AI coding-agent workflows from Anthropic, Google, and OpenAI could allow an unauthenticated attacker to exploit a malicious GitHub issue to achieve remote code execution (RCE), credential theft, persistent agent hijacking, or a software supply chain compromise. Novee Security researcher Elad Meged said the vulnerabilities were identified in default configurations […]
The post Anthropic, Google, and OpenAI Coding Agents Exposed to Zero-Privilege RCE appeared first on Cyber Security News.