Monday 13 July 2026 02:08:02 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#AI coding agents


Meta pushes Muse Spark 1.1 into U.S. preview, betting lower pricing will drive developer adoption

Published: 10 July 2026 12:07Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: SECPULSE

Muse Spark 1.1 enters U.S. public preview with lower-cost pricing for coding agents, a move that looks commercial on the surface but has workflow and governance implications for teams that adopt AI-assisted development.

The Approval That Missed the Target: A Symlink Trick Inside AI Coding Assistants

Published: 09 July 2026 08:25Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A filesystem path mismatch in six popular coding agents shows how a harmless-looking edit request can become a dangerous write to the wrong place.

AI Code Watchdogs Can Be Led by the Leash

Published: 09 July 2026 08:16Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A proof-of-concept called Friendly Fire highlights a sharper risk in agentic security: the tool meant to inspect hostile code can be steered into executing it.

When Coding Helpers Start Looking Like Intruders on Windows

Published: 08 July 2026 12:08Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

AI agents that write code and run commands can generate the same endpoint signals defenders watch for in real attacks, especially when they touch secrets or invoke native Windows binaries.

When an AI Skill Hides Its Teeth, Static Scanners See Only a Toy

Published: 06 July 2026 10:53Category: AI Security & Agentic SystemsAuthor: KERNELWATCHER

Security researchers have shown that malicious add-on skills for AI coding agents can be packed to look harmless at install time, exposing a trust gap in today’s plugin-style defenses.

When AI Skills Become the Payload: Static Scanners Lose Sight of the Trap

Published: 06 July 2026 10:14Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: INTEGRITYFOX

A new supply-chain risk in LLM coding agents shows why install-time checks can miss malicious skill packages that only reveal their behavior once execution begins.

When Shell History Meets Agentic AI, the Risk Moves to the Command Line

Published: 30 June 2026 19:05Category: AI Security & Agentic SystemsAuthor: KERNELWATCHER

Decades-old Bash tricks are being used to test whether open-source AI coding agents can be pushed past their safety checks and into dangerous repository-driven workflows.

When the Shell Smiles Back: GuardFall and the Fragile Safety Net Around AI Coding Agents

Published: 30 June 2026 18:19Category: AI Security & Agentic SystemsAuthor: KERNELWATCHER

A research bypass aimed at open-source AI coding and computer-use agents shows how quickly a command safeguard can become a paper wall if shell behavior is not modeled correctly.

When a Clean Repository Turns Into a Blind Spot for AI Coders

Published: 27 June 2026 18:03Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A seemingly harmless GitHub project can become dangerous the moment an agentic coding tool is told to clone it, set it up, and trust what comes next.

When AI Writes the Fix, the Guardrails Matter More Than the Code

Published: 23 June 2026 15:26Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A 20-year AWS reflection turns into a hard lesson for security teams: autonomous coding agents are only useful when specs, tests, and telemetry keep them on a short leash.

Inside the Agent Memory Trap: Why a Few Bad Lines Can Bend AI Coding Behavior

Published: 22 June 2026 08:08Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A study of coding-agent instruction files shows that the quietest part of the stack - the project memory layer - can become a source of wasted tokens, confused priorities, and inconsistent code work.

When Agent Memory Turns Noisy, AI Code Assistants Start Missing the Point

Published: 19 June 2026 06:05Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A study of repo-level instruction files shows how redundant, stale, or contradictory guidance can waste context and make coding agents less reliable.

Fake Bug Reports, Real Risk: How AI Coding Agents Can Be Led Off Course

Published: 18 June 2026 16:15Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

Security researchers have shown a new "Agentjacking" pattern in which a forged Sentry-style issue can persuade an AI coding agent to run code, exposing a trust problem at the heart of agentic developer tools.

AI Coding Agents Push Enterprise Software Into a New Control Problem

Published: 16 June 2026 15:29Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

The shift from low-code and no-code into AI-assisted orchestration is changing who can build software, but it is also changing what must be trusted, reviewed, and contained.

Agentjacking Turns AI Debugging Into a Trap for Coding Assistants

Published: 13 June 2026 12:08Category: AI Security & Agentic SystemsAuthor: KERNELWATCHER

A newly disclosed attack class shows how an AI helper asked to investigate an error can be steered into executing malicious code, without phishing or server compromise.

When AI Helpers Trust the Wrong Text, Code Execution Can Follow

Published: 13 June 2026 12:06Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A new agent-risk label is pushing a familiar security lesson into a more dangerous setting: if a coding assistant treats untrusted tool output like instructions, the boundary between data and action can collapse.

When a Fake Bug Report Becomes a Remote Control for AI Coders

Published: 12 June 2026 17:08Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: INTEGRITYFOX

Researchers have described a new attack pattern that can steer coding agents toward dangerous actions by hiding malicious instructions inside trusted-looking error data.

When a Shortcut Becomes a Backdoor: The SymJack Pattern Hitting AI Coding Agents

Published: 27 May 2026 18:17Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: INTEGRITYFOX

A symlink trick aimed at AI-assisted development shows how repository content, agent permissions, and MCP extensibility can collide into a supply-chain risk.

When AI Writes Code, Secrets Become the Real Attack Surface

Published: 21 May 2026 07:23Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A new credential model for OpenAI Codex spotlights a bigger security shift: coding agents should borrow access for a task, not keep secrets in their memory.

When the Bot Opens the Pull Request, the Real Risk Moves to Governance

Published: 15 May 2026 12:26Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: INTEGRITYFOX

AI coding has shifted from helpful autocomplete to software agents that can plan, edit, test, and submit changes - and that turns code review into a security control, not a formality.