Sunday 12 July 2026 04:31:38 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItalianoArabic

#AI coding assistants


GhostApproval Turns AI Coding Assistants Into a File-System Trap

Published: 11 July 2026 16:32Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: INTEGRITYFOX

A trust-boundary flaw in six code agents shows how a malicious repository can manipulate sandboxed tools, not by breaking the model, but by abusing path handling and approval design.

GhostApproval Turns AI Coding Tools Into Unwitting File Writers

Published: 09 July 2026 16:33Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A newly disclosed trust-boundary flaw shows how repository tricks can push coding assistants past their workspace limits, where a single bad write may become a serious host-level security problem.

GhostApproval Raises a Hard Question for AI Coding Tools: What Happens When Trust Is Only an Illusion?

Published: 09 July 2026 16:11Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

Wiz has disclosed GhostApproval, an attack method that uses a decades-old technique to mislead AI coding assistants and test the limits of approval-based security on developer machines.

When AI Approvals Drift: GhostApproval and the Broken Promise of Workspace Safety

Published: 09 July 2026 15:07Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: INTEGRITYFOX

A symlink-based trick shows how agentic coding tools can be pushed beyond the directory a user thinks they approved.

The Approval That Missed the Target: A Symlink Trick Inside AI Coding Assistants

Published: 09 July 2026 08:25Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A filesystem path mismatch in six popular coding agents shows how a harmless-looking edit request can become a dangerous write to the wrong place.

When a Model’s Guess Becomes a Supply-Chain Trap

Published: 09 July 2026 08:09Category: AI Security & Agentic SystemsGeo: Middle East / IsraelAuthor: INTEGRITYFOX

A newly named technique turns AI coding mistakes into a security boundary problem, showing how a hallucinated identifier can become a dangerous trust decision.

When Refusal Ends at Chat, the Code Editor Becomes the Back Door

Published: 08 July 2026 16:52Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: INTEGRITYFOX

A new security study suggests that an AI coding assistant can reject a harmful request in conversation and still help assemble it when the same objective is fragmented inside a development workflow.

AI Coding Assistants Are Now a Governance Risk, Not Just a Productivity Tool

Published: 08 July 2026 12:47Category: Privacy, Regulation & ComplianceGeo: Asia / ChinaAuthor: WHITEHAWK

Alibaba’s move against Claude Code shows how a single privacy allegation can turn an AI developer tool into a company-wide trust decision.

When Code Assistants Start Looking Like Intruders

Published: 08 July 2026 12:47Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: INTEGRITYFOX

AI coding tools can generate endpoint behavior that resembles attack traffic, forcing defenders to tell normal automation from hostile tradecraft.

The Plugin Trap: How a Helpful AI Tool Can Turn Into a Secret Stealer

Published: 17 June 2026 13:03Category: Malware & BotnetsGeo: Europe / Czech RepublicAuthor: IRONQUERY

A batch of JetBrains add-ons posing as AI coding assistants highlights a familiar weakness in modern development: once a plugin is trusted, it may inherit far more access than users realize.

Fake AI Helpers Turn Developer Trust Into a Credential Trap

Published: 17 June 2026 12:17Category: Malware & BotnetsGeo: Europe / NetherlandsAuthor: SIGNALMONK

Malicious JetBrains plugins and suspicious browser add-ons are putting AI keys and chatbot conversations in the crosshairs, showing how software supply chains can become data-collection pipelines.

Code by Contract, Not by Confidence: The Security Problem Hiding in Agentic AI

Published: 15 June 2026 12:11Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: INTEGRITYFOX

Coding assistants are being discussed less as chat tools and more as systems that can work with greater autonomy, which shifts the security question from output quality to control, permissions, and containment.

When AI Helpers Trust the Wrong Text, Code Execution Can Follow

Published: 13 June 2026 12:06Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A new agent-risk label is pushing a familiar security lesson into a more dangerous setting: if a coding assistant treats untrusted tool output like instructions, the boundary between data and action can collapse.

When a First Look at AI Code Tools Draws Fire, the Real Story Is Verification

Published: 08 June 2026 18:35Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A revisited take on an AI coding assistant became less about novelty and more about a familiar security question: what counts as enough due diligence before trusting machine-generated code?

When AI Pricing Becomes the Real Battlefield in Developer Tools

Published: 08 June 2026 06:11Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: TRUSTBREAKER

A public jab at a rival's pricing has turned into a clearer warning for enterprise buyers: in AI coding, cost control is now a core security-and-operations question, not a footnote.