Monday 13 July 2026 02:14:27 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#malicious repos


The Approval That Missed the Target: A Symlink Trick Inside AI Coding Assistants

Published: 09 July 2026 08:25Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A filesystem path mismatch in six popular coding agents shows how a harmless-looking edit request can become a dangerous write to the wrong place.

When a Code Assistant Trusts Too Much, the Workspace Can Turn Hostile

Published: 27 June 2026 12:10Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

A reported flaw in Amazon Q Developer for Visual Studio Code shows how AI coding tools can inherit old-school workspace and symlink bugs, turning a convenience layer into a local compromise risk.

When a Privacy Tool Turns into a Trap: The Problem With Trusting AI Hubs by Name Alone

Published: 09 May 2026 17:29Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A malicious Hugging Face repository reportedly imitated OpenAI’s Privacy Filter project and appeared in the platform’s trending list while delivering infostealer malware to Windows users.