Urgent.News

600+ sources. One page. See who else covered it.

Editions

AI

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next agent run. Novee Security ran the attack against each vendor's agent in the configuration that the vendor ships by default, and presented the work at Black Hat USA on August 5.

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

We haven't written up this one. The Hacker News has the full story — the link below goes straight to it.

Read the original at thehackernews.com →

More in AI

Enterprise AI doesn’t need another app: it needs its language

Enterprise AI doesn’t need another app: it needs its language

For the past two years, companies have been asking the same question in slightly different forms: which AI application should we build next? A customer service agent? A sales copilot? A procurement assistant? A coding agent? A research assistant? A workflow automation layer? A chatbot connected to internal data?

More from Friday 7 August →