Urgent.News

What's breaking now, across thousands of outlets.

AI

Cybersecurity Researchers Uncover Flaw in Google AI Coding Tool

Cybersecurity researchers from Pillar Security this week revealed how a prompt injection inserted into a GitHub repository was used to gain Editor-level access to an internal Google Cloud project using a flaw in the command line interface (CLI) of an artificial intelligence (AI) coding tool that Google provides. Dan Lisichkin, a cybersecurity researcher for Pillar […]

Cybersecurity Researchers Uncover Flaw in Google AI Coding Tool

Cybersecurity researchers from Pillar Security discovered a flaw in Google's AI coding tool that could allow attackers to gain Editor-level access to an internal Google Cloud project. The vulnerability was found in the command line interface (CLI) setup code of Google's AI tool, Gemini. A researcher from Pillar Security was able to exploit this flaw by filing a "bug report" containing hidden instructions that resulted in a prompt injection.

This injection led to a legitimate credentials file being issued via the Workload Identity Federation (WIF) framework, which the researcher then copied out. One of these credentials allowed the researcher to impersonate a more powerful account, granting them Editor-level control over the project. This breach highlights the growing risk of compromising software supply chains using AI technologies.

While this incident is isolated, it demonstrates how easy it is to exploit open source tools in the AI coding era. Cybercriminals could potentially compromise an entire software supply chain at machine speed by inserting malicious prompts into coding agents. DevSecOps teams should closely monitor the data sources an AI coding tool accesses to mitigate this risk.

This is not the first time Google's AI technologies have been found vulnerable by Pillar Security. Earlier this month, the researchers revealed the first instance of an AI agent that could exploit another AI agent, posing a significant security concern. Google has since addressed these issues, but the potential for new vulnerabilities remains high given the rapid development of AI technologies.

Written by urgent.news from DevOps.com's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at devops.com →

More in AI

Codex Skill Adds Guardrails to AI Presenter Video Workflows

The public GitHub project lanshu-create-ai-presenter-video packages a Codex-oriented Skill for turning a topic or script plus an authorized, clearly adult presenter image into an AI presenter video…

  • Codex-based Skill streamlines AI presenter video creation.
  • Developers install Skill in ~/.codex/skills directory.
  • Skill ensures timeline alignment for minimized lip-sync issues.

Transformers: Understanding the Architecture Behind Modern AI

Introduction Transformers are the heart of modern AI models. AI has seen a lot of breakthrough advancements from ChatGPT to AI, and now.

  • Transformers are the backbone of modern AI models
  • Multi-head attention enables effective semantic similarity capture
  • Positional encodings provide token position information

Are AI Coding Assistants Getting Worse in 2026? Data & Analysis

Originally published at nlocoding.com 72% of developers using AI code assistants say they're less satisfied with code quality in 2026 than they were in 2023. That’s not a typo. (Source: Stack Overflow Survey, 2026) 72%Developers reporting lower code quality with AI assistants (Stack Overflow, 2026) AI code assistants were supposed to be a…

  • 72% of developers report reduced code quality in 2026
  • AI coding assistants generate 32% more bugs per 1,000 lines
  • Legal disputes rise as AI-generated code implicated in plagiarism

More from Friday 28 August →