<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[These AI agent attacks are getting ridiculous]]></title><description><![CDATA[<p>These AI agent attacks are getting ridiculous</p><p>Malicious code hidden in source code repositories can trick AI coding agents into overwriting their own configuration files</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://adversa.ai/blog/the-approval-prompt-is-lying-to-you-symlink-rce-in-five-ai-coding-agents-claude-code-cursor-antigravity-copilot-grok-build/" title="The approval prompt is lying: a critical coding agent security flaw">
<img src="https://adversa.ai/wp-content/uploads/2025/06/Article-Website-Images-1-2.png" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://adversa.ai/blog/the-approval-prompt-is-lying-to-you-symlink-rce-in-five-ai-coding-agents-claude-code-cursor-antigravity-copilot-grok-build/">
The approval prompt is lying: a critical coding agent security flaw
</a>
</h5>
<p class="card-text line-clamp-3">A critical coding agent security flaw, SynJack, lets a fake "video copy" rewrite config in Claude, Cursor, Copilot, Codex, Grok, and Gemini. How to stop RCE.</p>
</div>
<a href="https://adversa.ai/blog/the-approval-prompt-is-lying-to-you-symlink-rce-in-five-ai-coding-agents-claude-code-cursor-antigravity-copilot-grok-build/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://adversa.ai/wp-content/uploads/2021/02/favicon.png" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />







<p class="d-inline-block text-truncate mb-0">Adversa AI | Agentic AI Security <span class="text-secondary">(adversa.ai)</span></p>
</a>
</div></p>]]></description><link>https://board.circlewithadot.net/topic/a21d6c8d-7a5d-4e80-a1b4-2ac890feeb58/these-ai-agent-attacks-are-getting-ridiculous</link><generator>RSS for Node</generator><lastBuildDate>Sun, 31 May 2026 17:54:45 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/a21d6c8d-7a5d-4e80-a1b4-2ac890feeb58.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 27 May 2026 23:00:27 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to These AI agent attacks are getting ridiculous on Thu, 28 May 2026 03:27:59 GMT]]></title><description><![CDATA[<p><span><a href="/user/campuscodi%40mastodon.social">@<span>campuscodi</span></a></span></p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/650/070/720/688/550/original/97ff6af96e7cddcd.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/cjust/statuses/116650074433842181</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/cjust/statuses/116650074433842181</guid><dc:creator><![CDATA[cjust@infosec.exchange]]></dc:creator><pubDate>Thu, 28 May 2026 03:27:59 GMT</pubDate></item><item><title><![CDATA[Reply to These AI agent attacks are getting ridiculous on Thu, 28 May 2026 01:33:46 GMT]]></title><description><![CDATA[<span><a href="/user/campuscodi%40mastodon.social">@<span>campuscodi</span></a></span> Karma!]]></description><link>https://board.circlewithadot.net/post/https://friendica.myportal.social/objects/e65e1095-126a-179b-7ac0-6fd267289037</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://friendica.myportal.social/objects/e65e1095-126a-179b-7ac0-6fd267289037</guid><dc:creator><![CDATA[claralistensprechen3rd@friendica.myportal.social]]></dc:creator><pubDate>Thu, 28 May 2026 01:33:46 GMT</pubDate></item><item><title><![CDATA[Reply to These AI agent attacks are getting ridiculous on Thu, 28 May 2026 01:21:45 GMT]]></title><description><![CDATA[<p><span><a href="/user/cwbussard%40ioc.exchange">@<span>cwbussard</span></a></span> <span><a href="/user/campuscodi%40mastodon.social">@<span>campuscodi</span></a></span> Or putting a blackhole for the slop provider's domain name in /etc/hosts so the whole thing stops working. <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f608.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--smiling_imp" style="height:23px;width:auto;vertical-align:middle" title="😈" alt="😈" /></p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/dalias/statuses/116649578005202611</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/dalias/statuses/116649578005202611</guid><dc:creator><![CDATA[dalias@hachyderm.io]]></dc:creator><pubDate>Thu, 28 May 2026 01:21:45 GMT</pubDate></item><item><title><![CDATA[Reply to These AI agent attacks are getting ridiculous on Thu, 28 May 2026 01:14:17 GMT]]></title><description><![CDATA[<p><span><a href="/user/dalias%40hachyderm.io">@<span>dalias</span></a></span> <span><a href="/user/campuscodi%40mastodon.social">@<span>campuscodi</span></a></span> </p><p>Yes... I think there'd be an audience for a plug-and-play version that you could just drop into any repo that would prevent AI slop pull requests by tricking the AI slop tools into nuking the local copy.</p>]]></description><link>https://board.circlewithadot.net/post/https://ioc.exchange/users/cwbussard/statuses/116649548708531397</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://ioc.exchange/users/cwbussard/statuses/116649548708531397</guid><dc:creator><![CDATA[cwbussard@ioc.exchange]]></dc:creator><pubDate>Thu, 28 May 2026 01:14:17 GMT</pubDate></item><item><title><![CDATA[Reply to These AI agent attacks are getting ridiculous on Wed, 27 May 2026 23:14:50 GMT]]></title><description><![CDATA[<span><a href="/user/dalias%40hachyderm.io" rel="ugc">@<span>dalias</span></a></span> <span><a href="/user/campuscodi%40mastodon.social" rel="ugc">@<span>campuscodi</span></a></span> plus well… it's not code]]></description><link>https://board.circlewithadot.net/post/https://queer.hacktivis.me/objects/635338e2-5932-4663-aedf-99d067af87d4</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://queer.hacktivis.me/objects/635338e2-5932-4663-aedf-99d067af87d4</guid><dc:creator><![CDATA[lanodan@queer.hacktivis.me]]></dc:creator><pubDate>Wed, 27 May 2026 23:14:50 GMT</pubDate></item><item><title><![CDATA[Reply to These AI agent attacks are getting ridiculous on Wed, 27 May 2026 23:08:58 GMT]]></title><description><![CDATA[<p><span><a href="/user/campuscodi%40mastodon.social">@<span>campuscodi</span></a></span> I don't call that malicious code I call that self-defense.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/dalias/statuses/116649055920106801</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/dalias/statuses/116649055920106801</guid><dc:creator><![CDATA[dalias@hachyderm.io]]></dc:creator><pubDate>Wed, 27 May 2026 23:08:58 GMT</pubDate></item></channel></rss>