VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_85ed5e7b7d468fa62e1db025daadc473

Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It

Published Jul 9, 2026

Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on your own machine instead.

That is the finding in a proof-of-concept published Wednesday by the AI Now Institute, an attack it calls "Friendly Fire." It works against Anthropic's Claude Code and OpenAI's Codex when either is running in an autonomous mode that approves its own

Affected AI Products

claude code anthropic ai agent openai claude
Get the weekly digest. Every Monday: top AI security stories of the week. Free.