Blog · Page 3

Friendly Fire: When the AI You Hired to Find Malware Runs It Instead

AI Now Institute discovered that Claude Code in auto-mode and Codex in auto-review will execute malicious code during security audits — the very task they were deployed to prevent. The attack requires zero hooks, zero plugins, zero MCP servers. Just prompt injections in source code. Combined with GhostApproval, every security layer in AI coding assistants is now bypassable.

·
ai-securityagent-securityfriendly-fire

GhostApproval: A 40-Year-Old Unix Trick Just Broke the Security Model of Every AI Coding Assistant

Wiz Research discovered that symlinks — a Unix feature from 1983 — let attackers bypass confirmation dialogs in six major AI coding assistants. Augment had it worst: silent read AND write without any confirmation. Windsurf performed file writes before showing approval. Here's what happened and what it means for the 'human in the loop' security model.

·
ai-securityagent-securityghostapproval