ainewsblitz.com

Breaking

Researchers Unveil 'Ghostcommit' Attack That Hides Malicious Prompts in Images to Hijack AI Coding Agents

  • Security
  • AI Agents
  • Software Dev & Coding

Security researchers have disclosed a new supply-chain attack called "Ghostcommit" that smuggles prompt-injection instructions inside PNG images, slipping past AI code reviewers and tricking coding agents into leaking a repository's secrets. The technique, published on July 11, 2026, as a proof-of-concept by the ASSET Research Group at the University of Missouri-Kansas City, exposes a blind spot in how automated review tools and coding assistants handle non-text files.

Continue reading

The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.

$20
Read this article
$29/month
Unlimited — all 7,813 articles, the full archive, and comprehension quizzes
Save 72%
$98/year
≈ $8.17/month
Unlimited, billed once a year