On July 8, 2026, researchers disclosed a new attack called HalluSquatting that abuses the "hallucinations" of AI coding assistants to make agents fetch and run malicious code, enabling botnet assembly and more. Attackers pre-register nonexistent repository or skill names that AI models tend to invent, then plant prompt-injection instructions inside them. When an agent mistakenly fetches such a resource, a reverse shell or malware can be installed via the integrated terminal. (The Hacker News, Ars Technica)
Continue reading
The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.
Already purchased? Sign in✓ Signed in — this article isn’t included in your current plan.