ainewsblitz.com

Breaking

Code-review AI tricked into running code via README

  • Security
  • AI Agents
  • Software Dev & Coding

Around July 8-9, 2026, the AI Now Institute published a proof-of-concept dubbed "Friendly Fire" showing that Anthropic's Claude Code and OpenAI's Codex can be made to run arbitrary code on the host through instructions planted in a repository's README. It demonstrates how AI agents performing autonomous security reviews can mistake attacker-embedded instructions for part of their task and execute malicious code, as detailed by The Hacker News and the AI Now Institute technical brief.

Continue reading

The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.

$20
Read this article
$29/month
Unlimited — all 7,865 articles, the full archive, and comprehension quizzes
Save 72%
$98/year
≈ $8.17/month
Unlimited, billed once a year