On July 8, 2026, the AI Now Institute published "Friendly Fire," a proof-of-concept that hijacks defensive AI coding agents such as Anthropic's Claude Code and OpenAI's Codex to achieve remote code execution (RCE). By hiding instructions (prompt injection) in a repository's README, an attacker's payload runs on the host as soon as the user simply asks the agent to review the code, a paradoxical attack. A detailed attack flow was released, along with a demonstration and video in Linux/container environments.
Continue reading
The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.
Already purchased? Sign in✓ Signed in — this article isn’t included in your current plan.