Researchers at the AI Now Institute on July 8–9, 2026 released a proof-of-concept exploit dubbed "Friendly Fire" that hijacks Anthropic's Claude Code CLI and OpenAI's Codex CLI via prompt injection to run attacker-supplied binaries on the host. The key trait is that simply asking the agent to read code for a security review can lead to remote code execution (RCE), as detailed in the AI Now Institute brief and The Hacker News.
Continue reading
The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.
Already purchased? Sign in✓ Signed in — this article isn’t included in your current plan.