BREAKING
'Friendly Fire' hijacks AI code agents
How the RCE injection works
1Plant prompt in README
2User asks security test
3Agent runs binary
4Remote code execution
Only auto modes are affected
Claude Code CLIauto-mode
v2.1.116 to 2.1.199
Sonnet 4.6, Sonnet 5, Opus 4.8
Codex CLIauto-review
v0.142.4
GPT-5.5
No plugins or config needed
PoC stops at initial RCE
Auto-approval modes face scrutiny
AI NEWS BLITZ
Researchers unveiled an exploit that turns AI code agents into a launchpad for attacks.