Affected Technology
GitHub incidents
GitHub AI tooling and Copilot security
Claude Code Information Disclosure Vulnerability
Evidence indicates that Claude Code is affected by a security issue. Reported affected versions include 2.1.88.
CVE-2024-0132 Container Escape Vulnerability affecting NVIDIA Container Toolkit
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. The supported impact is full host system access. Reported affected versions include < 1.16.2.
Nx build system Supply Chain Attack Vulnerability
Evidence indicates that Nx build system is affected by a security issue.
Copilot Prompt Injection Vulnerability
Evidence indicates that Copilot is affected by a security issue.
Researcher Uncovers 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks
Security researcher Ari Marzouk disclosed "IDEsaster," a collection of over 30 vulnerabilities, with 24 assigned CVEs, affecting various AI-powered Integrated Development Environments (IDEs) like GitHub Copilot and Cursor. These flaws enable attackers to chain prompt injection techniques with legitimate IDE features and auto-approved AI agent tool calls to achieve sensitive data exfiltration and remote code execution (RCE).
GitHub Remote Code Execution Vulnerability
Attackers can achieve remote code execution (RCE) on developer machines by leveraging indirect prompt injection against agentic AI developer tools. This is accomplished by introducing untrusted data, such as malicious commands in GitHub issues or hidden payloads in fake Python packages within pull requests, which the AI agent autonomously executes.
GitHub Remote Code Execution Vulnerability
A multi-stage supply chain attack, tracked as UNC6395, originated from the compromise of a Salesloft GitHub repository, leading to the theft of a sensitive OAuth token. This token enabled access to a high-privilege AI chatbot application (Drift) and subsequent exfiltration of customer conversation data and contact information from over 700 integrated Salesforce instances.
GitHub Supply-Chain Compromise
Fortunately, the company had a policy of checking source code on GitHub first
GitHub Copilot Security Vulnerability
An AI bot from Wiz successfully exploited a critical vulnerability discovered in Snowflake's cloud data platform. The exploit was facilitated by a bug partly generated or assisted by GitHub Copilot.
AI Security Incident
Anthropic’s AI used fake identities, malware in rogue attack on GitHub proje
AI Security Vulnerability
The GitHub Security Lab Taskflow Agent is an open-source AI-powered framework that leverages Large Language Models (LLMs) and structured taskflows to proactively identify high-impact web security vulnerabilities. This framework has successfully uncovered numerous authorization bypasses, IDORs, and token leaks, facilitating the discovery of issues such as unauthorized PII access and compromised authentication mechanisms.
AI Security Vulnerability
The GitHub Security Lab's Taskflow Agent leverages large language models (LLMs) to automate and enhance the triage of security alerts, effectively identifying real-world vulnerabilities in GitHub Actions and JavaScript projects. This AI framework significantly reduces false positives from static analysis tools like CodeQL by interpreting complex code semantics, leading to the discovery and remediation of numerous exploitable weaknesses.
Amazon AWS Supply-Chain Compromise
A hacker injected destructive system commands into Amazon's Visual Studio Code extension for Amazon Q via a compromised GitHub repository, distributing it through an official update. This supply chain attack exploited a lack of stringent vetting to leverage prompt injection, aiming to redefine the AI agent's behavior at runtime to erase user data and cloud resources.