Affected Technology
GitHub Copilot incidents
GitHub Copilot security
News
STABLE
Researcher Uncovers 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks
Security researcher Ari Marzouk disclosed "IDEsaster," a collection of over 30 vulnerabilities, with 24 assigned CVEs, affecting various AI-powered Integrated Development Environments (IDEs) like GitHub Copilot and Cursor. These flaws enable attackers to chain prompt injection techniques with legitimate IDE features and auto-approved AI agent tool calls to achieve sensitive data exfiltration and remote code execution (RCE).
Low severity NEW
GitHub Copilot Security Vulnerability
An AI bot from Wiz successfully exploited a critical vulnerability discovered in Snowflake's cloud data platform. The exploit was facilitated by a bug partly generated or assisted by GitHub Copilot.