Friendly Fire: Hijacking Defensive Cyber AI Agents for Remote Code Execution - AI Now Institute
2 directory members surfaced this signal.
“As governments and companies accelerate the deployment of AI agents for cyber defense, these risks require far greater scrutiny. Read “Friendly Fire: Hijacking Defensive Cyber AI Agents for Remote Code Execution” by @heidykhlaaf.bsky.social and Boyan Milano…”
“New! We hijack Claude Code(Sonnet 4.6,5/Opus 4.8) & Codex(GPT5.5) to achieve RCE when used to defensively assess an open-source/third-party library w/ prompt injections disseminated across its codebase. All without any skills, JSON, MCP, or config files req…”