None
EN
Black Hat 2026: Critical Flaws Found in Anthropic, Google, and OpenAI Coding Agents
['Ken Underhill']
eSecurity Planet
Key takeawaysResearchers found critical flaws in Anthropic, Google, and OpenAI AI coding agents that could enable attacks through a single malicious GitHub issue.
in Anthropic, Google, and OpenAI AI coding agents that could enable attacks through a single malicious GitHub issue.
The vulnerabilities affected AI agent workflows , enabling remote code execution, credential theft, and supply chain compromise.
AdvertisementOrganizations should evaluate AI agent workflowsThe researchers concluded that the vulnerabilities stemmed from hidden trust assumptions within AI agent harnesses rather than isolated implementation mistakes.
Organizations deploying AI coding agents should:Review AI agent workflows for untrusted inputs that can influence automated actions.