Defensive AI Agents Can Be Hijacked for Remote Code Execution
AINowInstitute · x · 2026-07-08
AI Now Institute has published a proof-of-concept vulnerability research named "Friendly Fire". The study reveals that defensive AI agents like Claude Code and Codex can be maliciously hijacked to trigger Remote Code Execution (RCE) during security scans.
Related event: Research Reveals Defensive AI Agents Vulnerable to Hijacking(4 posts)→
More from coding & agent
- Chaining dependent MCP tool calls: no rollback, duplicate risk — agentrsdg · 2026-09-11
- DeepMind-led paper makes design docs the source of truth, code disposable — SMART regenerates in 1.5-3h for ~$100 — Roger_M_Taylor · 2026-09-11
- Agent-built classifier labels 192k docs for $0.70 vs $13-26 with frontier LLMs — vanstriendaniel · 2026-09-11
- MathModelAgent gains traction: auto-solves math modeling and writes a submission-ready paper — jihe520 · 2026-09-11
- alphaXiv open-sources OpenResearch to run parallel research agents with any model — alphaXiv · 2026-09-11
- DeskcommCRM: open-source AI sales CRM with native agents and WhatsApp hits 1k stars — melgarafael · 2026-09-11