Google: attackers now use prompt injection against coding agents
fourfire · hn · 2026-09-09
Google Cloud Threat Intelligence details how adversarial AI is evolving from simple prompt injection to attacks targeting autonomous coding agents. With agents able to execute code, access repos and invoke tools, injected instructions now translate into real damage. The post analyzes real attack paths and argues defenses must shift from content filtering to permission and behavior controls.
More from coding & agent
- OpenAI opens up agent sandboxes: BYO or pick from Cloudflare, E2B, Modal, Vercel and more — threepointone · 2026-09-11
- SocialCrawl MCP lets agents search Reddit, YouTube, TikTok, X with one API key — dooddyman · 2026-09-11
- Astra builds a surprisingly polished Catan game in three.js, reusing past UI and 3D assets — FinanceYF5 · 2026-09-11
- Open-Source Tool Highlights the Exact PDF Paragraphs Behind AI Answers — Flat-Phone-1596 · 2026-09-11
- OpenAI Codex may issue another usage reset this weekend, says Codex lead resets happen — umesh_ai · 2026-09-11
- Dev swaps gemini-3.8 for gemini-3.5-flash-lite in his MCP harness at a fraction of cost — julianharris · 2026-09-11