Black Hat 2026: Coding Agents’ Trust Boundary Failures
6 min read
Black Hat showed one malicious GitHub issue can drive RCE and token theft in Claude Code, Gemini CLI, and Codex. Architectural fixes for agent harnesses.
5 articles
Black Hat showed one malicious GitHub issue can drive RCE and token theft in Claude Code, Gemini CLI, and Codex. Architectural fixes for agent harnesses.
Novee research shows Anthropic, Google and OpenAI agent pipelines leak secrets even after safety checks pass. The failure is composed trust across stages.
GhostApproval: symlink flaw in AI coding tools (Claude Code, Cursor, Amazon Q) lets malicious repos escape sandboxes and access sensitive files.
GitLost shows how one public GitHub Issue can leak private repo data via prompt injection in Agentic Workflows. Key lessons for securing agentic systems.
Dual-firewall and adaptive out-of-band defense patterns for securing agentic and RAG systems against prompt injection.