Friendly Fire tricks AI code-security agents into running malicious code

The AI Now Institute's proof-of-concept, disclosed Wednesday, shows its "Friendly Fire" attack can hijack AI agents that scan open-source code for vulnerabilities, causing them to execute the attacker's code instead. The attack works against Anthropic's Claude Code.
1 source
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Paper examines the limitations of current AI evaluation methods
- OnlyHuman filter list removes AI-generated SEO spam from search results
- Qwen tokenizes 330-line code into 1,609 tokens; Gemma needs 4,258
- LifeOS: open-source AI harness for personal growth and work
- MINIMAX video drops Indiana Jones into Mortal Kombat