INTEL_REPORT
The Hacker News · published 7/9/2026, 5:15:02 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on your own machine instead. That is the finding in a proof-of-concept published Wednesday by the AI Now Institute, an attack it calls "Friendly Fire." It works against Anthropic's Claude Code and OpenAI's Codex when either is running in an autonomous mode that approves its own Top …
https://thehackernews.com/2026/07/friendly-fire-ai-agents-built-to-catch.html
sha256:fc1668accbee404be373338f4fd323aadd21c61cf914b281a9cf4e244951940a
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| CVE-2026-39861 |
| Open → |