trampolim.net
PT EN

Trampolim · Technology weekly

The Week in Tech

Issue 09Week of June 22–28, 202616 stories
Issue 09/June 22–28, 2026/Past issues/BusinessSecurityAIWorkHardwareTools

85% of coding agents fell for the same trick

A new class of attack hijacks coding assistants by injecting instructions into the error logs they read. There is no universal fix. The same week, an audit-dedicated model found 24 flaws in the Linux kernel.

From the studio

What the agent reads is untrusted input

The week produced the quarter's most uncomfortable finding: 85% of tested coding assistants accepted instructions planted in the error logs they consult to help fix defects. The agent reads it as an order and executes with the developer's privileges.

What makes the case hard is that there's no patch. The agent has to read outside content to be useful, and outside content can be written by anyone. It's the same problem structure that appeared weeks later in AI browsers redirected by a planted comment.

The responses announced in the period all run in one direction, and none promises to block the entry: zero standing privilege, per-action authorisation, the agent's own identity. They don't prevent the malicious instruction, they reduce what it reaches.

The practical rule left standing is old and still holds: whatever enters a model's working context is user input, and deserves the suspicion applied to a web form. And every barrier counts only after someone has watched it fail on purpose.

In this issue

Hardware

Apple prepares a touchscreen laptop

The devices are expected to ship with the current processor generation rather than waiting for the next.

· Enterprise Times · Read the story →

Security

Agents reach data nobody explicitly approved

Research from the period shows agents inheriting the permissions of whoever configured them, with no scope of their own.

· Enterprise Times · Read the story →

Sections

Book a call