Security
Attack hijacks coding agents through error logs, and 85% failed the test
The technique injects instructions into monitoring data. The agent reads it as an order and executes on the developer's machine.
Trampolim · Technology weekly
A new class of attack hijacks coding assistants by injecting instructions into the error logs they read. There is no universal fix. The same week, an audit-dedicated model found 24 flaws in the Linux kernel.
Security
The technique injects instructions into monitoring data. The agent reads it as an order and executes on the developer's machine.
Security
The Daybreak programme found privilege escalations and a critical flaw in a widely used proxy.
From the studio
The week produced the quarter's most uncomfortable finding: 85% of tested coding assistants accepted instructions planted in the error logs they consult to help fix defects. The agent reads it as an order and executes with the developer's privileges.
What makes the case hard is that there's no patch. The agent has to read outside content to be useful, and outside content can be written by anyone. It's the same problem structure that appeared weeks later in AI browsers redirected by a planted comment.
The responses announced in the period all run in one direction, and none promises to block the entry: zero standing privilege, per-action authorisation, the agent's own identity. They don't prevent the malicious instruction, they reduce what it reaches.
The practical rule left standing is old and still holds: whatever enters a model's working context is user input, and deserves the suspicion applied to a web form. And every barrier counts only after someone has watched it fail on purpose.
In this issue
Security
The joint statement came in the same period an executive order created pre-release review for advanced systems.
Security
The proposal is zero standing privilege: the agent asks permission per action instead of carrying broad credentials.
AI
The announcement came on June 28, with use restricted to companies in the same group.
Business
Among them a central researcher and a science prize winner. A competitor hired them.
Business
The deal targets AI tools for film production and distribution.
Regulation
Signed on June 2, the process defined who could launch and when, weeks before the first public case.
Business
The acquisition moves the company from launch services into satellite communications.
Hardware
The devices are expected to ship with the current processor generation rather than waiting for the next.
Security
The partnership lets customers control assistant use and tool access through a single layer.
AI
The removal involved export controls and concerns about vulnerability-discovery capability.
Security
Research from the period shows agents inheriting the permissions of whoever configured them, with no scope of their own.
Business
The event took place the same week as the agency warnings and the code audit programme launch.
Work
The new attack class only makes sense because the tool sits in everyone's workflow.
Security
Researchers recommend human review between untrusted data and agent action.
Sections
This paper is written by the same team that builds and operates the systems discussed here. If any of it touches your operation, you talk directly to the people who build.
Book a call