Cylera reported that security researchers found vulnerabilities in GitSpawn, a set of vulnerabilities tracking AI coding agents like Anthropic Claude Code, OpenAI Codex, Cursor, Block Goose, Nous Hermes Agent, Alibaba Qwen Code, and xAI Grok Build, which could be hijacked before a prompt is typed.
Public source
Publisher name
Public post
One Folder Was All It Took: Security Researchers Find AI Coding Agents Can Be Hijacked Before a Single Prompt Is Typed. Opening a folder should not be a security event.…
Company
Cylera
- Industry
- Computer and Network Security
- Location
- New York, US
- Company size
- 11–50 employees
About Cylera
Cylera provides the easiest, most accurate and extensible, platform for healthcare IoT asset intelligence and security to optimize care delivery, service availability and cyber defenses across diverse connected medical device and infrastructure. The platform accurately discovers, categorizes, assesses and monitors known and unknown IoMT assets with high fidelity to deliver unparalleled asset inventory, usage telemetry, threat prioritization, analytics, and guided remediation. The SaaS solution offers rapid implementation and works with popular IT and healthcare systems to help organizations advance cyber program maturity, increase operational efficiency, mitigate cyber risk, and enable compliance audit-readiness.
See moreLatest activity
Latest activity from Cylera
2 signals
Discover more
Similar signals
Similar public activity from other companies.
Products & Services
Palo Alto Networks
Palo Alto Networks reported that the tool quietly runs git to figure out your project and runs a poisoned setting in a folder named the attacker’s command.
Products & Services
Hacktron AI
Hacktron AI tools prevent pre-authentication Remote Code Execution (RCE) issues before they reach production
Products & Services
Maze
Maze investigates every vulnerability using context from your code, cloud, and runtime before anything hits Jira
Products & Services
AISLE™
AISLE™ discovered 6 additional high- and critical-severity vulnerabilities in FFmpeg, following the 21 issues and 6 CVEs found in late July, in a codebase already scanned by both Google and Anthropic.
Products & Services
Cyera