← Founder Notes
Archive ·

Mandiant found an attacker who hijacked an active ai coding-assistant session, had it recommend…

14:34 ISTby Yethikrishna R

mandiant found an attacker who hijacked an active ai coding-assistant session, had it recommend poisoned packages, stole github oauth tokens, and spread a worm across about 100 internal repos. the assistant didn't fail — it was operated. the trust boundary is now the session, not the developer's machine.

Share

Embed this note

<iframe src="https://founder.myndlabs.tech/notes/embed/mandiant-found-an-attacker-who-hijacked-an-active-DdbEldCkSzu" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="Mandiant found an attacker who hijacked an active ai coding-assistant session, had it recommend…"></iframe>

Original

More notes