CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2228

As cited

Copy frozen at (site build).

ai security

AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique

Wiz has disclosed a new attack method called GhostApproval that tricks AI coding assistants into compromising developer machines using longstanding techniques. The attack exploits the trust developers place in AI code suggestions to execute malicious commands or introduce vulnerabilities on local systems.

Why it matters: Developers and organizations using AI coding assistants face direct risk of machine compromise when accepting AI-generated code without scrutiny; teams should establish code review practices and understand how AI tools can be manipulated before trusting their output.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique

Wiz disclosed a novel attack technique called GhostApproval that tricks artificial intelligence (AI) coding assistants into compromising developer machines using an established exploitation method. The attack leverages the trust developers place in AI-generated code suggestions to deliver malicious payloads without detection.

Why it matters: Developers and security teams using AI coding assistants face a direct threat: adversaries can weaponize trusted development tools to gain initial access to machines with repository and credential access, making this a supply chain risk that requires immediate code review discipline.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary