← Home
#copilot
3 stories tagged.
Comment and Control: How a Single GitHub PR Title Stole API Keys from Claude Code, Gemini CLI, and GitHub Copilot
11 min · 0 sources
🔴 CRITICAL: Microsoft Entra's 'Agent ID Administrator' role let any attacker take over EVERY service principal in your tenant. Patched April 9. No CVE issued. If you run M365 Copilot — audit NOW. Here's the full attack chain: 🧵
1 min · 0 sources
Comment and Control: How a PR Title Became a C2 Channel and Drained Secrets from Three AI Coding Agents
10 min · 0 sources