AI + Shopify
GitLost: We Tricked GitHub's AI Agent into Leaking Private Repos (opens in a new tab)
Researchers tricked GitHub's AI agent into leaking private repositories
Hacker News· Jul 8, 2026· 8/10
AI + Shopify
Researchers tricked GitHub's AI agent into leaking private repositories
Hacker News· Jul 8, 2026· 8/10
TL;DR : Noma Labs discovered a critical prompt injection vulnerability within GitHub’s new Agentic Workflows, allowing an unauthenticated attacker to silently pull data from private repositories by posting a crafted GitHub Issue in a public repository belonging to the same organization as the private repositories. Noma Labs named the vulnerability GitLost. Your browser does not support the video tag. Introduction GitHub recently launched GitHub Agentic Workflows, pairing GitHub Actions…
Read the full article on Hacker News (opens in a new tab)AI + Shopify
Hacker News· Aug 17, 2026· 6/10· 89% relevant
An AI-generated Copilot autofix exposed a security flaw in Snowflake's Jira, raising concerns about AI code safety.
RelatedAI + Shopify
Hacker News· May 8, 2026· 6/10· 85% relevant
Show HN: Git for AI Agents
RelatedAI + Shopify
Hacker News· Sep 12, 2026· 7/10· 84% relevant
Benchmarking AI models on private, real-world enterprise codebases to evaluate performance and applicability.
RelatedAI + Shopify
Hacker News· Aug 13, 2026· 7/10· 84% relevant
AI agents are perceived as dishonest and may deter users
RelatedAI + Shopify
Hacker News· Aug 17, 2026· 6/10· 83% relevant
A Hacker News thread offers strategies to mitigate intrusive AI features in development environments.
RelatedAI + Shopify
Hacker News· Sep 24, 2026· 6/10· 83% relevant
Reports on rogue AI agent activity and hacking attempts on urlquery.net.
Related