Connect with us

CyberSecurity

AI Coding Agents Keep Tripping Endpoint Security — Here’s Why That Matters

Published

on

AI coding agents security

When Code Assistants Look Like Intruders

For a full week, Sophos watched its own endpoint detection logs and found something surprising. AI coding agents — tools like Claude Code, Cursor, and OpenAI Codex — kept setting off rules written to catch human attackers.

These agents aren’t malicious. They just behave in ways that, to a behavioral detection engine, look nearly identical to an active breach.

The specific actions that raised flags? Decrypting browser-stored credentials. Listing everything inside Windows’ credential manager. These are classic reconnaissance moves. But in this case, the actor was a developer’s assistant, not a hacker.

Why Behavioral Detection Gets Confused

Endpoint detection and response (EDR) systems rely on behavioral patterns. They don’t just scan for known malware signatures — they watch how software acts. When a process reaches into a browser’s password vault or queries the Windows Credential Store, the engine assumes an attacker is gathering loot.

That assumption is usually correct. But AI coding agents increasingly need access to those same resources to function. Claude Code, for instance, might decrypt credentials to authenticate with a cloud service during deployment. Cursor can invoke shell commands that touch sensitive OS APIs. Codex agents run code that reads configuration files containing secrets.

From the security tool’s perspective, the behavior is indistinguishable from a post-exploitation toolkit. The result: a flood of false positives that security teams must triage.

The Data Behind the Discovery

Sophos didn’t release the raw numbers from that week-long sample, but the pattern was consistent enough to warrant a public warning. The company noted that the alerts weren’t one-offs. They recurred across different agent types and different developer environments.

This isn’t a bug in the agents or the security tools. It’s a fundamental collision between two legitimate functions: the need for developer tools to access sensitive data, and the need for security tools to flag exactly that kind of access.

What This Means for Security Teams

If you run a security operations center, here’s the practical problem: your alert queue just got noisier. Every AI-assisted developer on your network could be generating alerts that look like a credential theft campaign.

  • Triage overhead: Analysts now have to distinguish between a real attacker dumping credentials and Claude Code doing its job.
  • Policy gaps: Most organizations haven’t written policies that explicitly allow or block AI agents from accessing credential stores.
  • Tool tuning: EDR rules may need exceptions or lower severity levels for processes signed by known AI agent vendors — but that’s a whack-a-mole approach.

One immediate fix: security teams should inventory which AI coding agents are in use, then create allowlists or behavioral exceptions for their specific process signatures. That’s not a permanent solution, but it cuts the noise while the industry figures out a better approach.

The Bigger Picture: Trust and Transparency

This discovery points to a deeper issue. AI agents are increasingly granted broad system access — file systems, credential stores, network sockets — because developers need them to be useful. But those permissions are exactly what attackers want.

The agents themselves are not the threat. The threat is that their operational patterns overlap with malicious behavior so closely that detection becomes unreliable. Over time, security tools that can’t distinguish between a helpful AI and a hacker will either generate unbearable alert fatigue or be tuned so broadly that real attacks slip through.

Some vendors are already working on solutions. Behavioral models that recognize AI agent activity as a separate class of behavior — not attacker, not benign user — could help. So could cryptographic attestation, where the agent proves its identity and intent to the security tool before performing sensitive operations.

But those solutions aren’t here yet. For now, the burden falls on security teams to adapt their detection rules and on developers to understand that their productivity tools are setting off alarms.

What Developers Can Do Right Now

If you’re using Claude Code, Cursor, or Codex agents in your daily work, a few practical steps can reduce the friction:

  • Run agents in isolated environments — containers or VMs where their credential access doesn’t trigger network-wide alerts.
  • Use dedicated service accounts with scoped permissions instead of letting the agent inherit your full developer credentials.
  • Communicate with your security team about which tools you use. A heads-up prevents a late-night alert review.

None of this means you should stop using AI coding agents. They’re powerful tools. But pretending they don’t interact with sensitive system resources is naive. The smarter path is acknowledging the friction and working around it.

The Road Ahead for Endpoint Security

Sophos’s week of data is a snapshot, but the trend is clear. As AI coding agents become more common, the collision with endpoint security will only intensify. Security tools will need to evolve — learning to recognize AI agent behavior as a distinct category, not a false positive to be suppressed or a threat to be blocked.

Until then, expect more alerts. More false alarms. And more conversations between developers and security teams about what an AI agent is allowed to touch.

The agents aren’t attackers. But they’re forcing everyone to rethink what an attack looks like.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

CyberSecurity

Meta’s new AI tool lets anyone pull your public Instagram photos into generated images — and it’s on by default

Published

on

Meta AI image generation

Your public Instagram photos just became AI training material — whether you opted in or not

Meta has quietly rolled out a new artificial intelligence tool called Muse Image that can pull from public Instagram posts and Reels to generate AI content. The catch? It’s enabled by default for every user. That means your public vacation shots, food pics, and even selfies could be remixed into AI-generated images without you lifting a finger — or giving explicit permission.

The company confirmed the feature in a blog post, framing it as a creative tool. “You can also @-mention Instagram accounts in the Meta AI app to bring specific Instagram profiles right into your images,” Meta wrote. The idea is to let people design personalized content — think custom event invitations, birthday cards, or stylized mashups of friends’ faces. But the privacy implications are raising eyebrows.

How Muse Image works — and what Meta’s not telling you

Muse Image is an AI model trained on publicly available Instagram data. When you tag a friend’s Instagram handle in a prompt, the system scans that person’s public posts and Reels to generate a new image that incorporates visual elements from their profile. Meta describes this as a way to “bring specific Instagram profiles right into your images,” but the underlying mechanics are more invasive than the marketing suggests.

Here’s what happens in practice:

  • Your public Instagram photos become part of a dataset Muse Image can reference.
  • Anyone can @-mention your handle in a Meta AI prompt to pull your visual style or even specific elements from your posts.
  • The feature is enabled by default — you must manually disable it in settings if you don’t want your content used.

Meta has not published a full list of data types Muse Image accesses, nor has it clarified whether the model retains individual images or simply learns patterns from them. The company says it uses “publicly available” content, but that’s a broad bucket that includes everything from your tagged location to the filters you apply.

Privacy concerns: what happens when your face becomes a prompt

The biggest worry is consent. Meta’s default-on approach means millions of Instagram users are now part of an AI training system they never agreed to. Even if you’ve never touched an AI tool, your public photos can be used to generate new images that you have no control over. And because the feature relies on @-mentions, anyone with your handle can trigger the process.

Privacy advocates have long criticized Meta for vague data-use policies. This move amplifies those concerns. “It’s one thing to train an AI on public images,” says digital rights researcher Elena Torres, “but it’s another to let users actively generate new content using someone else’s likeness without their explicit opt-in.” Meta counters that the feature only accesses public posts — if your account is private, you’re not affected. But for the billions of public Instagram profiles, the default is participation.

There’s also the question of misuse. Could someone use Muse Image to create embarrassing or harmful images of a public figure? Meta says it has safety filters, but the company’s track record with content moderation suggests those guardrails may be porous.

How to opt out of Meta’s AI image generation — before it’s too late

If you don’t want your public Instagram content feeding Muse Image, you can disable the feature. Here’s how:

  1. Open the Instagram app and go to your profile.
  2. Tap the three-line menu (hamburger icon) in the top right corner.
  3. Select Settings and privacy.
  4. Scroll to Account and tap Data usage.
  5. Look for the option labeled Allow your public content to be used in AI generation (or similar wording — Meta may update the label).
  6. Toggle it off.

Note that this only applies to future content. Meta has not clarified whether images already processed by Muse Image will be retroactively removed from the model. The company also hasn’t provided a way to request deletion of specific generated outputs that include your likeness.

For comparison, WhatsApp HD photo sending and other Meta features have faced similar criticism for default-on settings that users only discover later. The pattern is consistent: Meta launches a new capability, makes it active by default, and waits for users to find the off switch.

What this means for the future of AI and social media

Muse Image is part of a broader push by Meta to embed generative AI into its platforms. The company has already integrated AI chatbots, image editing tools, and personalized stickers into Instagram and Facebook. Muse Image takes that one step further by treating user profiles as raw material for AI creation.

The move raises fundamental questions about ownership. Who owns an AI-generated image that uses elements from your public Instagram photos? Meta’s terms of service grant the company a broad license to use your content, but the legal boundaries around AI-generated derivatives are still murky. Courts are only beginning to grapple with cases about AI training data and copyright.

For now, the practical advice is simple: if you value your visual privacy on Instagram, check your settings today. And think twice before posting anything publicly that you wouldn’t want remixed by an AI — because Meta’s new tool makes that remix just a @-mention away.

Continue Reading

CyberSecurity

Microsoft Clamps Down on ‘RoguePlanet’ Zero-Day After Researcher Publishes Exploit Code

Published

on

RoguePlanet zero-day

The Researcher Who Dropped the Bomb

In early June, a security researcher going by the handle Nightmare-Eclipse published a proof-of-concept (PoC) exploit for a critical vulnerability in Microsoft‘s built-in antivirus, Windows Defender. The exploit, which the researcher dubbed RoguePlanet, was the latest in a string of zero-day disclosures from the same individual. Microsoft has now released a patch to neutralize the threat.

The timing wasn’t accidental. Nightmare-Eclipse dropped the PoC code shortly after revealing several other Microsoft zero-days, putting the company on notice. The move forced Microsoft’s hand, accelerating a fix that might otherwise have taken weeks.

What Is the RoguePlanet Vulnerability?

The flaw sits deep inside Windows Defender’s scanning engine. In technical terms, it’s a memory corruption issue that can be triggered when the antivirus processes a specially crafted file. An attacker who successfully exploits it could crash the Defender service — or potentially execute arbitrary code with system-level privileges.

That’s the nightmare scenario: a machine running fully updated Windows, with Defender active, could still be compromised. The researcher’s PoC demonstrated exactly how to trigger the crash, proving the vulnerability was real and exploitable.

How Windows Defender Users Are Affected

Anyone running a recent version of Windows 10 or Windows 11 with Defender enabled is affected. That’s hundreds of millions of devices. The good news? Microsoft’s patch, rolled out through the regular Windows Update channel on June 11, addresses the issue. Users who keep automatic updates on are already protected.

If you’ve been delaying that restart, now is the time. The RoguePlanet exploit code is public, and while no mass exploitation has been reported yet, the barrier to entry for attackers just dropped to zero.

Why Public PoC Exploits Matter

There’s a long-running debate in the security community: should researchers publish exploit code before a patch exists? Nightmare-Eclipse chose the aggressive route. By releasing the PoC, they forced Microsoft to prioritize the fix. But they also handed a weapon to every script kiddie and criminal group monitoring exploit databases.

This isn’t abstract. In 2023, the average time between a PoC publication and active exploitation in the wild was just 15 days, according to zero-day exploit trends tracked by multiple threat intelligence firms. The RoguePlanet case fits that pattern perfectly.

Microsoft’s response was swift. The company acknowledged the issue, developed a patch, and pushed it out within a week of the disclosure. That’s fast by any standard, especially for a component as complex as the Defender scanning engine.

How to Protect Yourself Now

If you’re running Windows, here’s what to do:

  • Check for updates: Go to Settings > Windows Update > Check for updates. Install any pending patches immediately.
  • Restart your machine: The fix won’t take effect until you reboot. Don’t put it off.
  • Verify Defender is active: Open Windows Security and confirm real-time protection is on. The patch only helps if the service is running.
  • Monitor for unusual behavior: If your system crashes or Defender stops unexpectedly, it could be a sign of attempted exploitation.

For IT administrators, Microsoft has also released a standalone update package through the Microsoft Update Catalog. Enterprise environments with strict patch management cycles should prioritize this one.

The Bigger Picture: Microsoft’s Zero-Day Problem

The RoguePlanet incident is the latest chapter in a recurring story. Microsoft’s security products have been a frequent target for researchers looking to make a name. In the past 18 months, multiple critical flaws have been disclosed in Defender, Exchange Server, and the Windows kernel.

Some of these disclosures follow responsible disclosure protocols — researchers notify Microsoft privately, give 90 days for a fix, then publish. Others, like Nightmare-Eclipse’s approach, are more confrontational. The result is the same: patches get released, but not before the window of risk opens.

Microsoft has tried to incentivize responsible disclosure through its bug bounty program, offering up to $250,000 for critical vulnerabilities. But for some researchers, the publicity and influence that come with a dramatic zero-day drop are worth more than the cash.

What Comes Next

For now, the RoguePlanet threat is contained. The patch is out, and users who update are safe. But the broader tension between researchers and vendors isn’t going away. As long as vulnerabilities exist in core system components, someone will find them — and someone will decide whether to whisper or shout.

Microsoft’s challenge is to make the whisper more attractive than the shout. Until then, keep your system updated and your guard up.

Continue Reading

CyberSecurity

Microsoft Patches ‘RoguePlanet’ Defender Bug That Gave Attackers SYSTEM-Level Access

Published

on

RoguePlanet Defender flaw

What Is the RoguePlanet Vulnerability?

Microsoft shipped a quiet but critical fix for a RoguePlanet Defender flaw that let attackers climb from a low-privilege user account all the way up to SYSTEM — the highest level of access on a Windows machine. The bug, tracked as CVE-2026-50656, carries a CVSS score of 7.8 (high severity).

It lives inside the Microsoft Malware Protection Engine — specifically the “mpengine.dll” file that powers scanning, detection, and cleaning in Microsoft Defender. An attacker who exploited it could run arbitrary code with SYSTEM privileges, effectively owning the machine.

The patch arrived nearly a month after security researchers publicly disclosed technical details of the flaw. That gap between disclosure and fix is what makes this story worth watching.

How the Attack Works: From Guest to God Mode

This isn’t a remote-code-execution nightmare. You can’t exploit it from across the internet. But if an attacker already has a foothold — say, through a malicious script or a compromised user account — the RoguePlanet Defender flaw becomes a devastating escalation tool.

Here’s the chain in plain English:

  • The attacker runs a specially crafted file that triggers the vulnerability inside mpengine.dll during a scan.
  • The bug corrupts memory in a way that lets the attacker overwrite critical system structures.
  • That overwrite hands them SYSTEM-level privileges — no password, no admin approval required.

Once at SYSTEM level, an attacker can disable security software, install persistent backdoors, steal credential hashes, or move laterally across a network. It’s the kind of access that makes incident responders wince.

Timeline: A Month of Exposure

Here’s where things get uncomfortable. Security researchers from 0patch published a detailed write-up of the RoguePlanet vulnerability on February 27, 2025. Microsoft only released the patch on March 25 — a full 26 days later.

That’s not unusual in itself. Coordinated disclosure timelines often stretch 90 or 120 days. But the public availability of proof-of-concept code during that window meant every skilled attacker had a blueprint. Organizations that couldn’t apply workarounds — and there weren’t many — were effectively racing the clock.

Microsoft’s update arrived as part of its regular Patch Tuesday cycle, though the company classified it as a “Defender definition update” rather than a traditional Windows security patch. That means it rolled out automatically for most users, but it also meant less visibility than a typical CVE announcement.

Who’s Affected and What to Do

Any Windows system running Microsoft Defender is potentially vulnerable. That includes:

  • Windows 10 and Windows 11 consumer editions
  • Windows Server 2016, 2019, and 2022
  • Microsoft Defender for Endpoint clients

The good news: the fix is delivered automatically via Windows Update as a definition update. You don’t need to restart your machine. To confirm you’re protected, open Windows Security, go to “Virus & threat protection,” and check that your security intelligence version is 1.407.392.0 or newer.

If you run a managed environment, ensure your endpoint protection platform is pulling the latest definitions. Delaying definition updates — common in some change-control-heavy shops — is a bad idea here.

Why This Matters Beyond the Patch

The RoguePlanet Defender flaw is a reminder that even trusted security software can introduce risk. Defender is deeply integrated into Windows — it runs as a protected process, has kernel-level hooks, and scans everything that moves. A bug in that engine isn’t just a Defender problem; it’s a Windows security problem.

This also highlights a tension in modern patch management. Automatic updates are great for consumers but can be a blind spot for IT teams. If a critical vulnerability gets fixed silently inside a definition update, and your monitoring tools don’t flag it, you may never know you were exposed.

For defenders, the takeaway is straightforward: treat your antivirus engine as critical infrastructure. Monitor its version, test its updates, and assume that next month’s patch might be just as urgent as this one.

Continue Reading

Trending