Connect with us

CyberSecurity

Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It

Published

on

AI coding agents

The AI Agents Meant to Protect Us Can Be Turned Against Us

Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker’s code on your own machine instead. That’s the unsettling finding from a new proof-of-concept published Wednesday by the AI Now Institute. The attack, dubbed “Friendly Fire,” targets Anthropic‘s Claude Code and OpenAI‘s Codex — two of the most widely used AI coding agents — when either is running in an autonomous mode that approves its own actions.

The core issue isn’t that these tools are poorly built. It’s that they’re too trusting — of the code they analyze and of themselves. When a developer asks an AI coding agent to review a third-party library or a pull request for vulnerabilities, the agent might execute commands embedded in the very code it’s supposed to inspect. Attackers can craft malicious snippets that look like harmless code but contain hidden instructions for the AI to run.

How the Friendly Fire Attack Works

The attack exploits a fundamental design flaw in autonomous coding agents. These agents operate by reading code, analyzing it for security issues, and then — crucially — executing actions based on that analysis. In autonomous mode, they don’t stop to ask a human for permission before running a command. So if the code under review contains a carefully disguised instruction like a shell command or a hidden API call, the agent runs it without a second thought.

The AI Now Institute demonstrated this with Claude Code and Codex. In their tests, they embedded malicious payloads inside seemingly benign open-source packages. When the agents scanned these packages for vulnerabilities, they triggered the payloads — effectively compromising their own host environment. The attack doesn’t require sophisticated social engineering. It’s a simple bait-and-switch: hide a dangerous command inside code that looks safe to review.

“The agent doesn’t distinguish between code it should analyze and code it should execute,” the researchers noted in their paper. “It treats all code as equally trustworthy.”

Why Autonomous Mode Is the Problem

Autonomous mode is a feature, not a bug — at least from the developer’s perspective. It lets Claude Code and Codex work through long tasks without constant hand-holding. You ask it to audit a codebase, and it plows through hundreds of files, flagging issues and even suggesting fixes. That speed is what makes these tools valuable.

But speed comes at a cost. In autonomous mode, the agent approves its own actions. It doesn’t ask, “Hey, should I run this command?” It just runs it. That’s fine when the code is clean. But when the code is malicious, the agent becomes an unwitting accomplice. The attacker doesn’t need to break into your system; they just need to trick the tool you trust into doing it for them.

The researchers point out that this isn’t a theoretical risk. Open-source code is the backbone of modern software development, and developers regularly use AI coding agents to scan it for flaws. If an attacker can poison a popular package — or even a single pull request — with a payload that targets these agents, they can compromise every machine that scans it.

Both Anthropic and OpenAI Have Been Notified

The AI Now Institute says it responsibly disclosed the vulnerability to both Anthropic and OpenAI before publishing the proof-of-concept. As of now, neither company has released a patch or a public statement addressing the specific attack. The researchers note that the issue isn’t limited to these two tools — any AI coding agent running in an autonomous mode that executes code from the input could be vulnerable.

Claude Code and Codex are the most prominent examples, but the attack pattern likely applies to other agents that follow similar design principles. The researchers recommend that developers avoid using autonomous mode when scanning untrusted code. If you must use it, they suggest running the agent in a sandboxed environment with no network access and limited file system permissions.

“The safest approach is to never let an AI agent execute code it’s analyzing,” the paper states. “Treat all external code as hostile until proven otherwise.”

What Developers Can Do Right Now

Until the companies roll out fixes, developers have a few options to protect themselves:

  • Disable autonomous mode when scanning code from unknown sources. Require explicit human approval for every action.
  • Run AI coding agents in isolated environments — containers, virtual machines, or sandboxes with restricted permissions.
  • Audit the agent’s actions manually before approving them. Don’t trust the agent’s judgment blindly.
  • Use static analysis tools that don’t execute code as part of their workflow. Traditional linters and vulnerability scanners don’t have this problem.

None of these are perfect solutions. Disabling autonomous mode defeats the purpose of using AI agents for speed. Running them in sandboxes adds overhead. But for now, it’s the best defense available. The Friendly Fire attack is a reminder that AI security flaws aren’t just about models hallucinating or leaking data — they can also turn your tools into weapons.

The broader lesson is that AI coding agents need a fundamental redesign. They should treat code as data, not as commands. They should never execute code they’re analyzing unless explicitly instructed to — and even then, only with human oversight. Until that happens, every developer using Claude Code or Codex in autonomous mode is one malicious pull request away from a compromised machine.

“We built these tools to help us write safer code,” the researchers conclude. “But we forgot to make them safe themselves.”

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

CyberSecurity

LG to Ban Residential Proxies from Smart TV Apps After Security Study

Published

on

residential proxies

Why LG Is Cracking Down on Proxy SDKs

LG Electronics announced this week it will suspend any smart TV apps that turn televisions into always-on residential proxy nodes. The move comes less than a month after researchers revealed that over 42 percent of games and utilities on LG’s webOS store let unknown third parties route internet traffic through users’ TVs.

Security firm Spur published findings in early July showing that residential proxy software development kits (SDKs) have quietly infiltrated smart TV platforms. For Samsung’s Tizen OS, more than a quarter of apps contained similar components. The data suggests a systemic problem, not an isolated incident.

What Are Residential Proxies Doing in Your TV?

Residential proxy networks pay app developers to embed SDKs that turn a device into a proxy node. Paying customers then rent that node to route their own traffic through it. In LG and Samsung smart TVs, Spur found these SDKs bundled with everything from Pac-Man clones to screensavers and file managers.

A Pac-Man app from Bright Data even offers users a choice: watch ads or let the TV serve as a proxy node. Bright Data, which accounted for the majority of proxy SDKs on both platforms, did not respond to requests for comment.

Bright Data and other providers claim they follow rigorous know-your-customer processes to prevent abuse. They also say they deploy countermeasures that stop proxy customers from interacting with other devices on the user’s local network. But critics argue that a one-time consent prompt buried in a TV app is not enough.

LG’s Response: Suspensions and Policy Changes

LG Senior Vice President John Taylor told KrebsOnSecurity that the company is working with developers to remove residential proxy options from their apps. Developers that fail to comply will see their apps suspended.

“A residential proxy network is not an intended use for LG smart TVs,” Taylor said. “LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform. If this option is not removed, these apps will be suspended.”

Taylor added that the review is “well underway now.” LG will also strengthen its evaluation process for developer-submitted apps, including those that incorporate proxy SDKs.

The Deeper Problem: Consent and Awareness

Spur’s Trevor Sutter put it bluntly: “A one-time consent prompt buried in a TV app is not a substitute for meaningful transparency, ongoing control, and platform oversight. The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors.”

Most consumers do not think of their smart TV as a computer. They don’t audit apps or check for background network activity. That makes residential proxies particularly insidious. The device sits in the living room, always on, always connected — an ideal node for someone who wants to hide their traffic behind a real residential IP address.

Spur’s report notes that the problem is not that residential proxy networks exist, but that they are being embedded at scale in devices that most people cannot easily monitor.

LG’s Other Controversy: McAfee Bloatware

LG’s announcement comes amid criticism over another partnership. This week, the YouTube channel Gamers Nexus showed that certain LG LCD monitors automatically install an app promoting paid McAfee antivirus subscriptions. The app arrives through Windows Update without any approval prompt. Users reported that the software drivers push McAfee promotions without consent, triggering frustration among gamers and professionals alike.

LG has not yet commented on the McAfee issue. But the combination of proxy SDKs in smart TVs and unwanted antivirus promotions in monitors suggests a pattern: LG is comfortable embedding third-party monetization in its hardware, often without clear user consent.

What This Means for LG Users

For now, LG’s crackdown on residential proxies is a positive step. Users should check which apps are installed on their webOS smart TVs and remove any they do not recognize. If an app offers a choice between ads and “network sharing,” the safest option is to uninstall it entirely.

The company says it will continue to review apps and enforce the ban. Whether that translates into real change — or just a temporary PR move — remains to be seen. But for the millions of LG smart TV owners, the message is clear: your television should not be a tool for strangers to hide their internet activity.

As Spur’s research showed, the problem extends beyond LG. Samsung has not announced any similar action for its Tizen platform. Consumers who want to avoid residential proxies altogether may need to look beyond the app store — or consider whether they need a smart TV at all.

Continue Reading

CyberSecurity

CISO Conversations: Andreas Gaetje – Why Business Sense Beats Bit-Crawling in Security Leadership

Published

on

Andreas Gaetje CISO

Not Your Typical Hacker Story

Andreas Gaetje won’t pretend he spent his teenage years breaking into systems or writing exploits. He didn’t. The CISO at Körber AG came to cybersecurity from economics and business politics — a route that was unusual in the 1990s and still raises eyebrows today.

“I’m not the deepest bit-crawler,” Gaetje admits. “That’s just not who I am.” And yet, he now leads security for a global technology and manufacturing group with roughly 13,000 employees across 100 locations. Körber’s machines are behind much of the world’s pharmaceutical supply chain. “Probably every vaccine you ever received has been through our machines,” he notes.

His story is a useful counterpoint to the idea that you need to be a hardcore technical wizard to become a CISO. What you do need, Gaetje argues, is a deep understanding of business, the ability to learn constantly, and the trust of the people around you.

From Public Service Dreams to a Consulting Detour

Gaetje didn’t set out to work in security. In the mid-1990s, fresh out of university with a focus on economics and business politics, he expected to land a job in public services. But reality intervened. He needed money immediately, not someday.

The internet was just beginning to transform from an academic niche into a business necessity. Email was becoming the default communication tool. Gaetje made a pragmatic pivot: “I said to myself, Okay, let’s maybe do something in the computer business.”

He joined a consulting firm, hoping to blend his interest in business and technology. But by the early 2000s, he realized that to truly focus on business inside IT, he needed depth in a single sector. He chose finance. “The best industry at that point in time, where IT was really crucial, was the finance industry,” he recalls. He joined an insurance company as an auditor.

The Compliance Era That Changed Everything

Back then, cybersecurity wasn’t the existential business threat it is today. “ITsec and audit had a natural affinity,” Gaetje explains. “ITsec was primarily about compliance — it wasn’t yet the business threat it has since become.” His mix of business knowledge, IT understanding, and audit experience put him in the right place at the right time.

When cybersecurity began to explode as a discipline, he was asked to manage the growing information security function. The real turning point came in the 2010s, with attacks like WannaCry and NotPetya. “It was very clear: we weren’t talking about a simple compliance issue anymore. This was a serious business threat,” he says. “Cybersecurity had become a hot topic. It was complex, innovative, and really interesting to work in.”

By 2018, Gaetje was CISO at Körber IT Solutions. A year later, he took the top security role at the parent company, Körber AG.

Career Advice: Don’t Get Stuck in One SECTOR

Gaetje credits much of his growth to a single piece of advice: if you want to truly understand security, don’t stay too long in one company or one industry. Different sectors have different risk profiles. Stay in one place too long, and your thinking can get rigid. Attackers change fast. You need to be able to change how you think.

“It’s what made me move from the insurance industry into manufacturing and machine building,” he says. “I wanted to learn something else, to experience something new, and do something different.”

What Makes a Security Leader?

Gaetje is blunt about his own leadership style. “I’m not a born leader. I would never consider that,” he says. But he has a clear philosophy: a leader provides direction and a vision of what can be achieved and how. In any group, someone emerges as the de facto leader. The challenge is to justify that dominance with reliability and trust.

“It’s something you can learn,” he insists. “It’s not something that comes out of the blue. I learned and enhanced that learning with training courses. But of course, your personality is also important. You need to be reliable — you need to be a person that people trust, otherwise it just doesn’t work.”

Leadership, Gaetje believes, isn’t limited to formal management titles. “You’re a leader, even if it’s a thought leader driving and directing other people in a specific direction.”

Building a Security Team in a Talent Crisis

The cybersecurity skills gap is well documented — estimates in 2025 ranged from 2.8 million to 4.8 million unfilled positions globally. Gaetje has felt that pressure firsthand. “In recruiting your team, you have a wish list, and then you have reality — and unfortunately, they don’t always fit together,” he says.

But one requirement is non-negotiable: “I need people who want to learn.” The cybersecurity landscape shifts so fast that prior experience matters less than curiosity. “It’s incredible how fast things change. So, what I always need are people who are engaged, can think out of the box, and want to go the extra mile to understand what’s going on.”

Training and career development he can provide. But that initial spark of enthusiasm? That’s on the candidate. “So, whether I’m looking for an engineer, an analyst or some junior position, experience is good, but enthusiasm to learn is necessary.”

Would He Hire a Hacker?

“That depends,” Gaetje says. The hacker mentality — built-in curiosity and persistence — is valuable. But there are two types. “White hackers I would employ; blackhats, no.” He isn’t comfortable bringing someone with a history of malicious activity into Körber.

His advice to ambitious team members is simple: “Be curious. Things are really changing. If you think you know everything about anything, you’re wrong. That’s never true. There’s always something new coming for you to learn and experience.”

AI: The Double-Edged Sword That’s Reshaping Security

Gaetje’s biggest concern today isn’t a specific threat — it’s the sheer speed of technological change. “Just think about the many things you’ve learned in the last few weeks, about new developments, new products and new techniques that have been deployed to the public. AI is an example — we learn new things about the potential of generative AI and agentic AI every week. What used to occur over a period of two years or more now happens in a couple of weeks.”

AI presents a unique challenge because it’s used by both attackers and defenders. Attackers are using it to scale and sophisticate their operations. Defenders are fighting back with their own AI, but those defenses can be manipulated. Meanwhile, shadow AI — systems deployed without IT or security knowledge — is proliferating inside organizations.

“The pace of new technology is truly hard to manage,” Gaetje says. “For each new technology you must find time to learn and understand it — but that’s on top of everything else you’re already doing. And it’s not just you — everyone on your team must find time to understand the new technology, and you must personally motivate them to do so when they are already fully occupied.”

Will AI reduce the need for human security staff? Gaetje doesn’t think so. “I think the role of cybersecurity, and even my own role will be much more important in the future than it is today. But it may change.” As AI spreads across the business, security problems will become too widespread for the security team to handle alone. Other departments — product development, software engineering — will need to be brought into the fold.

The Risk of Losing Core Skills

Gaetje worries that AI could erode foundational skills, especially among programmers and SOC analysts. “AI coding assistants require prompt engineers and architects above programmers — and that can be a problem. How do you bring people from this level to the next level if they are not able to program on their own?”

A similar issue looms for security analysts. The standard view is that AI will collapse the SOC tier hierarchy — no more tier 1 analysts doing triage because AI will handle it. But Gaetje asks: “If the security analyst job can be done via an agentic AI tool, then how will analysts learn how to analyze an event? Maybe in the future, if we just rely on AI, we will lose the ability to see the tricky things in the incident.”

Still, he’s not pessimistic. “I’m pretty sure we will find different ways to handle the changes. And honestly, there’s so much out there that I’m not really concerned that we will lose anything.”

The real challenge, he says, is guiding the security team through this transition. “The job of the security team will change dramatically in the future. That’s my strong belief. The CISO challenge is to help team members along this road to a new level, where they are able to think out of the box to see what else they can bring to the job.”

For more insights from security leaders, check out our other CISO Conversations with Aimee Cardwell and Tarah Wheeler.

Continue Reading

CyberSecurity

AI Attacks Move in Minutes. Here’s How to Build a Defense That Keeps Up.

Published

on

AI attacks defense

The Speed Gap Is Real — and It’s Getting Worse

It used to take an attacker days to craft a phishing lure, identify a target, test it, and move laterally. Now? It takes minutes. Models like Mythos let adversaries automate nearly every step of the kill chain. They write tailored bait, pick the most vulnerable targets, test what lands, and jump to the next host before your team even clears the first alert.

That’s the gap. And it’s not your fault. Most security teams are still running on tools and runbooks built for attackers who work at human speed. But the attackers aren’t human-speed anymore.

So what do you do when the clock is no longer on your side?

Why Traditional Defenses Fall Short Against AI Attacks

The problem isn’t just speed. It’s scale. An AI-powered attack can adapt in real time, shifting tactics based on what it learns from each failed or successful probe. Your average security stack — SIEM, SOAR, EDR — wasn’t designed for that. It was designed for predictable, manual attack patterns.

Think about it. Most incident response playbooks assume a human attacker needs time to pivot. They assume you have minutes or hours to detect, analyze, and respond. That assumption is now dangerous.

A single AI-driven attack can generate dozens of low-level alerts in seconds. Your team drowns in noise while the real threat moves deeper into the network. By the time you realize what’s happening, the attacker — or the AI agent running the attack — is already gone.

What a Modern Defense Needs to Do

To keep up with AI-driven attacks, your defense has to be as fast and adaptive as the offense. That means three things:

  • Automated detection at machine speed. No more waiting for a human to review a log. The system needs to spot anomalies and correlate them in milliseconds.
  • Real-time response orchestration. When an attack is detected, the response — isolating a host, blocking an IP, revoking credentials — should happen automatically, without a human in the loop.
  • Continuous learning. The defense should get smarter with every attack, updating its models to recognize new tactics as they emerge.

This isn’t about replacing your analysts. It’s about giving them a force multiplier that can handle the volume and speed that no human can match.

Join the Webinar: Building a Defense That Keeps Up

On [Date], we’re hosting a live webinar with cybersecurity experts who have been building and testing these systems in real environments. We’ll walk through:

  • How attackers are using AI models like Mythos to accelerate every phase of an attack
  • Concrete examples of AI-driven attacks that bypassed traditional defenses
  • A framework for designing a defense that operates at machine speed
  • Lessons from organizations that have already made the shift

You’ll leave with a clear roadmap for upgrading your security operations to handle the new reality. No fluff. No vendor pitches. Just practical strategies from people who have been in the trenches.

Who Should Attend

This webinar is designed for SOC managers, incident responders, threat hunters, and anyone responsible for keeping their organization safe from advanced threats. If you’ve ever felt like your team is always one step behind, this is for you.

How to Register

Spots are limited. Register for the cybersecurity webinar here to secure your place. You’ll also get access to the recording and slides afterward.

The Bottom Line

AI attacks aren’t coming. They’re already here. The question is whether your defense can keep up. If you’re still relying on playbooks written for human-speed attackers, you’re already behind.

But it doesn’t have to be that way. With the right approach — and the right tools — you can build a defense that moves as fast as the threat. Join us, and let’s figure out how together.

See you there.

Continue Reading

Trending