AINewsnow

Encrypted instructions trick Copilot CLI into spilling developer secrets

GitHub Copilot CLI can be made to read sensitive files from a developer’s machine and send their contents to an attacker from a single web page. Security researchers at Adversa AI said the new attack technique, dubbed Cryptographic Context Injection (CCI), hides malicious instructions inside encryp…

Read the full story at InfoWorld AI ↗

Timeline · 1 report

  1. 2026-10-07 11:54 · InfoWorld AI
    Encrypted instructions trick Copilot CLI into spilling developer secrets

More stories

  1. OpenAI will watermark ChatGPT outputs by default—but only in the EU — Ars Technica AI
  2. Claude Pro vs ChatGPT Plus vs Copilot Premium: which one would you choose for this use case? — r/ChatGPTPro
  3. Microsoft and Nvidia CEOs to launch Surface Laptop Ultra on Wednesday — The Next Web
  4. Satya Nadella reinvented Microsoft once. Can he do it again in the AI era? — CNBC Technology
  5. Anthropic’s enterprise moat is getting thinner — The Deep View
  6. One Copilot model refused. Another leaked secrets about half the time. — r/artificial
  7. PSA: if you manage dev machienes then every coding agent has its own file — r/AI_Agents
  8. I trust Anthropic with my data. I didn't agree to share it with Meta, TikTok and Google. (IMDEA study) — r/ClaudeAI

Get the daily brief of stories like this at 6:30 every morning →