Last Week in AppSec for 26. February 2026
ID: 5a848d43-bd60-5fab-a720-e2e33ddceb60
STIX ID: report--5a848d43-bd60-5fab-a720-e2e33ddceb60
Feed Name: Checkmarx Zero
This Checkmarx report details multiple high-risk issues in AI developer tools: Claude Code hook and MCP configuration vulnerabilities (CVE-2025-59536 and CVE-2026-21852) that allow remote command execution via malicious repository files, and a GitHub Copilot prompt-injection technique in Codespaces that can exfiltrate GITHUB_TOKEN values. The article explains attack mechanics, points to researcher write-ups, and recommends mitigations such as updating software, treating config changes with high scrutiny, and heeding trust dialogs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
