logo

Last Week in AppSec for 26. February 2026

ID: 5a848d43-bd60-5fab-a720-e2e33ddceb60

STIX ID: report--5a848d43-bd60-5fab-a720-e2e33ddceb60

Feed Name: Checkmarx Zero

Threat Score
75/100

Date Published: 2026-02-26

Date Updated: 2026-04-27

Author: Darren Meyer

...
...

This Checkmarx report details multiple high-risk issues in AI developer tools: Claude Code hook and MCP configuration vulnerabilities (CVE-2025-59536 and CVE-2026-21852) that allow remote command execution via malicious repository files, and a GitHub Copilot prompt-injection technique in Codespaces that can exfiltrate GITHUB_TOKEN values. The article explains attack mechanics, points to researcher write-ups, and recommends mitigations such as updating software, treating config changes with high scrutiny, and heeding trust dialogs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.