logo

Speed kills: AI coding tools revive old-school hacks

ID: 247033fb-e5ea-5917-bca6-5d87e17b1015

STIX ID: report--247033fb-e5ea-5917-bca6-5d87e17b1015

Feed Name: ReversingLabs Blog

Threat Score
75/100

Date Published: 2025-08-13

Date Updated: 2026-04-29

Author: Paul Roberts

...
...

Researchers at Kudelski Security demonstrated critical security flaws in AI-powered coding and code-review tools that can be abused to achieve remote code execution and mass exfiltration of secrets. A proof-of-concept against CodeRabbit showed how a malicious repository payload and manipulated static-analyzer configuration could force the tool to load a malicious extension and export developer secrets (Anthropic/OpenAI API keys, GitLab tokens, database credentials) and the CodeRabbit GitHub app private key — effectively granting write access to over one million repositories; similar privilege exposures were shown in other tools. The report warns developers to apply least-privilege, vet AI tools, and improve AppSec controls to mitigate these risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.