Friendly Fire: Hijacking Defensive Cyber AI Agents for Remote Code Execution
Exploit Brief We are revealing a proof-of-concept exploit that enables remote code execution in Anthropic’s Claude Code CLI (with Claude Sonnet 4.6 & 5, Opus 4.8) and OpenAI’s Codex CLI (with GPT-5.5) when employed to defensively assess the security of an open-source or third-party library. Our attack only requires an out-of-the-box configuration of Claude Code […] The post Friendly Fire: Hijacking Defensive Cyber AI Agents for Remote Code Execution appeared first on AI Now Institute .
Record details
Published: 8 July 2026
Source: AI Now Institute
Category: Field notes
Topics: Military & security · Agents & autonomy
Retrieved: 14 July 2026
Related evidence
These records share source-supplied organisations, an exact publisher byline, automatic topics or regions. The reason is shown on every link; related does not mean supporting, agreeing with or verifying this record.
Policy Brief: Friendly Fire
AI Now Institute · 8 July 2026
Double Agents: Defensive AI Agents Magnify Cyber Risks
AI Now Institute · 8 July 2026
AI hackers are getting faster. The government may not be ready
Fast Company Tech · 29 July 2026
Hugging Face hack marks start of dangerous AI cyber era and many firms 'don't even know it'
CNBC Technology · 8 August 2026
Meta returns to open models with Zuckerberg's plan to out-copy China and sell compute by auction
The Decoder · 10 August 2026
An opinionated guide to which AI to use to do stuff
Simon Willisons Weblog · 27 July 2026
How to cite this record
ethics.ai (8 July 2026), “Friendly Fire: Hijacking Defensive Cyber AI Agents for Remote Code Execution,” evidence record 1618, https://ethics.ai/record/1618 (originally published by AI Now Institute).
Use and limitations
This page is a stable index and citation surface for a source record. ethics.ai did not author the underlying report and has not independently verified every claim. Automatic topics may be imperfect. For consequential use, quote and cite the original publisher.