cd/entity/GitLost· home entities GitLost
grep -l @gitlost /news/*.json | wc -l → 12

GitLost

mentions 12 type Organization feed RSS

// recent coverage 12 mentions

20:15
2026-07-13
dev.to
ai-safety

Your AI code reviewer ran my malware (85% hit rate)

The AI Now Institute published a proof-of-concept attack called Friendly Fire that achieves an 85% hit rate against AI coding agents. Researchers Boyan Milanov and Heidy Khlaaf planted a malicious scr…

12:13
2026-07-08
byteiota.com
ai-safety

GitLost: GitHub Agentic Workflows Leak Private Repos

On July 7, Noma Security disclosed a critical prompt injection flaw in GitHub's Agentic Workflows, dubbed GitLost, that allows any free GitHub account to extract private repository contents by posting…

10:04
2026-07-08
sourcefeed.dev
ai-safety

GitLost Proves Agentic Workflows Have No Trust Boundary

Noma Labs disclosed GitLost, a vulnerability in GitHub Agentic Workflows that allowed an attacker to exfiltrate private repository contents via a crafted public issue. The attack exploited the AI agen…

07:06
2026-07-08
letsdatascience.com
ai-safety

Noma Reveals GitLost Flaw Leaking Private Repositories

Noma Labs disclosed a vulnerability called GitLost that exploits GitHub Agentic Workflows via indirect prompt injection, allowing an AI agent to read private repositories and post contents as public i…

19:49
2026-07-07
letsdatascience.com
ai-safety

GitHub AI Agent Leaks Private Repositories

Noma Labs disclosed GitLost, a July 2026 prompt-injection technique that could make GitHub Agentic Workflows leak private repository contents through a public issue comment. The attack exploits an arc…

19:05
2026-07-07
sourcefeed.dev
ai-safety

Securing GitHub Agentic Workflows Against the GitLost Exploit

Security researchers at Noma Security demonstrated the GitLost exploit, which uses indirect prompt injection to trick GitHub Agentic Workflows into exfiltrating private repository data through public …

// co-occurs with top 8 entities
// topics top 6 topics