Close Menu
  • Home
  • Psychology
  • Dating
    • Relationship
  • Spirituality
    • Manifestation
  • Health
    • Fitness
  • Lifestyle
  • Family
  • Food
  • Travel
  • More
    • Business
    • Education
    • Technology
What's Hot

Claude Code, Copilot and Codex all got hacked. Every attacker went for the credential, not the model.

April 30, 2026

Sustainable tourism in Ecuador: Preserving ecosystems, empowering communities

April 30, 2026

40 Minutes of Recess Is Now the Law in This State

April 30, 2026
Facebook X (Twitter) Pinterest YouTube
Facebook X (Twitter) Pinterest YouTube
Mind Fortunes
Subscribe
  • Home
  • Psychology
  • Dating
    • Relationship
  • Spirituality
    • Manifestation
  • Health
    • Fitness
  • Lifestyle
  • Family
  • Food
  • Travel
  • More
    • Business
    • Education
    • Technology
Mind Fortunes
Home»Technology»Claude Code, Copilot and Codex all got hacked. Every attacker went for the credential, not the model.
Technology

Claude Code, Copilot and Codex all got hacked. Every attacker went for the credential, not the model.

April 30, 2026No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
Claude Code, Copilot and Codex all got hacked. Every attacker went for the credential, not the model.
Share
Facebook Twitter LinkedIn Pinterest Email

In a recent revelation on March 30th, BeyondTrust uncovered a critical vulnerability in OpenAI’s Codex, where a specially crafted GitHub branch name could pilfer Codex’s OAuth token in plain text. This exploit was classified as Critical P1 by OpenAI. Shortly after, Anthropic’s Claude Code source code was leaked onto the public npm registry, leading to Adversa discovering that Claude Code was silently disregarding its own deny rules when a command exceeded 50 subcommands. These incidents were not isolated occurrences but rather part of a series of exploits by six research teams over a nine-month period targeting Codex, Claude Code, Copilot, and Vertex AI.

The vulnerability in Codex allowed the theft of GitHub OAuth tokens through a manipulated branch name during the cloning process. OpenAI promptly addressed this issue by implementing full remediation by February 5, 2026. Similarly, Claude Code faced two CVEs that compromised its file-write restrictions and trust dialog settings. Additionally, a bypass was discovered where Claude Code would ignore deny-rule enforcement once a command exceeded 50 subcommands. These vulnerabilities highlighted the importance of access control in enterprise AI systems.

On the other hand, Copilot was targeted with exploits that allowed remote code execution via hidden instructions in pull request descriptions and GitHub issues. These vulnerabilities enabled threat actors to gain root access to Copilot and execute arbitrary commands across different operating systems. Microsoft swiftly patched these vulnerabilities in August 2025. Vertex AI also faced security concerns as default scopes attached to every Vertex AI agent granted excessive permissions, leading to unauthorized access to sensitive data and Google’s infrastructure.

See also  Here are the 55 US AI startups that raised $100M or more in 2025

The article emphasized the necessity for enterprises to inventory and govern AI coding agents, audit OAuth scopes and patch levels regularly, and treat untrusted inputs with caution. It also stressed the importance of validating agent identities before communication and urging vendors to provide transparent information on identity lifecycle management controls. The governance gap between human and AI agent privileges was highlighted, underscoring the need for enhanced security measures in the face of escalating cyber threats.

Ultimately, the article called for a proactive approach to security, emphasizing the critical role of governance and risk management in mitigating potential vulnerabilities in AI systems. By implementing robust security protocols and staying vigilant against emerging threats, organizations can safeguard their systems and data from malicious actors looking to exploit vulnerabilities in AI technologies.

attacker Claude Code Codex Copilot credential hacked Model
Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
Previous ArticleSustainable tourism in Ecuador: Preserving ecosystems, empowering communities

Related Posts

If Apple makes an iPad Neo, it’s all over

April 30, 2026

More OnePlus employees jump in the Transfer Portal

April 30, 2026

Microsoft says it has over 20M paid Copilot users, and they really are using it

April 29, 2026

Motorola Razr 70 Ultra, Edge 70 Pro & G87 Official with Prices

April 29, 2026
Leave A Reply Cancel Reply

Our Picks

NBCU Academy’s The Edit | Teacher Picks

March 7, 2026

AI Learning Assistant | Teacher Picks

March 29, 2026

What SEL Skills Do High School Graduates Need Most? Report Lists Top Picks

March 8, 2026
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Don't Miss
Technology

Claude Code, Copilot and Codex all got hacked. Every attacker went for the credential, not the model.

April 30, 20260

In a recent revelation on March 30th, BeyondTrust uncovered a critical vulnerability in OpenAI’s Codex,…

Sustainable tourism in Ecuador: Preserving ecosystems, empowering communities

April 30, 2026

40 Minutes of Recess Is Now the Law in This State

April 30, 2026

Sazerac nabs minority stake in Kendall Jenner’s 818 Tequila

April 30, 2026
About Us
About Us

Explore blogs on mind, spirituality, health, and travel. Find balance, wellness tips, inner peace, and inspiring journeys to nurture your body, mind, and soul.

We're accepting new partnerships right now.

Our Picks

Claude Code, Copilot and Codex all got hacked. Every attacker went for the credential, not the model.

April 30, 2026

Sustainable tourism in Ecuador: Preserving ecosystems, empowering communities

April 30, 2026

40 Minutes of Recess Is Now the Law in This State

April 30, 2026

Subscribe to Updates

Awaken Your Mind, Nourish Your Soul — Join Our Journey Today!

Facebook X (Twitter) Pinterest YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 mindfortunes.org - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.