# Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code

> Security researchers have detailed a new class of attack they call Agentjacking, which targets the AI coding agents developers increasingly let run semi-autonomously. The trick exploits how these agents handle errors: by planting crafted content in the error-tracking flow, an attacker can steer the agent into executing malicious code. In testing, the technique succeeded about 85 percent of the time, a strikingly high rate for a fresh attack class. The finding lands on a growing sore spot. AI agents are being handed real permissions, to read code, run commands, and touch production systems, precisely because their usefulness comes from acting on their own. That autonomy is also the vulnerability. An agent that faithfully follows instructions it encounters can be manipulated by whoever controls those instructions. The broader lesson is that agent security is not the same as model safety. Even a well-behaved model becomes dangerous when wired into tools with the ability to act. As companies rush agents into production, work like this is a warning that the attack surface is new, poorly understood, and, judging by that success rate, wide open.

_Section: [Daily AI Updates](https://www.wortins.com/daily-ai) · Source: The Hacker News · Published Friday, July 10, 2026_

## Wortins' read

Security researchers have detailed a new class of attack they call Agentjacking, which targets the AI coding agents developers increasingly let run semi-autonomously. The trick exploits how these agents handle errors: by planting crafted content in the error-tracking flow, an attacker can steer the agent into executing malicious code. In testing, the technique succeeded about 85 percent of the time, a strikingly high rate for a fresh attack class. The finding lands on a growing sore spot. AI agents are being handed real permissions, to read code, run commands, and touch production systems, precisely because their usefulness comes from acting on their own. That autonomy is also the vulnerability. An agent that faithfully follows instructions it encounters can be manipulated by whoever controls those instructions. The broader lesson is that agent security is not the same as model safety. Even a well-behaved model becomes dangerous when wired into tools with the ability to act. As companies rush agents into production, work like this is a warning that the attack surface is new, poorly understood, and, judging by that success rate, wide open.

## Source

[Read the full story at The Hacker News](https://thehackernews.com/2026/06/agentjacking-attack-tricks-ai-coding.html)

## Related coverage

- [Critical CoSnitch Vulnerability in Microsoft Copilot Enables Silent Data Theft](https://www.wortins.com/story/critical-cosnitch-vulnerability-in-microsoft-copilot-enables-8d78b855) — [Varonis](https://www.varonis.com/blog/cosnitch)
- [Anthropic Launches Global Watermarking for Claude-Generated Text to Comply with EU AI Act](https://www.wortins.com/story/anthropic-launches-global-watermarking-for-claude-generated--9522e158) — [Anthropic](https://www.anthropic.com/news/claude-text-watermark)
- [Wiz Introduces Sensor for Developer Workstations To Prevent Supply Chain AI Attacks](https://www.wortins.com/story/wiz-introduces-sensor-for-developer-workstations-to-prevent--13d47964) — [Wiz Blog](https://www.wiz.io/blog/introducing-the-wiz-sensor-for-developer-workstations)
- [Figma Config 2026: Motion, Shaders, Code Layers Bring AI Into Design Workflows](https://www.wortins.com/story/figma-config-2026-motion-shaders-code-layers-bring-ai-into-d-add5bbac) — [Figma](https://help.figma.com/hc/en-us/articles/39582753756695-What-s-new-from-Config-2026)
- [Ours Privacy Raises $15M Series A for Healthcare AI Data Platform](https://www.wortins.com/story/ours-privacy-raises-15m-series-a-for-healthcare-ai-data-plat-4ae00549) — [Crunchbase News](https://news.crunchbase.com/venture/biggest-funding-rounds-ai-defense-fintech-robotics/)
- [Rippling Launches AI Spend Console to Measure Employee Token ROI and Curtail Runaway Costs](https://www.wortins.com/story/rippling-launches-ai-spend-console-to-measure-employee-token-f2cda775) — [TechCrunch](https://techcrunch.com/2026/08/07/after-rippling-blew-millions-on-ai-in-months-it-built-an-employee-roi-tool/)

---

_Curated and written by [Wortins](https://www.wortins.com) — The daily AI briefing. Every story links to its original source; the "Wortins read" on each is our own original analysis. [About Wortins & our editorial approach](https://www.wortins.com/about)._
