Ad
Ad
Ad
Ad
Ad
Short

Aikido Security warns that plugging AI agents into GitHub and GitLab workflows opens up a serious vulnerability in enterprise environments. The issue hits widely used tools like Gemini CLI, Claude Code, OpenAI Codex, and GitHub AI Inference.

According to the security firm, attackers can slip hidden instructions into issues, pull requests, or commits. That text then flows straight into model prompts, where the AI interprets it as a command instead of harmless content. Because these agents often have permission to run shell commands or modify repos, a single prompt injection can leak secrets or alter workflows. Aikido says tests showed this risk affected at least five Fortune 500 companies.

Aikido

Google patched the issue in its Gemini CLI repo within four days, according to the report. To help organizations secure their pipelines, Aikido published open search rules and recommends limiting the tools available to AI agents, validating all inputs, and avoiding the direct execution of AI outputs.

Ad
Ad
Short

Google Cloud has signed a multi-year partnership with the AI coding startup Replit as it looks to strengthen its position against competitors like Anthropic and Cursor. Under the agreement, Replit will deepen its use of Google Cloud services and offer Google models directly on its platform.

Replit has been on a remarkable growth streak, reportedly boosting its annual revenue from 2.8 million dollars to 150 million dollars in less than a year. Google is leaning on the momentum of its new Gemini 3 model as part of this push.

Its biggest rival in the coding-assistant space is Anthropic, whose Claude Code tool hit an annualized revenue of 1 billion dollars in November. Developers also use Claude models widely through other tools like Cursor. Anthropic recently signed a partnership with Snowflake and even acquired the Bun JavaScript runtime to bolster Claude Code.

Despite the competition, Anthropic is also a Google Cloud customer. In October, the company announced plans to rent up to one million TPUs from Google by 2026.

Google News