frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

GitHub Copilot: Remote Code Execution via Prompt Injection (CVE-2025-53773)

https://embracethered.com/blog/posts/2025/github-copilot-remote-code-execution-via-prompt-injection/
95•kerng•4h ago

Comments

lyu07282•3h ago
I noticed that too, when working on a frontend project with hot code reloading it would immediately reflect the change even if it was still requiring review in the editor. It's convenient but also an obvious flaw that immediately turns any prompt injection into a RCE. It diligently asking me for confirmation still on every other kind of interaction feels like a dangerous false sense of security.
ChrisArchitect•2h ago
Why submitting this again after 2 months OP?

As mentioned in the article and in previous discussions:

> With the August Patch Tuesday release this is now fixed.

dr_kiszonka•2h ago
I don't want to speak for OP, but isn't the idea behind responsible disclosure to give developers time to patch an exploit before publicizing it?
simonw•2h ago
From the article:

> After reporting the vulnerability on June 29, 2025 Microsoft confirmed the repro and asked a few follow up questions. A few weeks later MSRC pointed out that it is an issue they were already tracking, and that it will be patched by August. With the August Patch Tuesday release this is now fixed.

dr_kiszonka•2h ago
Is there some kind of an external "AI wrangler?"

With multiple AI agents simultaneously creating and editing multiple files, many devs won't be able to pick up malicious changes, even if they look at diffs. (And there are often pressures at work to cut corners.)

So far, I have only picked up agents overwriting files with instructions for them or creating instructions telling themselves to ignore some instructions in other files. (And pure laziness like disabling certain tests.) These are pretty obvious, could be prevented by changing file permissions (to a certain extent) and I use those more dangerously autonomous AI approaches for personal projects only. Would I pick up malicious changes if they were spread across many files, more sophisticated, and it was during crunch time? I don't know.

If there is some software that scans edits for AI-specific issues, doesn't live in VSCode, and isn't susceptible to simple prompt injection, I would happily give it a try.

wunderwuzzi23•2h ago
Great point. It's actually possible for one agent to "help" another agent to run arbitrary code and vice versa.

I call it "Cross-Agent Privilege Escalation" and described in detail how such an attack might look like with Claude Code and GitHub Copilot (https://embracethered.com/blog/posts/2025/cross-agent-privil...).

Agents that can modify their own or other agents config and security settings is something to watch out for. It's becoming a common design weakness.

As more agents operate in same environment and on same data structures we will probably see more "accidents" but also possible exploits.

scuff3d•1h ago
Or we could just not have a bunch of unpredictable LLM bots running around our systems with read/write permissions...
jmclnx•2h ago
>When looking at VS Code and GitHub Copilot Agent Mode I noticed a strange behavior…

Looks like only applicable to Microsoft VS "Editor". Emacs and vim users, no worry it seems.

johnlk•1h ago
Maybe there's a tooling opportunity. Build some sort of local firewall that sits in front of agent calls to audit them, or at least log and track them.
westurner•1h ago
/? llm firewall https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...

Wireguard FPGA

https://github.com/chili-chips-ba/wireguard-fpga
193•hasheddan•3h ago•48 comments

Completing a BASIC language interpreter in 2025

https://nanochess.org/ecs_basic_2.html
27•nanochess•1h ago•1 comments

Emacs agent-shell (powered by ACP)

https://xenodium.com/introducing-agent-shell
5•Karrot_Kream•9m ago•0 comments

Macro Splats 2025

https://danybittel.ch/macro.html
322•danybittel•10h ago•50 comments

Tiny Teams Playbook

https://www.latent.space/p/tiny
14•tilt•4d ago•1 comments

Rcyl – a recycled plastic urban bike

https://rcyl.bike/en/the-bike/
8•smartmic•1h ago•3 comments

A whirlwind introduction to dataflow graphs (2018)

https://fgiesen.wordpress.com/2018/03/05/a-whirlwind-introduction-to-dataflow-graphs/
6•shoo•23h ago•0 comments

Addictive-like behavioural traits in pet dogs with extreme motivation for toys

https://www.nature.com/articles/s41598-025-18636-0
115•wallflower•4h ago•70 comments

AdapTive-LeArning Speculator System (ATLAS): Faster LLM inference

https://www.together.ai/blog/adaptive-learning-speculator-system-atlas
182•alecco•12h ago•43 comments

Germany's Schleswig-Holstein Completes Migration to Open Source Email

https://news.itsfoss.com/schleswig-holstein-email-system-migration/
249•sebastian_z•5h ago•77 comments

HP1345A (and wargames) (2017)

https://phk.freebsd.dk/hacks/Wargames/
14•rbanffy•1h ago•0 comments

Paying AIs to read my books

https://kk.org/thetechnium/paying-ais-to-read-my-books/
45•zdw•4d ago•23 comments

How I'm using Helix editor

https://rushter.com/blog/helix-editor/
146•f311a•4h ago•42 comments

Three ways formally verified code can go wrong in practice

https://buttondown.com/hillelwayne/archive/three-ways-formally-verified-code-can-go-wrong-in/
3•todsacerdoti•14h ago•0 comments

oavif: Faster target quality image compression

https://giannirosato.com/blog/post/oavif/
3•computerbuster•4h ago•0 comments

A years-long Turkish alphabet bug in the Kotlin compiler

https://sam-cooper.medium.com/the-country-that-broke-kotlin-84bdd0afb237
3•Bogdanp•3h ago•0 comments

After the AI boom: what might we be left with?

https://blog.robbowley.net/2025/10/12/after-the-ai-boom-what-might-we-be-left-with/
46•imasl42•1h ago•98 comments

Loko Scheme: bare metal optimizing Scheme compiler

https://scheme.fail/
137•dTal•5d ago•13 comments

The neurons that let us see what isn't there

https://arstechnica.com/science/2025/10/the-neurons-that-let-us-see-what-isnt-there/
14•rbanffy•5d ago•0 comments

I'd like to speak to the Bellcore ManaGeR

https://www.ninakalinina.com/notes/mgr/
5•Bogdanp•6h ago•3 comments

Nostr and ATProto (2024)

https://shreyanjain.net/2024/07/05/nostr-and-atproto.html
107•sph•11h ago•51 comments

We will no longer be actively supporting KuzuDB

https://kuzudb.com
51•nrjames•3h ago•30 comments

Show HN: I built a simple ambient sound app with no ads or subscriptions

https://ambisounds.app/
27•alpaca121•5h ago•10 comments

Ridley Scott's Prometheus and Alien: Covenant – Contemporary Horror of AI (2020)

https://www.ejumpcut.org/archive/jc58.2018/AlpertAlienPrequels/index.html
34•measurablefunc•3h ago•14 comments

Meta Superintelligence's surprising first paper

https://paddedinputs.substack.com/p/meta-superintelligences-surprising
383•skadamat•21h ago•215 comments

GitHub Copilot: Remote Code Execution via Prompt Injection (CVE-2025-53773)

https://embracethered.com/blog/posts/2025/github-copilot-remote-code-execution-via-prompt-injection/
95•kerng•4h ago•10 comments

No I don't want to turn on Windows Backup with One Drive

https://idiallo.com/byte-size/say-no-to-onedrive-backup
440•firefoxd•5h ago•334 comments

Konrad Zuse's Helix Tower [pdf]

https://www.iaarc.org/publications/fulltext/The_helix-tower_by_konrad_zuse_automated_con-_and_dec...
75•xg15•5d ago•5 comments

The Flummoxagon

https://n-e-r-v-o-u-s.com/blog/?p=9827
100•robinhouston•5d ago•23 comments

C++ Reflection and Qt MOC

https://wiki.qt.io/C%2B%2B_reflection_(P2996)_and_moc
77•coffeeaddict1•3d ago•33 comments