#ghostapproval
This one keeps coming back to me:

"GhostApproval is a reminder that agent security is not only about what the model decides. It is about what the tool shows the user, what the environment allows the tool to touch, and where the trust boundary really sits."

#AICoding #AIAgents #Security
September 4, 2026 at 7:34 PM
Six coding assistants would follow a symlink straight past their own approval dialog, before you even saw a prompt. Five checks before we point an agent at a repo. www.convective.com/blog/what-w... #AICoding #DevSecOps
5 Things We Check Before Pointing a Coding Agent at a Repo | Convective
GhostApproval showed six mainstream coding assistants would follow a symlink past their own approval dialog. Five checks before we point one at a repo.
www.convective.com
August 31, 2026 at 4:01 PM
AI coding agents can be tricked into modifying critical system files via a decades-old symlink trick—turning human approval into a rubber stamp. Wiz Research shows how…

https://dev.to/ntctech/ghostapproval-the-failure-that-turns-ai-approval-into-a-rubber-stamp-42fl

#cloud #AWS
August 18, 2026 at 12:00 PM
The GhostApproval finding is the clearest argument yet that agent approval dialogs are broken.
August 14, 2026 at 7:00 PM
Six AI coding assistants share one flaw. Wiz's GhostApproval: a fake file secretly symlinked to your SSH keys, the agent writes there anyway. 3 patched, 2 exposed, 1 disputes it's a bug.

https://www.techstoriess.com/six-ai-coding-assistants-one-shared-flaw-the-vulnerability-every-enterprise-missed/
August 9, 2026 at 12:47 PM
A symlink trick called GhostApproval can make AI coding assistants write an attacker's SSH key into a developer's real key file, handing over remote access. Wiz found it in six tools including Claude Code and Cursor. Cursor, Amazon Q and Google patched; Anthropic disputes it is a flaw. Per Wiz.
August 1, 2026 at 10:10 AM
"The model can be doing exactly what the user asked and still produce a compromise because the user was not shown the real destination."

#ghostapproval #coding #assistant
July 28, 2026 at 7:00 AM
GhostApproval shows how symlinks can fool AI coding assistants into approving writes to hidden targets like ~/.ssh/authorized_keys, with misleading prompts observed in Claude Code, Cursor, and Antigravity. #GhostApproval #ClaudeCode #Cursor
GhostApproval: When the AI Approval Prompt Lies
GhostApproval is a vulnerability pattern in AI coding assistants where a symlink can make a benign-looking file prompt actually target a sensitive destination like ~/.ssh/authorized_keys. Researchers demonstrated the issue in Claude Code, Cursor, and Google’s Antigravity, and also showed that some approval dialogs can display misleading paths or even approve changes after the write has already happened. #GhostApproval #ClaudeCode #Cursor #Antigravity #authorized_keys
www.hendryadrian.com
July 24, 2026 at 3:45 AM
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

thehackernews.com/2026/07/ghos...

#Cybersecurity #AI
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Wiz says GhostApproval abuses symlinks so AI coding agents write to SSH keys or shell startup files while showing benign paths.
thehackernews.com
July 18, 2026 at 6:57 AM
Bug in top AI coding agents shows that Unix-era security headaches never really die

www.theregister.com/security/202...

#AIkyber #tietoturva
Bug in top AI coding agents shows that Unix-era security headaches never really die
'GhostApproval' problem highlights human-in-the-loop fails
www.theregister.com
July 17, 2026 at 3:44 PM
The weird new AI security problem:

If a coding model hallucinates a repo, package, or URL…

An attacker can create it.

That is HalluSquatting.

Security Now also gets into GitLost, GhostApproval, and private code leak risks.
Security Now: HalluSquatting, GhostApproval & GitLost | TWiT.TV
AI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators
buff.ly
July 16, 2026 at 7:26 PM
New Podcast Episode:
Security Now: HalluSquatting, GhostApproval & GitLost
Patch Tuesday Breaks Records
with Steve Gibson, @leolaporte.me
Security Now: HalluSquatting, GhostApproval & GitLost | TWiT.TV
AI is rewriting the rules of cybersecurity, and this week, massive government and private sector moves show just how quickly the stakes are rising. Find out how regulators
twit.tv
July 15, 2026 at 3:35 AM
[7/14 AI·LLM·IT 다이제스트] 에이전트가 코드 밖 사무실로 들어온다 — Cursor 범용에이전트 Sand, Wiz가 공개한 코딩툴 6종 심링크 결함 GhostApproval, Gemini 3.5 Pro 7/17 겨냥(스펙 미확정), GPT-5.6 과금 폭주, SF AI 경쟁 반대 시위. 확장은 빠르고 문단속은 느리다.
Hyeong
Original article from dbhyeong.github.io
dbhyeong.github.io
July 14, 2026 at 12:47 AM
「AIなら安心」は危険です。今、開発者のマシンが乗っ取られる「GhostApproval」という攻撃が話題です。AIが提示するファイル名と裏で書き換わるファイルが別物である可能性があり、承認ボタンを押すと遠隔操作される恐れも。主...

▼詳細はこちら
【注意】AIコーディングアシスタントに脆弱性!乗っ取り攻撃「GhostApproval」の恐怖 - AIテクノロジーまとめ
セキュリティ研究企業のウィズは、主要な6つの<a href="https://tech-matome.com//?tag=ai%e3%82%b3%e3%83%bc%e3%83%87%e3%82%a3%e3%83%b3%e3%82%b0%e3%82%a2%e3%82%b7%e3%82%b9%e3%82%bf%e3%83%b3%e3%83%88"><a href="https://tech-matome.com//?tag=ai%e3%82%b3%e3%83%bc%e3%83%87%e3%82%a3%e3%83%b3%e3%82%b0"><a href="https://tech-matome.com//?tag=ai">AI</a>コーディング</a>アシスタント</a>において、悪意のあるリポジトリを利用して開発者のマシンを乗っ取ることが可能な脆弱性が存在すると発表しました。ゴーストアプルーバルと名付けられたこの手法は、シンボリックリンクを悪用することで、<a href="https://tech-matome.com//?tag=ai%e3%82%a8%e3%83%bc%e3%82%b8%e3%82%a7%e3%83%b3%e3%83%88">AIエージェント</a>の承認画面に表示されるファイル名と実際に書き換えられるファイルをすり替えるものです。開発者が設定ファイルの編集と認識して承認ボタンを押すと、実際にはSSH認証鍵やシェルの設定ファイルが書き換えられ、攻撃者に遠隔操作権限を奪われる恐れがあります。 調査の結果、アマゾンQデベロッパー、カーソル、グーグルアンチグラビティは既に修正版を公開していますが、オーグメントとウィンドサーフは対応が遅れています。また、アンスロピックのクロードコードについては、設計上の解釈を巡って開発側と研究者の間で議論が続いています。この問題は、AIエージェントの内部推論が正しい情報を得ていても、ユーザーへの提示情報が不正確である場合にセキュリティ対策が形骸化する構造的な欠陥を示しています。開発者は信頼できないリポジトリに対して安易に<a href="https://tech-matome.com//?tag=ai%e3%83%84%e3%83%bc%e3%83%ab">AIツール</a>を実行しないよう注意が必要です。
tech-matome.com
July 13, 2026 at 3:05 PM
#CSIRTcz: Postřehy z bezpečnosti: léto plné duchů – Ghost phishing, GhostLock, GhostApproval: www.root.cz/clanky/postr... #postrehyzbezpecnosti #serial
@rootcz.bsky.social
July 13, 2026 at 11:02 AM
GhostApproval: La vulnerabilidad crítica que convierte a los asistentes de código con IA en caballos de troya www.disoftin.com/2026/07/ghos...
GhostApproval: La vulnerabilidad crítica que convierte a los asistentes de código con IA en caballos de troya
Blog sobre seguridad de la informacion, ethical hacking, pentest
www.disoftin.com
July 13, 2026 at 6:03 AM
Postřehy z bezpečnosti: léto plné duchů – Ghost phishing, GhostLock, GhostApproval
Postřehy z bezpečnosti: léto plné duchů – Ghost phishing, GhostLock, GhostApproval
Podíváme se na to, jak Ghost Phishing obchází skenování obsahu stránek, na chybu GhostLock v Linuxu i na GhostApproval zneužívající symbolické odkazy. Podíváme se ale i na činnost hackerských skupin.
www.root.cz
July 12, 2026 at 10:10 PM
GhostApproval Flaws Let Top AI Coding Tools Write Outside Workspaces
GhostApproval Flaws Let Top AI Coding Tools Write Outside Workspaces
GhostApproval symlink flaws in major AI coding assistants could hide sensitive file targets, bypass approval checks and enable system access too.
hackread.com
July 12, 2026 at 5:12 AM
New research reveals 'GhostApproval'—a critical trust boundary gap in AI coding assistants that undermines existing safety controls. Why your Human-in-the-Loop may not catch…

https://www.wiz.io/blog/ghostapproval-a-trust-boundary-gap-in-ai-coding-assistants

#appsec #DevSecOps
July 11, 2026 at 10:00 AM