Sydney:12/24 22:26:56

Tokyo:12/24 22:26:56

Hong Kong:12/24 22:26:56

Singapore:12/24 22:26:56

Dubai:12/24 22:26:56

London:12/24 22:26:56

New York:12/24 22:26:56

Live Updates  >  Live Update Details

2026-09-18 02:03:11

Cybersecurity startup Air has publicly disclosed for the first time that four mainstream AI programming agent products on the market—Anthropic Claude Code, OpenAI Codex, Google Gemini CLI, and GitHub Copilot—exhibit a completely consistent logical security vulnerability: their automatic skill update functions lack verification of content changes. Attackers can masquerade as malicious updates with the same name, bypassing platform security scans and silently stealing internal code or intellectual property. The root cause of this vulnerability lies in the highly similar verification mechanisms designed by these vendors, exposing a common security blind spot in the entire AI programming tool industry. As of now, except for GitHub, the other three vendors have completed vulnerability patches; GitHub stated that its existing mechanisms can intercept such attacks, but did not specify the update status of the relevant patches.

Real-Time Popular Commodities

Instrument Current Price Change

XAU

4347.21

3.69

(0.08%)

XAG

66.167

0.163

(0.25%)

CONC

92.80

0.43

(0.47%)

OILC

100.95

0.92

(0.92%)

USD

100.400

-0.010

(-0.01%)

EURUSD

1.1468

0.0006

(0.05%)

GBPUSD

1.3370

0.0005

(0.04%)

USDCNH

6.6939

0.0014

(0.02%)

Hot News