Comment and Control: The GitHub AI Agent Attack That Three Vendors Hushed
On April 15, 2026, The Register reported that security researcher Aonan Guan had successfully hijacked AI agents from three separate companies — Anthropic, Google, and GitHub — using the same class of attack against each, paid quiet bug bounties from all three, and received no CVE assignments, no public advisories, and no disclosure of any kind to users running older versions of the affected tools. The attack is called "comment and control." The name is a deliberate play on "command and control...
Original Source
Read the full article at Dev →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.