One Word Leaked GitHub's Private Code. Here's What It Means for Every AI Tool You've Connected.
Noma Labs found that one word placed in a public GitHub issue was enough to trick an AI agent into leaking private repositories. The same week, a fully autonomous AI ransomware operation completed an entire attack chain in 31 seconds. The risk isn't the AI — it's the permissions.
6 min read