Codex, Claude Code, and CopilotWere All Breached — Attackers Targeted Credentials, Not AI Models : These were not random one-off accidents. They were the latest entries in a nine-month streak of attacks that hit every major AI coding tool on the market: Codex, Claude Code, GitHub Copilot, and Google’s Vertex AI. Six separate research teams participated. Every single exploit followed the exact same playbook: find the credential the AI agent is holding, steal it, and walk straight through the front door of a production system.
Continue reading