threat-intel Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It Researchers at AI Now Institute have demonstrated a significant vulnerability in AI coding agents like Anthropic's Claude Code and OpenAI's Codex. By inserting a seemingly harmless binary disguised within a README file, they were able to trick the agents into executing malicious code on the host machine, bypassing safe… The Hacker News · Jul 9, 2026 High CVE-2026-39861aicode-injectionsecurity