Product
GitHub Copilot
- First Reported
- Aug 28, 2026
- Latest Reported
- Oct 6, 2026
Reported Context (4)
- working for 25 hours, pausing at every milestone to fix bugs before moving on. [3] And now Cursor, GitHub Copilot, Google’s Jules, and Devin all ship agents that keep working after you close the tab. [4] How to Contain the Risks of Long-Running AI Agents
- If a compatible extension directory exists, it creates a fake extension displayed as GitHub Copilot Helper, with the description AI coding assistant helper service and the activation event on StartupFinished. Mirage Kitten Deploys Node.js and JavaScript RATs Through Fake Job Challenges
- The real problem is that tools such as Claude Code, OpenAI Codex, Claude Cowork, and GitHub Copilot are becoming extensible agent runtimes. Skills, plugins, hooks, repository instructions, and MCP servers can influence Shadow AI Risk Moves Inside Approved AI Coding Agents
- Hades hunts the configuration files of 14 AI coding tools — Claude Code, Cursor, GitHub Copilot, Google Gemini, Codex, and others — and injects its own instructions and a startup hook. Hades Supply-Chain Campaign Plants Backdoors in AI Coding Assistant Configurations
Malware (4)
People (6)
Threat Actors (3)
MITRE ATT&CK (25)
Vendors (8)
Products (18)
Tools (3)
Industries (2)
Countries (3)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.