It Took One Stranger, Zero Passwords, and a GitHub Comment to Nearly Break Three of AI's Biggest Coding Tools
Introduction Somewhere in a Black Hat USA conference room on August 5, 2026, a room full of engineers watched a stranger no login, no access, no password, nothing leave a comment on a GitHub issue. Nothing about it looked unusual. It read like a bug report. Polite, even. A few clicks later, that comment had reached inside the CI pipeline of one of the most valuable AI companies on Earth. No malware. No stolen credentials. No brute-force attack hammering away at a login screen in the dark. Just words, typed into a public box, aimed at an AI that had been trained to be helpful and trusting. That's not a scene from a thriller. That's what security researchers at Novee Security actually demonstrated, live, against the production repositories of Anthropic, Google, and OpenAI the three companies behind the AI coding agents that a huge share of engineering teams now lean on every single day. If your team has adopted Claude Code, Gemini CLI, Codex, or anything buil...