“Comment and Control” — New Prompt Injection Attack Hijacks Claude Code, Gemini CLI, and GitHub Copilot Agents
Summary Security researchers have disclosed a new prompt injection attack method called “Comment and Control” that can hijack AI coding agents through untrusted GitHub data — PR titles, issue comments,…
