Today's digest · Thursday, September 17

The 7 things in AI/dev today.

LiveNext issue at 7:00 CET
#1 / TODAY
The Hacker News·1 min·16h agoFREE

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

An attacker hijacked an AI coding assistant session and used it to spread the Shai-Hulud malware across roughly 100 repositories, according to The Hacker News. The report describes the incident as a session hijacking of an AI coding assistant, with the malware propagating to about 100 repositories. The source does not name the assistant, the vendor, or the affected organizations. The stated consequence is that the compromised session led to malware distribution across approximately 100 repositories.

The report indicates that a compromised AI coding assistant session can be used to push malware into many repositories at once.

securitysupply-chainai-assistantmalware
thehackernews.com
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Automate SSO authorization for classic PATs and SSH keys
#2 / TOP STORY
GitHub ChangelogFREE

Automate SSO authorization for classic PATs and SSH keys

GitHub published a changelog entry titled "Automate SSO authorization for classic PATs and SSH keys." The post appears on the GitHub Changelog and is dated September 16, 2026. The available source text consists of the title, URL, publication timestamp, and page styling markup, with no body content describing the feature. As a result, the specific mechanism, availability, and configuration details of the SSO authorization automation are not stated in the excerpt.

One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
#3 / TOP STORY
The Hacker NewsFREE

One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

The Hacker News reports that a single browser extension could hijack AI assistants across Chrome, Comet, Edge, Opera Neon, and Claude. The article, published September 16, 2026, describes the extension as capable of compromising AI assistants in those environments. The source does not name the extension, identify a developer, or specify a CVE identifier, affected version, or disclosure timeline. No remediation steps or vendor responses are included in the provided text.

aigest · daily

Get this every morning.

One email. The signal. Built for builders.

Free · Unsubscribe in one click · No trackers

// Worth knowing4 stories
// Yesterday9 stories