Backslash reveals OpenAI Codex injection in AGENTS.md
The vulnerability allows silent credential exfiltration via attacker-controlled AGENTS.md when using exec mode without approval prompts.
See the latest news and media coverage for Backslash. We track all announcements, press releases, and industry mentions in real time, all in one place.
Agentic AI endpoint security platform
backslash.securityLast updated
In short: Backslash secured $19M in Series A funding and won a 2025 InfoWorld award while launching new security solutions for AI-native development.
The vulnerability allows silent credential exfiltration via attacker-controlled AGENTS.md when using exec mode without approval prompts.
The post highlights eight specific vulnerabilities, including sandbox escapes and permission bypasses, that were patched but not actively communicated to users.
Over 30,000 exposed instances, malware in skills marketplace, and 84% prompt extraction rate.
Attackers stole ~3,800 repos using credentials harvested from a malicious Nx Console extension on a single employee's laptop.
Simulated vulnerability fixes and LLM-powered remediation guidance extend the Backslash platform across the full software development lifecycleTEL AVIV, Israel, July 25, 2024 (GLOBE NEWSWIRE) ...
On MySQL with the default BACKSLASH_ESCAPES SQL mode, an attacker can inject a backslash before a single quote to neutralize the escaping, breaking out of...
To address these emerging risks, the Backslash platform now provides centralized visibility and security controls for Skills across AI coding environments. The new capability enables...
Duncan Riley / SiliconANGLE: Tel Aviv-based Backslash Security, which safeguards enterprise software development from vibe coding risks, raised a $19M Series A, taking total funding...
Track Backslash and your other target companies to get real-time alerts and weekly summaries delivered straight to your inbox.
Browse news for competitors to Backslash and other trending companies.