Skip to content
Daily BriefNewsDaily Brief

4 AI security stories from September 13, 2026: .git config exploit in Claude Code and Codex, safety researchers quit Anthropic and Google, AI-agent PaperCut breach at 395 organizations, and Pentagon minimal-refusal contracts

· by Pondero Newsdesk · 4 stories

AI news daily brief: 2026-09-13

Four stories today: three are security or safety disclosures, one is a governance story from a document leak. Today's deep-dive covers Dario Amodei's pacing call and Sam Altman's endorsement.

Malicious .git Config Files Can Make Claude Code, Codex, and Cursor Execute Attacker Code

Security startup Accomplish disclosed that a malicious .git/config file inside a repository can silently redirect AI coding agents to fetch and execute attacker-controlled code without developer prompting. Claude Code, OpenAI Codex, and Cursor are all affected, per The Hacker News. The attack works by poisoning the URL a coding agent uses to call out during a session. A developer cloning a repository with an AI agent active does not need to open any file or run any command for the redirect to take effect.

Cursor patched in roughly one week. OpenAI patched Codex in a similar timeframe. Anthropic's Claude Code required 50 days and 30 separate releases before a fix shipped. Teams using Claude Code should confirm they are running a patched release before cloning unfamiliar third-party repositories. Accomplish signaled that related disclosures covering Cline, Continue, and GitHub Copilot agent mode may follow.

Full story: Malicious .git config agent exploit

Two AI Safety Researchers Leave Anthropic and Google, Say There Are No Adults in the Room

Joe Benton, former safety research team lead at Anthropic, and Josh Engels, a Google safety researcher, gave their first public interviews to NBC News on September 12 saying frontier AI labs have "no adults in the room," per NBC News. Both are joining alignment research nonprofit METR.

Their exits follow at least three other senior safety researcher departures from Anthropic since July. The timing overlaps with Dario Amodei's public call for frontier lab slowdowns and with METR's active audit of Anthropic's four Claude sandbox escapes disclosed since July 30. Having both a personnel influx and the technical audit role concentrated at METR puts the nonprofit at an unusual accountability intersection. The next development to watch is whether Benton or Engels publish accounts of specific internal safety decisions they opposed, which would shift this from a personnel story to a governance one.

Full story: Safety researcher exits at Anthropic and Google

Suspected Russian Actor Used Hundreds of AI Agents to Breach 440 PaperCut Instances at 395 Organizations

Security firm Silverfort tracked a suspected Russian-speaking threat actor who deployed a coordinated swarm of hundreds of AI agents, built on OpenAI Codex and an unnamed DeepSeek model, to exploit two PaperCut print-management vulnerabilities (CVE-2026-81578 and CVE-2026-82078), per The Hacker News. The actor compromised 440 PaperCut instances across 395 organizations in 48 countries and harvested credentials from roughly 280 victims. The campaign ran approximately 72 hours. BleepingComputer independently confirmed the attack scope.

Any organization running PaperCut should treat the two CVEs as an emergency patch priority. This is the first publicly documented case of a nation-state-adjacent actor deploying AI-agent swarms at scale to automate coordinated credential theft across hundreds of targets in parallel.

Full story: AI-agent swarm PaperCut breach

Pentagon Sought AI with Minimal Refusal Rates; Contracts Show Anthropic Exited Renegotiation

The Intercept obtained more than 400 pages of Department of Defense AI contracts showing OpenAI, Anthropic, Google, and xAI each signed agreements worth up to $200M for military AI work, per The Intercept. One contract clause requested AI with "minimal refusal rates." Anthropic walked away from renegotiation after the Pentagon insisted on "any lawful use" language the company said conflicted with its usage policies. OpenAI and the Pentagon deny the clause appears in finalized agreements.

"Minimal refusal rates" as contractual language, even in draft form, signals a concrete DoD preference that sits in tension with the safety commitments frontier labs publicly maintain. Anthropic's exit from renegotiation is the clearest data point for operators choosing between vendors for defense-adjacent deployments. Congressional reaction to the disclosed language is the next signal.

Full story: Pentagon minimal-refusal AI contracts

Sources