
RuntimeAI Reports 16 AI Security Incidents Including Malicious Git Configs Hijacking Claude Code and 6 AI Agents
RuntimeAI's weekly report covers 16 AI-related security incidents including attacks against coding agents, AI infrastructure, MCP-style integrations and AI supply-chain components. Attackers are increasingly targeting the systems surrounding autonomous agents.
Executive Takeaway — TL;DR
- Category:
- AI Cyber Attacks
- Severity:
- High
- Actor Type:
- Unknown
- Geography:
- Global
- Confidence:
- High Confidence
- Source:
- RuntimeAI
- Read Time:
- 6 min
Executive Summary
RuntimeAI's weekly AI security incident report for September 4, 2026 covers 16 AI-related security incidents, with particular relevance to attacks against coding agents, AI infrastructure, MCP-style integrations, and AI supply-chain components.
The report highlights that attackers are increasingly targeting the systems surrounding autonomous agents rather than the agents themselves.
Key Incidents
Malicious Git Configs Hijack AI Agents
The headline incident involves malicious .git configuration files that hijacked Claude Code and six other AI coding agents, demonstrating how agent-adjacent infrastructure can be weaponized.
Attacks on AI Infrastructure
Multiple incidents targeted AI infrastructure components, including model hosting, API endpoints, and orchestration layers.
MCP-Style Integration Attacks
Attacks targeting MCP (Model Context Protocol) style integrations show that the connective tissue between agents and tools is a growing attack surface.
AI Supply Chain Targeting
AI supply-chain components, including dependencies and plugins used by autonomous agents, are increasingly targeted by attackers.
Implications
- The ecosystem surrounding AI agents is as important as the agents themselves.
- Coding agents, MCP integrations, and supply-chain components need security scrutiny.
- Weekly tracking of AI security incidents is essential for threat awareness.
Sources
- RuntimeAI, 4 Sep 2026
Defensive research only. No exploit code or attack instructions.
Sources
- 1.RuntimeAI - AI Security Incidents: Week of September 4, 2026Weekly AI security incident report covering 16 incidents
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Google GTIG Documents Evolution From Prompting to Autonomy in Adversarial AI Attack Workflows

Your Agents Can Be Hacked by Other Agents: The Rise of Machine-vs-Machine Cyberattacks

