<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Dorklist Blog</title>
    <link>https://dorklist.com/blog</link>
    <atom:link href="https://dorklist.com/blog/feed.xml" rel="self" type="application/rss+xml" />
    <description>Breach breakdowns, dork playbooks, and hunter spotlights from the Dorklist team.</description>
    <language>en-us</language>
    <lastBuildDate>Mon, 04 May 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>Comment and Control: One PR Title Made Three AI Coding Agents Leak Their Own Keys</title>
      <link>https://dorklist.com/blog/comment-and-control-ai-agents-leaked-secrets</link>
      <guid isPermaLink="true">https://dorklist.com/blog/comment-and-control-ai-agents-leaked-secrets</guid>
      <pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate>
      <description>A researcher typed a malicious instruction into a GitHub PR title. Claude Code, Gemini CLI, and Copilot Agent each read it, obeyed it, and posted their own API keys back as PR comments. No external infrastructure required — GitHub itself became the C2 channel.</description>
      <category>Breach Breakdowns</category>
    </item>
  </channel>
</rss>