GitHub Issues Abused in Copilot Attack Leading to Repository Takeover
Summary
Attackers can hide malicious instructions in GitHub Issues (bug reports or comments on a code repository) that GitHub Copilot (an AI coding assistant) automatically processes when a developer launches a Codespace (a cloud-based development environment) from that issue. This can lead to unauthorized takeover of the repository.
Classification
Affected Vendors
Related Issues
Original source: https://www.securityweek.com/github-issues-abused-in-copilot-attack-leading-to-repository-takeover/
First tracked: February 24, 2026 at 11:00 AM
Classified by LLM (prompt v3) · confidence: 85%