
AMA Today: Novee Security researchers who presented at Black Hat 2026 (Java RCE & GitHub Al Agent Hijacking)
“We're Lidor B./thisis0xczar and Elad Meged, founding-team vulnerability researchers at Novee Security.
At Black Hat this year we presented pre-auth remote code execution chains in enterprise Java platforms, reaching internal execution surfaces through routing logic, unsafe deserialization, and template evaluation.
We also published research showing how a single untrusted GitHub issue could compromise the AI coding agents from Anthropic, Google, and OpenAI (Claude Code, Gemini CLI, and Codex), leading to remote code execution and credential theft.
Some of our research:
https://novee.security/blog/pre-auth-rce-in-enterprise-java/
https://novee.security/blog/critical-flaws-in-anthropic-google-and-openais-coding-agents/
Ask us anything about:
For both of us:
- Using offensive AI to find real vulnerabilities
- What it's like presenting at Black Hat Where AI and offensive security are heading
- Getting into vulnerability research and how we work
- Anything else on finding and exploiting bugs
For Lidor (enterprise Java RCE):
- Pre-auth remote code execution and how these chains come together
- Deserialization, routing logic, and template evaluation attacks
- Finding RCE in widely deployed enterprise platforms
- Enterprise and application security
For Elad (AI coding agents):
- Hijacking AI coding agents through a single GitHub issue
- Turning Claude Code, Gemini CLI, and Codex into attack vectors
- What breaks when AI agents get high-privilege access to real systems
- Hacking AI agents
We'll be here live on Monday, Aug 17 from 12 PM to 1 PM PT answering your questions in real time. “