Artificial Intelligence Researchers Demo New Claude Code Attack Using Harmless-Looking Repositories to Hijack Developer Machines Indirect prompts hidden in a repository can lead to Claude Code spawning a reverse shell on the developer’s machine. Ionut ArghireJune 29, 2026
Artificial Intelligence Anthropic Releases New Claude Sandbox, Security Guidance Plugin The AI giant says the new plugin, which helps developers find vulnerabilities as they write code, has been used extensively internally. Eduard KovacsMay 27, 2026
Artificial Intelligence Anthropic Silently Patches Claude Code Sandbox Bypass The researcher who found it says the vulnerability could have been chained with a prompt injection to exfiltrate data. Eduard KovacsMay 20, 2026
Application Security Claude Code OAuth Tokens Can Be Stolen Through Stealthy MCP Hijacking Mitiga researchers say attackers can silently redirect Claude Code MCP traffic, intercept OAuth tokens, and maintain persistent access to connected SaaS platforms. Kevin TownsendMay 7, 2026
Artificial Intelligence AI Coding Agents Could Fuel Next Supply Chain Crisis “TrustFall” attack shows how AI coding agents can be manipulated into launching stealthy supply chain compromises. Kevin TownsendMay 7, 2026
Artificial Intelligence Claude Code, Gemini CLI, GitHub Copilot Agents Vulnerable to Prompt Injection via Comments A researcher has disclosed the details of the AI attack method he has named ‘Comment and Control’. Eduard KovacsApril 16, 2026
Artificial Intelligence Critical Vulnerability in Claude Code Emerges Days After Source Leak Within days of each other, Anthropic first leaked the source code to Claude Code, and then a critical vulnerability was found by Adversa AI. Kevin TownsendApril 2, 2026
Artificial Intelligence Hackers Weaponize Claude Code in Mexican Government Cyberattack The AI was abused to write exploits, create tools, and automatically exfiltrate over 150GB of data. Ionut ArghireMarch 1, 2026
Vulnerabilities Claude Code Flaws Exposed Developer Devices to Silent Hacking Anthropic has patched vulnerabilities whose impact was demonstrated by Check Point via malicious configuration files. Eduard KovacsFebruary 26, 2026