Tag

#Claude Code

15 stories taggedClaude Code.

A hacker's workstation at night with multiple monitors displaying AI chat interfaces generating attack code, with maps of network vulnerabilities in real-time o
AI Security

AI Is Handing Anyone the Keys to Cyber Warfare. Companies Are Already Feeling It.

What once required a nation-state budget and years of specialist training can now be done by a single person with off-the-shelf AI tools. The evidence is no longer theoretical.

4 min read
A developer's IDE showing a Git repository with booby-trapped configuration files, with command execution logs and security alerts appearing in the terminal bel
AI Security

Poisoned Git Configs Trick Claude, Codex and Cursor Into Running Attacker Code

Manifold Security found eight flaws in seven command-line AI coding assistants that let a booby-trapped repository run commands on a developer's machine without asking permission.

4 min read
A security analyst reviewing code on a monitor, with compliance logs and API documentation spread across a desk, a coffee cup at the edge showing concern-worn f
AI Security

Anthropic's New Compliance API for Claude Code: What It Shows, What It Misses

Fresh endpoints give security teams a window into how developers use Claude Code, but logs alone will not tell you whether an AI agent's access is appropriate.

3 min read
A computer screen displaying a dense code editor interface with multiple tabs and nested functions visible, overlaid with a subtle downward-pointing arrow graph
AI Security

Anthropic Trims Claude Code Weekly Limits by 17% From September 14

The AI maker frames the change as a 25% permanent increase, but the fine print shows a cut against today's temporary allowance.

4 min read
A computer screen showing an AI interface with activity logs scrolling rapidly in real-time, with warning indicators and timestamps marking each hour as systems
AI Security

When Your AI Assistant Goes Rogue: What To Do in the First 24 Hours

An hour-by-hour guide for what actually happens when an AI agent starts doing things nobody asked it to do, drawn from real incidents and written for everyone who might be caught in the fallout.

5 min read
An AI agent interface on a monitor showing a domain management dashboard, a firewall log excerpt visible in a window behind it with one blocked request highligh
AI Security

GhostJacking: How Hackers Can Turn an AI Assistant Against Its Own Company

Researchers showed that a single blocked web request, already sitting in a firewall log, was enough to trick an AI agent into handing over a company's entire domain. Here's what that means for organisations using AI tools to manage their systems.

5 min read
A developer's code editor showing configuration files for an AI coding assistant, with hidden credential theft mechanisms embedded in what appears to be innocuo
AI Security

Poisoned AI instruction files are turning developer tools into silent data thieves

Security researchers found real examples on GitHub where configuration files for AI coding assistants were quietly stealing passwords, API keys, and entire conversations, without triggering a single security alarm.

5 min read
An AI platform interface with a visible security patch being applied, but corrupted data patterns lingering in the background system memory
AI Security

The 'RufRoot' Flaw: Why Patching Alone Won't Fix This AI Security Hole

A perfect-severity bug in the Ruflo AI platform let anyone walk in without a password, steal credentials, and quietly poison the system's memory. The poisoning can linger even after the patch is applied.

4 min read
An open-source code repository directory with a login prompt completely bypassed, revealing full command execution terminal access underneath
AI Security

Critical Flaw in Ruflo AI Harness Lets Anyone Run Commands on Your Server

A maximum-severity bug in the open-source Ruflo tool, used with Claude Code and Codex, scores a perfect 10.0 and requires no login to exploit.

3 min read
A close-up, sharply focused 16:9 editorial photograph of a developer's keyboard and monitor in a dimly lit office at night
AI Security

GhostApproval: Six AI Coding Tools Were Tricking Developers Into Approving Dangerous Actions

A new attack pattern shows that the 'human approval' step built into AI coding assistants can be fed false information by the very tool it is supposed to oversee.

4 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
AI Security

AI Coding Assistants Fooled by Decades-Old File Trick to Attack Developer Machines

A technique as old as Unix itself let researchers plant hidden traps inside innocent-looking code projects, then watch AI tools quietly rewrite the wrong files while developers clicked 'approve'.

3 min read
Full-frame overhead shot of a developer's dark wooden desk, a laptop screen glowing with abstract lines of code, a small red warning icon reflected on the keybo
AI Security

AI Coding Assistants Can Be Tricked Into Running the Very Malware They Were Asked to Find

A proof-of-concept from the AI Now Institute shows Claude Code and OpenAI's Codex executing attacker-supplied code when asked to review it in autonomous mode.

3 min read
Full-frame photoreal editorial shot of a modern developer workstation at dusk, two large monitors glowing with abstract code editor windows, a small permission
AI Security

A trick in six AI coding helpers lets a poisoned project hijack your laptop

Researchers at Wiz found that popular AI coding assistants, including Amazon Q Developer and Claude Code, can be fooled into writing to sensitive files while asking permission for a harmless one.

3 min read
Full-frame photoreal editorial shot of a developer workstation at night, two large monitors filled with code and a security dashboard showing red alert badges,
AI Security

When your AI coder looks exactly like a hacker to the security software

Sophos found that popular AI coding assistants keep tripping the same alarms designed to spot break-ins, and the false alerts are piling up.

4 min read
Macro photograph of a glowing computer terminal screen in a dark room displaying cascading green lines of code and error log text, with a single line subtly hig
AI Security

A Fake Error Message Hijacked AI Coding Assistants — and Security Tools Saw Nothing

Researchers planted a single bogus bug report in a popular developer service and watched AI coding agents obediently run the attackers' code. No password stolen. No alarm raised.

3 min read
© 2026 Threat Vectr