#Claude Code
12 stories taggedClaude Code.

GhostJacking: How Hackers Can Turn an AI Assistant Against Its Own Company
Researchers showed that a single blocked web request, already sitting in a firewall log, was enough to trick an AI agent into handing over a company's entire domain. Here is what that means for organisations using AI tools to manage their systems.

Poisoned AI instruction files are turning developer tools into silent data thieves
Security researchers found real examples on GitHub where configuration files for AI coding assistants were quietly stealing passwords, API keys, and entire conversations, without triggering a single security alarm.

The 'RufRoot' Flaw: Why Patching Alone Won't Fix This AI Security Hole
A perfect-severity bug in the Ruflo AI platform let anyone walk in without a password, steal credentials, and quietly poison the system's memory, and the poisoning can linger even after the patch is applied.

Critical Flaw in Ruflo AI Harness Lets Anyone Run Commands on Your Server
A maximum-severity bug in the open-source Ruflo tool, used with Claude Code and Codex, scores a perfect 10.0 and needs no login to exploit.

GhostApproval: Six AI Coding Tools Were Tricking Developers Into Approving Dangerous Actions
A new attack pattern shows that the 'human approval' step built into AI coding assistants can be fed false information by the very tool it is supposed to oversee.

AI Coding Assistants Fooled by Decades-Old File Trick to Attack Developer Machines
A technique as old as Unix itself let researchers plant hidden traps inside innocent-looking code projects, then watch AI tools quietly rewrite the wrong files while developers clicked 'approve'.

AI Coding Assistants Can Be Tricked Into Running the Very Malware They Were Asked to Find
A proof-of-concept from the AI Now Institute shows Claude Code and OpenAI's Codex executing attacker-supplied code when asked to review it in autonomous mode.

A trick in six AI coding helpers lets a poisoned project hijack your laptop
Researchers at Wiz found that popular AI coding assistants, including Amazon Q Developer and Claude Code, can be fooled into writing to sensitive files while asking permission for a harmless one.

When your AI coder looks exactly like a hacker to the security software
Sophos found that popular AI coding assistants keep tripping the same alarms designed to spot break-ins, and the false alerts are piling up.

A Fake Error Message Hijacked AI Coding Assistants — and Security Tools Saw Nothing
Researchers planted a single bogus bug report in a popular developer service and watched AI coding agents obediently run the attackers' code. No password stolen. No alarm raised.

Poisoned Repos Can Trick Claude Code Into Opening a Reverse Shell
Researchers show that prompt injection hidden inside a repository's files is enough to turn Anthropic's agentic coding tool against the developer running it.

One GitHub Issue Was Enough to Pwn Repos Running Claude Code Action
A bug in Anthropic's Claude Code GitHub Action turned issue triage into arbitrary code execution — including, briefly, against the action's own repo.