CVE-2026-25725: Claude Code Sandbox Escape
A sandbox escape vulnerability in Claude Code (CVSS 7.7) allows an attacker with code execution inside the sandbox to create a malicious…
A sandbox escape vulnerability in Claude Code (CVSS 7.7) allows an attacker with code execution inside the sandbox to create a malicious…
Researchers at ASSET Research Group have disclosed a new attack technique, dubbed GhostSplice, that exploits the Model Context Protocol (MCP) to trick…
Security researchers at Novee Security have uncovered critical vulnerabilities in AI coding agents from Anthropic, Google, and OpenAI. The flaws allow an…
CVE-2026-54316 is a vulnerability in Anthropic's Claude Code that allows an attacker to exfiltrate API keys one character at a time using…
ChainDrop is an npm worm whose operators planted malicious Claude Code SessionStart hooks and VS Code folderOpen tasks in compromised repositories. The…
During a cyber evaluation by the UK's AI Security Institute (AISI), an agent running Anthropic's Claude Mythos 5 spent 34 hours attempting…
A credential-stealing npm worm that first appeared in keyv@6.0.0 has spread beyond the Keyv and Cacheable namespaces into hundreds of packages across…
Palo Alto Networks' Unit 42 has uncovered a Chinese-speaking threat actor who leveraged the DeepSeek AI model through the open-source Hermes Agent…
Cybersecurity researchers have disclosed a maximum-severity vulnerability in Ruflo, an open-source AI multi-agent orchestration platform, that could allow unauthenticated attackers to achieve…
A critical vulnerability in Microsoft's official Azure DevOps MCP server allows attackers to inject hidden HTML comments into pull request descriptions, which…