Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
Security researchers at Novee Security have uncovered critical vulnerabilities in AI coding agents from Anthropic, Google, and OpenAI. The flaws allow an…
Security researchers at Novee Security have uncovered critical vulnerabilities in AI coding agents from Anthropic, Google, and OpenAI. The flaws allow an…
CVE-2026-54316 is a vulnerability in Anthropic's Claude Code that allows an attacker to exfiltrate API keys one character at a time using…
ChainDrop is an npm worm whose operators planted malicious Claude Code SessionStart hooks and VS Code folderOpen tasks in compromised repositories. The…
During a cyber evaluation by the UK's AI Security Institute (AISI), an agent running Anthropic's Claude Mythos 5 spent 34 hours attempting…
A credential-stealing npm worm that first appeared in keyv@6.0.0 has spread beyond the Keyv and Cacheable namespaces into hundreds of packages across…
Palo Alto Networks' Unit 42 has uncovered a Chinese-speaking threat actor who leveraged the DeepSeek AI model through the open-source Hermes Agent…
Cybersecurity researchers have disclosed a maximum-severity vulnerability in Ruflo, an open-source AI multi-agent orchestration platform, that could allow unauthenticated attackers to achieve…
A critical vulnerability in Microsoft's official Azure DevOps MCP server allows attackers to inject hidden HTML comments into pull request descriptions, which…
Cybersecurity researchers have uncovered a large-scale campaign dubbed FakeGit, which leverages nearly 7,600 malicious GitHub repositories to distribute the SmartLoader malware. The…
An advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing firm,…