CVE-2025-59536: Claude Code MCP Config Command Execution
A vulnerability in Claude Code allowed project-level MCP configuration to lead to command execution.
A vulnerability in Claude Code allowed project-level MCP configuration to lead to command execution.
Cybersecurity researchers at Tenet Security have identified a new class of attack called Agentjacking, which tricks AI coding agents into executing arbitrary…
Cybersecurity researchers at JFrog have uncovered a set of malicious npm packages that masquerade as legitimate PostCSS tools to deliver a Windows-based…
GPT-5.4 dropped to 0% compliance behind Claude Code, suggesting that Claude Code's safety controls may mitigate the GhostSplice attack.