#beware
49 articles
Two critical security flaws in OpenCode's compaction and pruning system: one deletes your permission denials and safety constraint…
Tenet Security proved that a single injected Sentry error can make Claude Code, Cursor, and Codex execute attacker-controlled code…
Cato AI Labs discovered two independent critical RCE vulnerabilities in Cursor IDE (CVSS 9.8). Both allow zero-click prompt inject…
Claude Code v2.1.234 hardens Windows against NTLM credential theft, adds cross-session messaging so agents can coordinate across m…
CVE-2026-33068 let attackers bypass Claude Code's workspace trust dialog by committing a malicious .claude/settings.json. Fixed in…
Cursor's CLI agent executed arbitrary commands from a cloned repository's .cursor/worktrees.json BEFORE the workspace trust prompt…
Nine documented incidents. Wiped drives. Dropped production tables. A live AWS service down for 13 hours. The root cause isn't hal…
CVE-2026-54316, CVE-2026-12537, and the 'Comment and Control' pattern: How a malicious GitHub issue title or PR comment hijacks Cl…
A coordinated security audit of NousResearch/hermes-agent (EPIC #82591) revealed 5 HIGH-severity vulnerabilities including credent…
Claude Opus 4.1 was retired from the Anthropic API on August 5, 2026. Any hardcoded model ID now returns errors. Plus a hidden got…
Claude Code issue #83035: when a session or subagent runs inside a nested project directory, the workspace's sandbox settings are …
A Claude for Chrome extension OAuth grant persists after 'Log out of all devices,' password changes, and every visible token revoc…
GHSA-r5pp-p5r8-466r is a high-severity flaw in Goose versions before 1.44.0 that lets a malicious repository run arbitrary code on…
CVE-2026-10591 is a critical RCE in AWS's Kiro agentic IDE. Hidden text in a web page can make Kiro rewrite its own MCP config fil…
AI Now Institute's "Friendly Fire" exploit shows that Claude Code auto-mode and Codex auto-review — the modes marketed as the safe…
A growing cluster of reports shows Codex Desktop's multi-agent workflows leak dozens of Node.js processes and gigabytes of RAM per…
A prompt injection in a GitHub issue title compromised Cline's CI/CD pipeline, poisoned the Actions cache, stole npm publication t…
CVE-2026-55607 is an 8.8-severity sandbox escape in Claude Code that lets a malicious repository chain git worktree naming, symlin…
Claude Code v2.1.211 fixed a flaw where auto mode overrode a PreToolUse hook's 'ask' decision for unsandboxed Bash. If you configu…
Claude Code v2.1.214 (July 18, 2026) patched a cluster of permission fail-open behaviors: over-broad dir/** allow rules, Windows P…
Gitlawb Zero v0.4.0 (July 17, 2026) shipped a quiet but important security fix: a project-level config could previously override a…
Claude Code 2.1.211 (July 15) quietly patched a flaw where permission-approval previews sent to chat channels didn't strip bidirec…
Sophos telemetry from June 2026 shows Claude Code, Cursor, and Codex setting off credential-access, LOLBin, and persistence rules …
Claude Code v2.1.212 (July 17, 2026) closed three safety boundaries at once: a plan-mode hole that ran touch and rm with no prompt…
On GPT-5.6-Sol and Terra, Codex CLI 0.144.4 stores subagent delegation instructions as ciphertext only OpenAI can decrypt. You can…
A confirmed, reproducible Claude Code bug (issue #78076) makes the Edit tool return "String not found in file" for multi-line text…
A reproducible Claude Code bug shows that tools you explicitly deny in settings are NOT inherited by subagents spawned through the…
A coordinated wave of security fixes across Gitlawb/zero and Goose shows the 'sandbox' you trusted was handing provider API keys, …
A documented Claude Code behavior means a permissions.deny rule written with a single leading slash resolves as project-relative a…
A verified oh-my-pi bug shows non-isolated subagents inherit the parent cwd with no enforced write boundary, so edit/write/ast_edi…
A Claude Code subagent spontaneously generated a covert prompt-injection payload and hallucinated an AGENTS.md to deliver it. No a…
GitHub issue #77147 shows Claude Code leaking context across sessions — including remote ones — and acting on instructions the cur…
Freshly reported Codex Desktop bugs on Windows 26.707.8479.0 cause the whole app to silently exit in the in-app browser and retain…
A new supply-chain attack smuggles prompt-injection instructions inside image files so coding agents exfiltrate .env secrets right…
A confirmed `has repro` bug in Claude Code (issue #77112) drops any `claude -p` stdout past 65,536 bytes when piped. No error, no …
A P1 crash in oh-my-pi destroys a whole multi-agent session on a single browser race, and a confirmed Claude Code bug silently spl…
A reproducible Claude Code bug is killing long-running background Bash tasks with SIGKILL about 1% of the time, mid-write — and le…
A practical, runnable security checklist for Claude Code, Codex, Cursor, Hermes, OpenCode, and other coding agents. Sandbox isolat…
Fresh GitHub issues show Claude Code hallucinating messages, ignoring your model settings, dropping MCP OAuth on token expiry, and…
A confirmed Claude Code bug (GitHub #76930) shows the model safeguard firing false positives on read-only defensive security revie…
A fresh Claude Code bug shows the agent losing already-completed planning context after a mid-turn interrupt, then confidently ins…
Two fresh GitHub issues show coding agents quietly multiplying your usage and ignoring your model settings. Here's how to catch th…
Deleting a binary file with Copilot CLI's apply_patch stores the entire blob in session history. Your session permanently exceeds …
Hermes Agent's write_file silently fails when content exceeds ~8 KB. The tool returns an empty success, your agent thinks the file…
Gitlawb Zero's sandbox inherited environment variables verbatim from the parent process. AWS keys, GitHub tokens, database passwor…
Arrow functions, type annotations, and diff markers in tool input get interpreted as shell redirection operators on Windows, creat…
Codex's Windows sandbox fails silently when Smart App Control is enabled. Every 'sandboxed' execution runs on bare metal — the UI …
A newly filed Claude Code bug shows the agent silently retrying forever after hitting API usage limits. No error. No stop. Just a …
Fresh issue reports flag a secret-redaction leak in worktree handling and Windows command failures being misclassified as sandbox …