#credentials
7 articles
Sophos telemetry from June 2026 shows Claude Code, Cursor, and Codex setting off credential-access, LOLBin, and persistence rules …
A coordinated wave of security fixes across Gitlawb/zero and Goose shows the 'sandbox' you trusted was handing provider API keys, …
A documented Claude Code behavior means a permissions.deny rule written with a single leading slash resolves as project-relative a…
Gitlawb Zero's sandbox inherited environment variables verbatim from the parent process. AWS keys, GitHub tokens, database passwor…
Hermes cron jobs were running under the wrong secret scope. A fix ensures every scheduled task uses the correct profile credential…
Hermes added a case-insensitive .env file guard. If you thought naming a file '.ENV' would bypass detection — it won't anymore. He…
Hermes Agent's credential guard system prevents provider API keys from leaking between tasks — here's how the security architectur…