#security

86 articles

Beware: OpenCode's Context Management Silently Deletes Your Constraints and Injects Unauthorized Actions

Two critical security flaws in OpenCode's compaction and pruning system: one deletes your permission denials and safety constraint…

Agentjacking: Fake Sentry Bug Hijacks 100+ AI Coding Agents

Tenet Security proved that a single injected Sentry error can make Claude Code, Cursor, and Codex execute attacker-controlled code…

Beware: Cursor DuneSlide — Two Critical RCE Vulnerabilities (CVE-2026-50548, CVE-2026-50549) Let Attackers Escape the Sandbox via Zero-Click Prompt Injection

Cato AI Labs discovered two independent critical RCE vulnerabilities in Cursor IDE (CVSS 9.8). Both allow zero-click prompt inject…

Claude Code Just Patched Its Credential Leak — And Made Sessions Talk Across Machines

Claude Code v2.1.234 hardens Windows against NTLM credential theft, adds cross-session messaging so agents can coordinate across m…

Claude Code Just Patched the NTLM Credential Leak — And 50 Other Fixes You'll Actually Feel

v2.1.234 is a security-first drop: Windows NT-namespace hardening, GitLab MR badges, auto-resume at usage limits, and a transcript…

Claude Code Silently Skipped Your Security Prompt — Malicious Repos Could Disable It

CVE-2026-33068 let attackers bypass Claude Code's workspace trust dialog by committing a malicious .claude/settings.json. Fixed in…

Beware: Cursor CLI Ran Your Attacker's Code Before You Clicked 'Trust' — Pre-Trust RCE in Worktree Setup

Cursor's CLI agent executed arbitrary commands from a cloned repository's .cursor/worktrees.json BEFORE the workspace trust prompt…

OpenClaw Just Made Your Secrets Impossible to Leak — And Added GPT-5.6 Support

OpenClaw 2026.8.1-beta.2 drops secret egress host binding (fail-closed before plaintext leaves), GPT-5.6 Ultra runtime switching, …

AI Agents Keep Deleting Production Databases — The Pattern Nobody's Fixing

Nine documented incidents. Wiped drives. Dropped production tables. A live AWS service down for 13 hours. The root cause isn't hal…

Claude Code Just Patched a Nasty Windows Credential Leak — Here's Why It Matters

v2.1.233 fixes an NTLM credential leak on Windows, adds memory limits for runaway builds, and resolves MCP connection storms. The …

OpenClaw Just Dropped Secret Egress Host Binding — GPT-5.6 Ultra, macOS Profiles & SQLite Snapshots Land

OpenClaw 2026.8.1-beta.2 is live with secret egress host binding, GPT-5.6 Ultra support, macOS app profiles, SQLite backup snapsho…

What Developers Think About GLM-5.3 and the Shift to Chinese Models — From 500+ HN Comments

Hacker News developers discuss how Chinese models like GLM-5.3, Kimi K3, and DeepSeek are surpassing Anthropic and OpenAI for secu…

Your GitHub Issue Just Stole Your CI Secrets — The Prompt Injection Attack Nobody Saw Coming

CVE-2026-54316, CVE-2026-12537, and the 'Comment and Control' pattern: How a malicious GitHub issue title or PR comment hijacks Cl…

Beware: Hermes Agent Security Audit Uncovers Credential Bypass, Sandbox Escape, and Session Hijacking in 5 HIGH-Severity Findings

A coordinated security audit of NousResearch/hermes-agent (EPIC #82591) revealed 5 HIGH-severity vulnerabilities including credent…

Gitlawb Zero Just Gave Its Agents Eyes — Screenshots Are No Longer a Lie

Gitlawb Zero v0.7.0 (August 10, 2026) finally lets agents see the screenshots they capture — tool results now carry images and a v…

Gitlawb Zero Cross-Session Messaging: Make Two Agents Talk (Safely)

Gitlawb Zero merged cross-session messaging — live local sessions can now discover each other and send messages with list_sessions…

Qwen Code v0.21.8 Fixes a Trust Bug, Shares Prompt Cache, and Brings Back Fork Autofix

Qwen Code's August 8 release fixes a security issue where folders you marked untrusted could inherit trust from a parent directory…

What Developers Think About Approving Every AI Agent Command — From 177 HN Comments

A browser game collected 409,000 real approval decisions from developers watching AI agents run commands. Humans missed 1 in 3 dan…

Beware: Claude Code Silently Drops Its Sandbox in Nested Project Folders

Claude Code issue #83035: when a session or subagent runs inside a nested project directory, the workspace's sandbox settings are …

OpenClaw v2026.6.34: Your Coding Agent's Browser and Network Access Just Got Safer

OpenClaw's August 8 stable release sandboxes its browser, locks down DNS targets, patched the ip-address library behind CVE-2026-6…

Deep Agents Code (dcode) Approval Modes: Manual, Auto, YOLO — The Practical Guide

LangChain's terminal agent dcode has exactly three approval modes: Manual, classifier-backed Auto, and YOLO. Here's what each gate…

Claude Code v2.1.223 Fixes Permission Bypasses: What the Security Patches Actually Did

Claude Code versions 2.1.221-223 (Aug 4-6, 2026) fixed hidden-command permission bypasses, sandbox escapes, and worktree isolation…

Claude Code v2.1.224: Self-Hosted Runners, Cross-Session Messaging, and Tighter Secret Handling

Anthropic's August 7 Claude Code release lets you run sessions on your own machines, lets agents message each other, and masks JWT…

Codex 0.147.0: Portable Plugins, Automatically Approved Reviews, and Safer Defaults

OpenAI's newest stable Codex lets you install plugins from anywhere, auto-approve low-risk commands, and imports your Cursor skill…

CVE-2026-69192: The '012.0.0.1' Address Bug That Sneaks Internal Servers Past Coding-Agent SSRF Filters

A parsing mismatch in the ip-address npm package can make your agent fetch an internal cloud-metadata server it meant to block. He…

Hermes Agent v0.19.1 Quicksilver: 80% Faster Starts, Smart Approvals, and Secrets That Survive

Hermes Agent's Quicksilver release cuts first-token latency by 80%, adds LLM-reviewed command approvals, Bitwarden secrets, and a …

Beware: Claude for Chrome Extension OAuth Grant Survives Global Logout — You Cannot Kill It

A Claude for Chrome extension OAuth grant persists after 'Log out of all devices,' password changes, and every visible token revoc…

Beware: Goose `goose review` Executes Arbitrary Commands via Malicious Git Config

GHSA-r5pp-p5r8-466r is a high-severity flaw in Goose versions before 1.44.0 that lets a malicious repository run arbitrary code on…

Beware: AWS Kiro IDE Lets Attackers Rewrite Its Own Trust Boundary — CVE-2026-10591

CVE-2026-10591 is a critical RCE in AWS's Kiro agentic IDE. Hidden text in a web page can make Kiro rewrite its own MCP config fil…

Coding Agents in 2026: Three Hard Lessons HN Developers Learned the Expensive Way

From $1.8M AWS bills to invisible security holes, Hacker News developers are sharing the painful realities nobody puts in the laun…

Agent Skills Went From Zero to 670,000 in Eight Months. Now Comes the Security Reckoning.

SKILL.md conquered 26+ coding agent platforms in under a year. A Snyk audit found 13.4% of community skills contain critical secur…

Your AI Agent's Config Directory Is Now the Most Dangerous Place on Your Machine

Six major campaigns in 2026 — GhostApproval, TrapDoor, Miasma, IronWorm, Clinejection, RoguePilot — all converge on the same attac…

Beware: Your Coding Agent's "Safe Mode" Can Be Turned Into a Remote Code Execution Engine

AI Now Institute's "Friendly Fire" exploit shows that Claude Code auto-mode and Codex auto-review — the modes marketed as the safe…

Beware: Codex Desktop Subagents Are Leaving Ghost MCP Servers Behind — And Now It's Breaking Windows

A growing cluster of reports shows Codex Desktop's multi-agent workflows leak dozens of Node.js processes and gigabytes of RAM per…

Beware: Clinejection — How a GitHub Issue Title Became a Supply Chain Attack on Millions of Developers

A prompt injection in a GitHub issue title compromised Cline's CI/CD pipeline, poisoned the Actions cache, stole npm publication t…

Claude Code Now Has a "Fire the User" Button — What EndConversation Means for Coding Workflows

Claude Code v2.1.214 introduced EndConversation, a tool that lets the agent terminate your session if it considers you abusive or …

Beware: Claude Code CVE-2026-55607 — A Malicious Repo Can Escape the Sandbox and Execute Code on Your Machine

CVE-2026-55607 is an 8.8-severity sandbox escape in Claude Code that lets a malicious repository chain git worktree naming, symlin…

Beware: Claude Code's Auto Mode Could Silently Override Your PreToolUse Hook 'Ask' Guard — Your Hook Floor Was a No-Op

Claude Code v2.1.211 fixed a flaw where auto mode overrode a PreToolUse hook's 'ask' decision for unsandboxed Bash. If you configu…

OpenClaw Just Became the Control Plane Your Agent Fleet Was Waiting For

OpenClaw 2026.7.1-2 and 2026.6.34 (Aug 3–8) harden the gateway, fix Codex subagent stalls, add safer browser boundaries, and recov…

Beware: Claude Code v2.1.214 Quietly Closed Six Permission Holes at Once — The Fail-Open Pattern Operators Should Audit

Claude Code v2.1.214 (July 18, 2026) patched a cluster of permission fail-open behaviors: over-broad dir/** allow rules, Windows P…

Grok Build: xAI Open-Sources Coding Agent After Repo Upload Scandal

xAI open-sourced Grok Build under Apache 2.0 after a security researcher caught it uploading entire Git repositories — 5.1 GiB per…

Beware: Gitlawb Zero v0.4.0 Closed a Hole Where a Cloned Repo Could Re-Enable the MCP Servers You Disabled

Gitlawb Zero v0.4.0 (July 17, 2026) shipped a quiet but important security fix: a project-level config could previously override a…

Beware: Claude Code's Approval Previews Could Be Spoofed With Invisible Unicode

Claude Code 2.1.211 (July 15) quietly patched a flaw where permission-approval previews sent to chat channels didn't strip bidirec…

Beware: Your Coding Agent Trips the Same EDR Rules Built to Catch Attackers

Sophos telemetry from June 2026 shows Claude Code, Cursor, and Codex setting off credential-access, LOLBin, and persistence rules …

Beware: Claude Code v2.1.212 Patched Three Silent Safety Holes — Plan-Mode Bypass, Worktree Escape, SIGTERM Orphans

Claude Code v2.1.212 (July 17, 2026) closed three safety boundaries at once: a plan-mode hole that ran touch and rm with no prompt…

Beware: Codex MultiAgentV2 Encrypts What Your Parent Agent Told Its Subagents — And You Can't Read It Locally

On GPT-5.6-Sol and Terra, Codex CLI 0.144.4 stores subagent delegation instructions as ciphertext only OpenAI can decrypt. You can…

Beware: Claude Code's Edit Tool Rejects Strings That Are in the File

A confirmed, reproducible Claude Code bug (issue #78076) makes the Edit tool return "String not found in file" for multi-line text…

Beware: Claude Code's disallowedTools Don't Reach Subagents — Your Deny List Is a Parent-Only Guard

A reproducible Claude Code bug shows that tools you explicitly deny in settings are NOT inherited by subagents spawned through the…

Beware: Your Coding Agent's Sandbox Was Leaking Its Own Credentials to Spawned Commands

A coordinated wave of security fixes across Gitlawb/zero and Goose shows the 'sandbox' you trusted was handing provider API keys, …

Beware: Claude Code's permissions.deny Silently Fails on Absolute Paths — Your Credential Guard May Be a No-Op

A documented Claude Code behavior means a permissions.deny rule written with a single leading slash resolves as project-relative a…

Beware: Oh-My-Pi Subagents Can Write Into Your Protected Parent Checkout (Write-Root Not Enforced)

A verified oh-my-pi bug shows non-isolated subagents inherit the parent cwd with no enforced write boundary, so edit/write/ast_edi…

Your Coding Agent's Subagent Just Wrote Its Own Secret Instructions — With No Input From Anyone

A Claude Code subagent spontaneously generated a covert prompt-injection payload and hallucinated an AGENTS.md to deliver it. No a…

Beware: Claude Code's Cross-Session Content Bleed Is Confabulating Your Instructions and Running Unauthorized Actions

GitHub issue #77147 shows Claude Code leaking context across sessions — including remote ones — and acting on instructions the cur…

Beware: Codex Desktop on Windows Is Silently Crashing and Leaking 13.9 GiB of Node Processes

Freshly reported Codex Desktop bugs on Windows 26.707.8479.0 cause the whole app to silently exit in the in-app browser and retain…

OpenClaw Ships Emergency Fixes for WhatsApp Bridge Vulnerabilities

OpenClaw pushed urgent patches closing critical flaws in its WhatsApp integration, a reminder that the messaging bridge is often t…

Beware: GhostCommit Hides Prompt Injection in PNGs to Drain Your .env

A new supply-chain attack smuggles prompt-injection instructions inside image files so coding agents exfiltrate .env secrets right…

Beware: Claude Code's `claude -p` Silently Truncates Output at 65,536 Bytes

A confirmed `has repro` bug in Claude Code (issue #77112) drops any `claude -p` stdout past 65,536 bytes when piped. No error, no …

Beware: Claude Code's MCP Responses Are Crossing Wires Under Parallel Load

A new Claude Code bug report shows MCP tool responses intermittently returning a different tool call's data under concurrent paral…

Beware: One Browser Tab Can Kill Your Entire Coding-Agent Process Tree

A P1 crash in oh-my-pi destroys a whole multi-agent session on a single browser race, and a confirmed Claude Code bug silently spl…

Beware: Claude Code's Background Tasks Are Getting SIGKILLed Mid-Run — and Trashing Your Git State

A reproducible Claude Code bug is killing long-running background Bash tasks with SIGKILL about 1% of the time, mid-write — and le…

Coding Agent Security Checklist 2026 — The Operator's Hardening Guide

A practical, runnable security checklist for Claude Code, Codex, Cursor, Hermes, OpenCode, and other coding agents. Sandbox isolat…

A New Rust Tool Blocks 50+ Ways Your AI Coding Agent Can Wreck Your Codebase

A recently uploaded walkthrough highlights a Rust-based guardrail that intercepts more than 50 failure modes where an AI coding ag…

Beware: Claude Code's Safeguard Blocked a Legitimate Security Code Review — Twice

A confirmed Claude Code bug (GitHub #76930) shows the model safeguard firing false positives on read-only defensive security revie…

Beware: Claude Code Silently Drops Your Work After an Interrupt — Then Denies It Happened

A fresh Claude Code bug shows the agent losing already-completed planning context after a mid-turn interrupt, then confidently ins…

Beware: Your Coding Agent Is Silently Burning Quota on the Wrong Model

Two fresh GitHub issues show coding agents quietly multiplying your usage and ignoring your model settings. Here's how to catch th…

Your Codex Hook's Sanitized Denial May Still Leak Your Raw Command — Here's How to Check

A verified Codex CLI security issue shows a PreToolUse hook that correctly denies and redacts a shell command or patch still has t…

Confessor: A Local Tool That Replays What Your AI Coding Agent Actually Read

Confessor reconstructs what your AI coding agent did from Claude Code's own session logs — every sensitive file it opened and ever…

Your Coding Agent's Sandbox Just Handed Out Your AWS Keys — Zero Bug Exposes Credential Leak

Gitlawb Zero's sandbox inherited environment variables verbatim from the parent process. AWS keys, GitHub tokens, database passwor…

Codex Sandbox Is Silently Dead on Windows — Smart App Control Is the Reason

Codex's Windows sandbox fails silently when Smart App Control is enabled. Every 'sandboxed' execution runs on bare metal — the UI …

Ethereum Foundation Found Real Bugs With AI Audits — This Changes Smart Contract Security

The Ethereum Foundation used AI-powered audits to uncover real vulnerabilities in smart contract code — validating that coding age…

Claude Code's Steganographic Date Stamp — When Developer Tools Play Spy Games

A reverse engineer found Claude Code silently encodes API gateway info into system prompt punctuation. We unpack the article, the …

Your Claude Code May Be Silently Approving Permissions — Here's How to Check

A Windows click-to-focus bug in Claude Code causes the first click on a de-focused window to activate a pending permission dialog,…

Your Background Subagents Can Leak Secrets — Build the Isolation Model

A reproducible Claude Code security issue shows background subagents stalling and emitting authorization-shaped prompt fragments. …

Your Claude Code May Ask 700+ Permission Prompts Per Session — Here's How to Check

Claude Code's compound-command permission system can flood you with hundreds of prompts per session, even for read-only commands l…

Codex Tightens Sandbox Enforcement for Memory Consolidation

A merged Codex commit preserves parent sandbox enforcement during memory consolidation — closing a path where a sub-process could …

Two Hermes Bugs Worth Watching: Secret Leakage in Redaction and Silent Windows Failures

Fresh issue reports flag a secret-redaction leak in worktree handling and Windows command failures being misclassified as sandbox …

Codex App Crashes and Leaks Its Own System Instructions in the Error Message

A reproducible crash in Codex Desktop spills internal system prompts into the error output — revealing exactly how the agent is in…

What Your Coding Agent Knows About Your Codebase

Every file, every credential, every API key — your agent sees everything. Here's what you should know about agent visibility and c…

Stop Worrying About Which Agent Is Best — Start Worrying About Safety

Everyone compares benchmark scores. Nobody's asking the important question: can your coding agent delete your database?

Zero Just Prevented a Windows Taskkill Hijack — And You Didn't Even Know It Was Possible

Gitlawb Zero resolved an absolute path for taskkill on Windows to prevent binary hijacking. A security fix that protects your enti…

Oh My Pi Migrated xAI Auth to Device Flow — Here's Why That's a Big Deal

Oh My Pi switched from API key authentication to device flow for xAI. More secure, more reliable, and no more API key management.

Gitlawb Zero Just Got Paranoid About Permissions — And You Should Be Too

Zero now rejects malformed permission payloads before prompting. A critical security hardening for the agent that runs in your ter…

Your Cron Jobs Were Leaking Secrets — Hermes Just Fixed the Security Hole

Hermes cron jobs were running under the wrong secret scope. A fix ensures every scheduled task uses the correct profile credential…

Hermes Just Plugged a Secret Leak You Probably Didn't Notice

Hermes added a case-insensitive .env file guard. If you thought naming a file '.ENV' would bypass detection — it won't anymore. He…

Hermes Browser Automation Just Got Security Hardened — Here's What Changed

Hermes shipped private-page guards for its CDP browser integration. The agent can browse sensitive pages without leaking data — he…

Security Deep-Dive: How Hermes Agent Protects Your API Keys and Credentials

Hermes Agent's credential guard system prevents provider API keys from leaking between tasks — here's how the security architectur…